
A curated, actively maintained collection of Android security resources — analyzers, static and dynamic analysis tools, scanners and research — aimed at professionals conducting authorized assessments and malware research.
| Tool | ashishb/android-security-awesome — curated awesome-list of Android security tools, research, and exploit references |
| Category | Curated resource collection / awesome list (Makefile, Apache-2.0) |
| Primary Use | Discovery and triage of Android security tooling: online analyzers, static/dynamic analysis frameworks, vulnerability scanners, academic research |
| Safe Use | Reference for authorized penetration testers, app developers hardening their own applications, and malware researchers working in controlled lab environments |
| Telemetry Note | Purely a documentation resource — no binaries, no execution, no network activity; defenders can safely browse and clone it |
ashishb/android-security-awesome is one of those rare awesome-lists that has survived a decade of Android security churn and remains genuinely useful. With nearly ten thousand stars, an Apache-2.0 license, and a battery of CI badges — validate-links.yml, lint-shell-script.yaml, lint-markdown.yaml, lint-yaml.yaml, and lint-github-actions.yaml — it is maintained with an engineering discipline you seldom see in curated lists. The link-liveness checker is the detail that matters most: in a domain where analysis services die constantly, an automated workflow that validates every URL is the difference between a living map and a graveyard of dead links.
The structure is deliberately minimal: three top-level sections covering Tools, Academic/Research/Publications/Books, and Exploits/Vulnerabilities/Bugs. That taxonomy mirrors how an Android security practitioner actually works — you reach for a tool first, consult the literature when the tool's output needs interpretation, and mine historical vulnerability write-ups when hunting for bug classes. The Tools section is further decomposed into Online Analyzers, Static Analysis Tools, App Vulnerability Scanners, and Dynamic Analysis Tools, which is roughly the pipeline shape of a mobile assessment: triage, decompile, scan, instrument.
The Online Analyzers subsection is a snapshot of the commercial and free scanning market, and its most interesting feature is what has been struck through. Roughly two dozen services — Anubis, SandDroid, CopperDroid, NVISO ApkScan, AndroTotal, Droidbox-adjacent sandboxes — are preserved as strikethrough entries rather than deleted. This is quietly valuable: it documents which capabilities have consolidated or vanished, and warns you off stale blog posts that still recommend dead infrastructure. Among the living entries are VirusTotal, Koodous with its YARA-driven community rules, Pithus as an open-source static APK analyzer, AppSweep by Guardsquare targeted at developers, and enterprise platforms like Oversecured and NowSecure Lab Automated, with licensing terms honestly annotated (not free, free quotas).
The Static Analysis Tools list reads like a history of Android reverse engineering. Classics like FlowDroid for taint analysis, PSCout for permission-specification extraction from AOSP source, and Androwarn for behavioral warning sit alongside more modern and operationally relevant entries: APKLeaks for scanning APK files for URIs, endpoints and secrets, Quark-Engine as an obfuscation-neglecting malware scoring system, ClassyShark for standalone executable inspection, JAADAS built on Soot and Scala, and StaCoAn with its usability-focused GUI for developers and bug-bounty hunters. MobSF appears here as the heavyweight all-in-one option, and RiskInDroid offers permission-based risk scoring with an online demo.
App Vulnerability Scanners is a shorter, sharper list aimed at developers and assessors checking their own applications. QARK from LinkedIn targets app developers scanning for security issues; AndroBugs provides a framework-style scan; Nogotofail from Google focuses on network traffic security; and Ostorlab scans published apps across the Play Store, iOS App Store, and Huawei AppGallery. The strikethrough of Devknox — an IDE plugin no longer maintained — again reflects the list's policy of retaining history while marking decay.
The Dynamic Analysis Tools section is where the instrumentation tradecraft lives: Drozer for attacking and inspecting IPC surfaces, House from NCC Group as a Frida-powered runtime toolkit with a web GUI, Inspeckage as an Xposed module for API hooking, CuckooDroid extending the Cuckoo sandbox to Android, Androl4b as a ready-made assessment and reverse-engineering virtual machine, and DECAF for QEMU-based dynamic executable analysis. Entries like StaDynA, which combines static and dynamic analysis to handle dynamic class loading and reflection, show the curator understands that modern Android malware hides behind runtime code updates.
What elevates this list above a bookmark dump is annotation quality. Nearly every entry carries a one-line functional description, licensing notes where relevant, and lifecycle status (incomplete, not under active development anymore, unable to find the actual tool). That last candor is rare — most lists inflate their count with phantom tools, while this one explicitly flags Crowdroid as unfindable beyond its paper. For a professional building an assessment toolkit, these annotations are the actual product: they tell you what to invest learning time in and what to skip.
In an authorized workflow, this repository functions as the discovery layer. Before you write your own analysis pipeline for a client engagement, you check whether MobSF, APKLeaks, and Quark-Engine already cover the gap. For defenders and threat researchers, the same list maps the analyst-side landscape: knowing which sandboxes and YARA platforms exist (Koodous, Pithus) tells you what visibility the community has into Android malware campaigns. Malware analysts running samples in Androl4b or CuckooDroid benefit from the curated pairing of tools with the research literature in the academic section.
There are operational cautions worth noting. Several linked tools are aging — Droidbox, AuditdAndroid, and various strikethrough entries reflect an ecosystem that has moved toward Frida-based and web-driven analysis. The README itself is the only artifact; the repository is essentially documentation plus CI, written largely in Makefile-languaged plumbing for its automation. Treat every outbound link as external and untrusted: the list curates, it does not vet, so before uploading any client APK to a third-party analyzer, confirm your engagement's data-handling rules permit it — a point that applies to VirusTotal and every cloud sandbox alike.
For blue teams and purple teams, android-security-awesome doubles as a detection-side index: every dynamic analysis tool listed is also something you may observe in a lab or, if abused, on a managed device. Knowing that Xposed-based hooking, Frida injection via House, and runtime instrumentation via Inspeckage exist tells defenders what runtime-protection and integrity checks should look for. As an educational map of the field — its tools, its research canon, and its attrition rate — this repository remains one of the highest-signal starting points in Android security.
ashishb/android-security-awesome.Educational analysis for authorized security professionals. Use only in controlled, authorized environments.
0 comentários:
Post a Comment
Note: Only a member of this blog may post a comment.