Hacking Tools

Installation – Comprehensive Guide To Using Androguard

The versatile capabilities of Androguard, a powerful tool for reverse engineering Android applications.

This guide provides a step-by-step overview on how to install Androguard using different methods, including direct downloads from PyPI and builds from the latest commits on GitHub.

Once installed, explore its comprehensive command-line interface that offers a range of functionalities from APK analysis to dynamic tracing.

Whether you’re a developer or a security analyst, Androguard equips you with the essential tools to dive deep into Android app structures and behaviors.

You can install Androguard in three different ways:

Getting One Of The released Versions From PyPI

pip install Androguard

or if you want an older version

pip install androguard==3.3.5

Getting A Version With All The Latest Commits

git clone https://github.com/androguard/androguard.git
cd androguard
pip install .

or the same thing using pip and the GitHub URL of the project:

pip install git+https://github.com/androguard/androguard

Androguard Is Now Available To Be Used As A CLI And As A library.

Sessions

All events are saved in the file ‘androguard.db’ which is basically a sqlite db. There are 3 tables:

  • information (related to all APK/DEX/… analyzed during a session)
  • session (unique key to identify a particular session done)
  • pentest (events from frida saved)

Please note that the sessions are work in progress!

CLI

The CLI serves as the primary and easiest way for interacting with Androguard.

Upon installing androguard with any of the methods shown above, the tool should be available in your path as androguard

Usage: androguard [OPTIONS] COMMAND [ARGS]...

  Androguard is a full Python tool to reverse Android Applications.

Options:
  --version           Show the version and exit.
  --verbose, --debug  Print more
  --help              Show this message and exit.

Commands:
  analyze      Open a IPython Shell and start reverse engineering.
  apkid        Return the packageName/versionCode/versionName per APK as...
  arsc         Decode resources.arsc either directly from a given file or...
  axml         Parse the AndroidManifest.xml.
  cg           Create a call graph based on the data of Analysis and...
  decompile    Decompile an APK and create Control Flow Graphs.
  disassemble  Disassemble Dalvik Code with size SIZE starting from an...
  dtrace       Start dynamically an installed APK on the phone and start...
  dump         Start and dump dynamically an installed APK on the phone
  sign         Return the fingerprint(s) of all certificates inside an APK.
  trace        Push an APK on the phone and start to trace all...

For more information click here.

Tamil S

Tamil has a great interest in the fields of Cyber Security, OSINT, and CTF projects. Currently, he is deeply involved in researching and publishing various security tools with Kali Linux Tutorials, which is quite fascinating.

Recent Posts

Exploit Street – Navigating The New Terrain Of Windows LPEs

Exploit-Street, where we dive into the ever-evolving world of cybersecurity with a focus on Local…

11 hours ago

ShadowDumper – Advanced Techniques For LSASS Memory Extraction

Shadow Dumper is a powerful tool used to dump LSASS (Local Security Authority Subsystem Service)…

1 day ago

Shadow-rs : Harnessing Rust’s Power For Kernel-Level Security Research

shadow-rs is a Windows kernel rootkit written in Rust, demonstrating advanced techniques for kernel manipulation…

2 weeks ago

ExecutePeFromPngViaLNK – Advanced Execution Of Embedded PE Files via PNG And LNK

Extract and execute a PE embedded within a PNG file using an LNK file. The…

3 weeks ago

Red Team Certification – A Comprehensive Guide To Advancing In Cybersecurity Operations

Embark on the journey of becoming a certified Red Team professional with our definitive guide.…

3 weeks ago

CVE-2024-5836 / CVE-2024-6778 : Chromium Sandbox Escape via Extension Exploits

This repository contains proof of concept exploits for CVE-2024-5836 and CVE-2024-6778, which are vulnerabilities within…

4 weeks ago