Open-source project
AzeemIdrisi/PhoneSploit-Pro avatar
AzeemIdrisi/PhoneSploit-Pro

PhoneSploit Pro: a menu-driven ADB front end for Android pentesting

An all-in-one hacking tool to remotely take over Android devices.

6,321 stars897 forksPythonGPL-3.0

At a glance

What is it?
PhoneSploit Pro wraps adb, scrcpy, Nmap and Metasploit in a numbered Python menu. It is useful when you already have an authorized test device and do not want to retype adb invocations, and it is the wrong tool the moment that authorization is missing.
Who is it for?
Adopt PhoneSploit Pro if you run authorized Android assessments and want the adb, scrcpy and Metasploit invocations collected behind one numbered menu instead of scattered shell history.
Can I use it commercially?
Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
Is it still maintained?
Yes. The repository last received commits 16 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What PhoneSploit Pro actually removes from an Android test

The problem is not that adb is hard. It is that a full Android walkthrough is dozens of separate invocations, each with its own flags, and the ones you need change depending on whether the target is on USB or on the network. PhoneSploit Pro collects those invocations behind a numbered menu. The README describes the tool as one that means "you no longer need to memorize commands and arguments" and that you "pick a number and run." That is the whole value proposition, and it is a real one for anyone who tests phones occasionally rather than daily.

The audience is narrow and the README says so indirectly. The feature list includes unlocking the device, reading the shell, sending keycodes, extracting data, streaming camera and microphone, managing apps, and automating what the README calls a full Metasploit compromise. Every one of those assumes an authorized target and a device where you can reach Developer options. This is a lab and assessment tool, not something you point at a stranger's phone.

How the menu drives adb, scrcpy, Nmap and Metasploit

The entry point is a single Python file, phonesploitpro.py, with supporting code under modules/. The declared dependencies are small: requirements.txt lists python-nmap and rich, nothing more. Everything else the tool drives is an external binary that has to exist on the host already, which is why the README carries a separate "Installing tools manually" section and an "Installing dependencies" section rather than a single pip install line.

The control surface is the ADB server. The feature table lists starting, stopping and restarting that server, listing connected devices, disconnecting all sessions, and opening an interactive shell. When more than one device is attached over USB or network, the README says the tool lets you choose which one the session uses, and names the environment variable that carries that choice, ANDROID_SERIAL. That is the one piece of state that decides which phone every later menu action hits, so it is worth checking before you start clicking.

Beyond adb, the tool shells out to scrcpy for screen work, Nmap for network scanning, and Metasploit for the exploitation path. The README frames the Metasploit integration as automation of a full compromise rather than a set of primitives you assemble yourself. Treat that as a convenience wrapper over tools you should already understand, because when a step fails you will be reading Metasploit or adb output, not PhoneSploit Pro's.

Installing PhoneSploit Pro and running a first authorized session

The repository ships two platform installers at the top level, install.sh and install.ps1, alongside requirements.txt. The README also documents installing the external tools manually, which is the step people skip and then wonder why a menu entry does nothing. Python 3.10 or newer is the stated floor.

On a Linux host, clone the repository and run the shell installer:

bash
git clone https://github.com/AzeemIdrisi/PhoneSploit-Pro.git
cd PhoneSploit-Pro
chmod +x install.sh
./install.sh

The installer is the repository's own script; read it before running it on a machine you care about, since it is the component that pulls in or prompts for adb, scrcpy, Nmap and Metasploit. If you prefer to control that yourself, install the Python dependencies directly and follow the README's manual tools section:

bash
pip install -r requirements.txt

That gives you python-nmap and rich. It does not give you adb, scrcpy, Nmap or Metasploit.

With the tool installed and a device you own attached over USB, start the program:

bash
python3 phonesploitpro.py

You should see the numbered menu. The README's device setup tutorial is the prerequisite: enable Developer options and USB debugging on the target, accept the host key prompt on the device, then use the menu entry that lists connected devices. If your device does not appear there, no later menu entry will work, and the fix is in adb, not in PhoneSploit Pro. If several devices are attached, pick the right one before continuing, because the selection drives ANDROID_SERIAL for the rest of the session.

Where PhoneSploit Pro stops being the right tool

The obvious boundary is consent. The README's own disclaimer section exists for a reason: this is a tool for devices you are authorized to test. If you cannot show that authorization, nothing else in this review matters.

The technical boundary is just as sharp. Every capability in the feature table is downstream of an adb connection, and adb requires USB debugging to be enabled on the target. A phone with a locked bootloader, debugging off, and no physical access is out of scope, and no menu entry changes that. The README's device setup tutorial is not optional background reading; it is the precondition for the entire tool.

There is a second, quieter limitation. PhoneSploit Pro orchestrates other programs. When scrcpy fails to start, or Metasploit cannot establish what the README calls a full compromise, the error you see comes from those tools, and the menu gives you no extra diagnostics. A tester who does not already know how to run adb, scrcpy and Metasploit by hand will struggle to tell a tool problem from a target problem. The menu removes typing, not understanding.

Finally, the repository is a Python script plus modules and installers, not a packaged distribution. There is no published wheel or container image in the README, so you are running from a clone, and you own the dependency drift on your host.

PhoneSploit Pro against driving adb and scrcpy directly

The real alternative is not another all-in-one tool; it is the tools themselves. If you already know adb, scrcpy and Metasploit, running them directly gives you the full flag surface, scriptable output, and error messages you can read. PhoneSploit Pro's menu is a fixed set of numbered actions, so anything outside that set means dropping to a shell anyway, and at that point you have two interfaces to keep in mind instead of one.

The trade is speed of recall. For an occasional device check, remembering the right adb invocation for a screenshot or a reboot into bootloader is friction, and the menu removes it. For a repeatable assessment you script, direct adb calls compose better: they exit with codes, they pipe, and they drop into CI. PhoneSploit Pro is interactive by design, and the README presents it that way. Pick it when a human is sitting at the keyboard and the target is a device in front of them, not when you need an unattended run.

Maintenance, licensing and the cost of running from a clone

The repository is not archived. The last push was on 2026-09-14, and the most recent release is v2.3 from 2026-09-02, following v2.1 in May 2026 and v2.0 in April 2026. That is a steady release cadence through 2026, and the project carries a Hacktoberfest topic, which usually means it accepts outside contributions. None of that guarantees your platform's install path keeps working, and the README does not describe a support policy or a deprecation process.

The upgrade cost is mostly in the externals. PhoneSploit Pro's own Python surface is two dependencies, so a git pull is cheap. The expensive part is the adb, scrcpy, Nmap and Metasploit versions on your host, which the project does not pin. Expect to re-check the Metasploit path after any host upgrade, because that is where version drift shows up first.

The licence is GPL-3.0. If you fork it, distribute a modified version, or ship it inside another product, the copyleft terms apply to the combined work. That is a real constraint for anyone thinking of embedding the menu in a commercial service. This is a description of the licence, not legal advice; read the LICENSE file in the repository and talk to someone qualified if the distribution question matters to you.

Editorial conclusion

Adopt PhoneSploit Pro if you run authorized Android assessments and want the adb, scrcpy and Metasploit invocations collected behind one numbered menu instead of scattered shell history. Do not adopt it if you cannot point to written authorization for the device, or if you need something that works on a non-rooted target with USB debugging off: the README's own device setup tutorial assumes you can enable Developer options and USB debugging, and nothing in the repository changes that. Before relying on it, verify three things on your own hardware: that install.sh or install.ps1 completes on your platform, that the tool detects your device through adb devices, and that the Metasploit path reaches a session on a device you own.

Frequently asked questions

Which Python version does PhoneSploit Pro need?

The README states Python v3.10 or newer. The repository's requirements.txt lists python-nmap and rich, and the external tools adb, scrcpy, Nmap and Metasploit are installed separately.

Does PhoneSploit Pro work on a device with USB debugging turned off?

No. Every feature in the README's feature table runs through ADB, and the README includes a device setup tutorial for enabling Developer options and USB debugging on the target before use.

How do I install PhoneSploit Pro on Linux or Windows?

The repository ships install.sh and install.ps1 at the top level for the two platforms, and the README also documents installing the external tools manually. After installation the program is started with python3 phonesploitpro.py.

What happens if more than one Android device is connected to PhoneSploit Pro?

The README's feature table describes a multi-device selection step: when several ADB devices are attached over USB or network, you choose which one the session uses, and that choice is carried in the ANDROID_SERIAL environment variable.

Official sources

  1. AzeemIdrisi/PhoneSploit-Pro on GitHub
  2. License: GPL-3.0
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/azeemidrisi-phonesploit-pro.svg)](https://hysenlabs.com/projects/azeemidrisi-phonesploit-pro)