
androguard is a mature Python toolkit for disassembling, decompiling and auditing Android APKs, aimed at analysts doing authorized mobile security assessments and malware research.
| Tool | androguard/androguard — Python toolkit for Android reverse engineering: APK/DEX parsing, disassembly, decompilation, vulnerability scanning and LLM integration |
| Category | Static analysis / reverse engineering framework |
| Primary Use | Opening an APK in authorized engagements to inspect the manifest, disassemble Dalvik bytecode, decompile to Java via androguard[decompile], run --findrefs and --scan-vulns audits |
| Safe Use | For authorized penetration tests, in-house app reviews, and defensive malware research on samples you own or are contracted to analyze |
| Telemetry Note | Purely local static analysis — operates entirely on the analyst workstation; since it never touches the target device, defenders would not observe its use on endpoints, only in lab telemetry |
androguard is one of the longest-standing open-source projects in the Android security space, and the current repository represents Androguard 5, a substantial rearchitecting of the classic toolkit into a modular ecosystem of purpose-built libraries. The README describes it plainly: a Python toolkit for Android reverse engineering that lets you open an APK, inspect the manifest and DEX, disassemble or decompile code, hunt references and vulnerabilities, and optionally patch or analyze native ARM code. With roughly 6250 stars, an Apache-2.0 license, and topics spanning android, dalvik, dex, odex, pentesting, and reverse-engineering, it occupies the position of a reference tool rather than a niche script — the kind of framework a mobile assessor reaches for before anything else when a sample lands on their desk.
What distinguishes version 5 from its predecessors is the ecosystem decomposition. Rather than a monolith, the project is now layered over sibling libraries with focused roles: apk-parser (published as apkparser-ag) handles ZIP structure, signatures, and manifest hooks; dex-parser (dexparser-ag) provides a Rust core with Python bindings for classes, methods, fields, and bytecode; axml and axml-parser decode AndroidManifest.xml and resources.arsc; and a set of optional extras add capability on demand. This design means the heavy parsing happens in compiled Rust rather than interpreted Python, which matters when you are iterating over tens of thousands of methods in a production app. The modular split also lets each layer evolve independently — a defensive researcher who only needs manifest and permission extraction can depend on the APK layer without pulling in decompilation machinery.
Installation deserves careful attention because the README is unusually explicit about a packaging trap: Androguard 5 is the repository itself, not the package currently published on PyPI. A bare pip install androguard currently fetches version 4.1.4 and can actually uninstall a working 5.0.0 setup. From a checkout you need the Rust sibling libraries present, and the README shows the sequence: pip install -e ../apk-parser, pip install -e ../dex-parser, then pip install -e '.[full]'. A Rust toolchain is required for the optional extras, and on Python 3.14+ you must set PYO3_USE_ABI3_FORWARD_COMPATIBILITY=1 because the bindings use PyO3 0.23, which caps at 3.13. Once 5.0.0 hits PyPI, the standard pip install 'androguard[full]' will work directly.
The feature surface reads like a checklist of what a mobile code audit actually requires. The base install covers APK and DEX analysis: package metadata, permissions, classes, methods, and strings. Optional extras unlock the deeper work — androguard[disasm] for method-level Dalvik disassembly and control-flow graphs, androguard[decompile] for DEX-to-Java decompilation of methods, classes, or whole packages, androguard[arm] for disassembling and decompiling native ARM64 code in bundled .so libraries, and androguard[patch] for decoding and rebuilding APK project trees. That last capability is the one that pushes the tool from read-only analysis into modification territory, and in an authorized workflow it is typically used for instrumenting your own test builds rather than tampering with third-party production apps.
The CLI is well designed for iterative triage. A summary invocation like androguard -i my.apk returns the package name, main activity, DEX count, class and method counts at a glance. From there you narrow down: --list-classes and --list-methods for enumeration, --disasm --class TestActivity --method onCreate with regex support for targeted disassembly, --decompile-method 'com.example.Class#method' for readable Java, and --findrefs string --findrefs-value password for hunting sensitive references across the DEX. The --cfg flag renders control-flow graphs for a disassembled method, and --emulate runs method emulation — useful for evaluating obfuscated logic without executing the app on a device. The README thoughtfully bundles a smoke test against tests/data/APK/TestActivity.apk, so an analyst can validate the full toolchain immediately after installation.
What elevates androguard 5 above a mere parsing library is the vulnerability scanner, --scan-vulns, and its validation methodology. The scanner is tested against every OWASP MASTG Android demo, with results checked into docs/mastg-coverage.md including pass/gap/skip status per MASTG-DEMO-* identifier, Frida static assessments where relevant, and the MASWE/MASVS/MASTG category mappings the scanner reports. This is a level of transparency rare in security tooling: rather than claiming broad coverage, the project publishes exactly which weakness classes it detects and which it misses. The regeneration scripts, scripts/mastg_validate.py and scripts/mastg_coverage_doc.py, require JDK 17 and ANDROID_HOME for full rebuilds, which tells you the validation rebuilds the actual demo apps rather than replaying cached results.
The most forward-looking piece is the LLM integration, which is unusual to see documented this thoroughly in a reverse-engineering tool. The repository ships Claude Code project support in the form of agent and skill definitions — /analyze-apk, /decompile-apk, /find-refs, /scan-vulns — with a workspace/ directory for samples, decompiled output, and reports. Beyond that, androguard can run as an MCP server (androguard-mcp, or python -m androguard.mcp) so LLM hosts like Claude Code or Cursor call typed analysis tools instead of shelling out to the CLI. The documented flow — open_apk returning a session_id, then list_classes, find_refs, decompile_method, scan_vulns — is essentially an API for agentic APK analysis, with ANDROGUARD_MCP_ROOTS scoping filesystem access and --log-tools providing an audit trail of every tool call.
The programmatic API follows the same layered philosophy. The high-level Application class gives you app.summary() as a dict — app name, main activity, package, DEX files, class/method/string counts, signature status — plus iterable class_names and methods. Beneath it, apkparser.APK accepts flags like OPTION_AXML, OPTION_SIGNATURE, and OPTION_PERMISSION, while dexparser.DEXHelper exposes from_string, from_rawdex, and from_path constructors and lets you walk classes, methods, fields, and strings directly, including filtering the string table for terms like password. The README even shows raw DEX header access via d["header"], which is exactly the kind of primitive a researcher building a custom detection or triage pipeline wants.
Versioning caveats matter here. The README warns that versions >= 4.0.0 differ substantially from the last pre-gap stable, 3.3.5 from 2019, and that certain functionalities were removed in the rewrite. Anyone maintaining automation built against the 3.x APIs should budget migration time and file issues when behavior changes. The documentation badge itself reads InProgress, so expect the code and examples in the repo — notably examples/, which doubles as the test suite via tests/test_examples.py — to be more authoritative than prose docs for now.
For defenders and authorized assessors, androguard fits squarely into static analysis workflows: triaging suspected malicious APKs in an isolated lab, verifying whether an organization's own mobile builds leak hardcoded secrets via string and reference hunting, or mapping an application's attack surface from its manifest permissions before dynamic testing on a controlled device. Because it operates purely offline on the sample file, it leaves no footprint on any target system and carries no risk of interacting with live infrastructure — a property that makes it a safe default for first-pass analysis of unknown samples. The README's nod to IsMyPhonePwned for consumers who suspect compromise underlines the project's positioning as a research and defensive instrument rather than an attack tool. Combined with its MASTG-validated scanner and the novel MCP integration, androguard 5 is a rare case of a legacy security tool modernizing without abandoning the depth that made it canonical.
androguard/androguard.Educational analysis for authorized security professionals. Use only in controlled, authorized environments.
0 comentários:
Post a Comment
Note: Only a member of this blog may post a comment.