6 repositorios
Executing Java code and specialized security modules directly on an Android device to test for systemic weaknesses.
Distinct from Security Testing: Distinct from general Security Testing: specifically targets Android runtime with Java code injection and module execution.
Explore 6 awesome GitHub repositories matching security & cryptography · Android Runtime. Refine with filters or upvote what's useful.
Elder driver Xposed Framework.
Hooks into the Android Runtime (ART) to replace or extend method implementations at runtime using native C/C++ components.
Drozer es un framework de pruebas de seguridad y analizador de tiempo de ejecución para aplicaciones y dispositivos Android. Funciona como un framework de gestión de exploits y un conjunto de herramientas de seguridad utilizado para identificar vulnerabilidades, configuraciones erróneas y fugas de información dentro del sistema operativo Android y sus aplicaciones instaladas. El framework permite la simulación del comportamiento de las aplicaciones y la interacción con puntos finales de comunicación para detectar fallos de seguridad. Gestiona la ejecución, el análisis y el intercambio de exploits públicos para la investigación de seguridad móvil. El sistema proporciona capacidades para la auditoría de aplicaciones, la investigación de vulnerabilidades y la ejecución de módulos de seguridad especializados. Esto incluye la capacidad de interactuar con el tiempo de ejecución de Android y la shell del dispositivo para evaluar el estado de seguridad del hardware y el software.
Analyzes the Android runtime and device shell to detect vulnerabilities within installed applications.
Drozer is a security testing framework for Android applications that operates through an agent-based remote execution model. It combines a client-server command routing system with a device-side agent, enabling security assessments by mapping inter-process communication (IPC) attack surfaces and running dynamic exploit modules directly on Android devices. The framework distinguishes itself through its ability to discover and enumerate exported Android components by analyzing manifest data and crafting Intents to probe for vulnerabilities. It supports content provider query injection to detect
Executes Java code and specialized security modules directly on an Android device to test for systemic weaknesses.
XposedBridge is an Android Java hooking framework and bytecode instrumentation engine. It functions as a runtime system for intercepting and modifying Java method calls within the Android operating system and installed applications. The project provides a mechanism for zygote process injection, ensuring that all spawned applications inherit the instrumentation logic. It enables the modification of internal Android system behaviors through method proxying and Java reflection to access private internal system members. The framework supports dynamic Android instrumentation and runtime analysis,
Supports observing and manipulating method execution flows in a live Android environment for research and debugging.
BiliRoamingX is a collection of binary modifications and an application feature unlocker for a mobile client. It functions as a set of patches designed to unlock hidden features, remove regional restrictions, and modify the behavior and appearance of the application. The project utilizes a customization framework to remove unwanted page elements and adjust interface scales. It includes a media playback optimizer that forces default high resolutions and enables custom playback speeds for video streams. The modification suite covers regional restriction bypasses, content feed filtering, and su
Alters the properties and methods of active application objects to enable disabled features.
This project is an Android security analysis toolkit and mobile app runtime manipulator designed for reverse engineering and auditing mobile applications. It provides a system for modifying Java classes and method behavior in active mobile processes to bypass security controls. The toolkit includes a web-based interface for controlling the instrumentation engine and a specialized utility for disabling certificate validation to intercept and inspect encrypted network traffic via SSL pinning bypass. It also features an Android file explorer for browsing and managing files within private data di
Intercepts function calls and alters Java classes in real time to change how a mobile application executes.