Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/androguard/androguard
Android SecurityStatic AnalysisDynamic Analysis (Sandboxing)Mobile App PentestingReverse EngineeringMobile ForensicsMalware AnalysisPenetration TestingMobile SecurityTop in Android Security #6
6.2k1.1k961 day agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Top in Mobile App Pentesting #7
Top in Mobile Forensics #9
Top in Mobile Security #7
GitHubandroguard/androguard

androguard

Reverse engineering and pentesting for Android applications

View Repository

Androguard

Androguard

Androguard: Reverse engineering and pentesting for Android applications

Powered By: Androguard

PyPI Upload PyPI - Version Static Badge

Androguard 5 is a Python toolkit for Android reverse engineering: open an APK, inspect the manifest and DEX, disassemble or decompile code, hunt references and vulnerabilities, and optionally patch or analyze native ARM — from the CLI, a high-level Application API, Claude Code skills, or an MCP server for LLM hosts.

Main features

  • APK / DEX analysis — package metadata, permissions, classes, methods, strings (apkparser-ag, dexparser-ag, axml)
  • Dalvik disassembly & CFG — method-level bytecode via androguard[disasm]
  • Java decompilation — methods, classes, or whole packages via androguard[decompile]
  • Cross-refs & vulns — findrefs, vulnerability scanners, method emulation
  • Native ARM64 — disassemble / decompile .so code via androguard[arm]
  • APK patch — decode / rebuild project trees via androguard[patch]
  • LLM integration — Claude Code agent & skills, plus an MCP server (androguard-mcp) for Claude Code, Cursor, and other MCP clients
  • MASTG demo coverage — status of every OWASP MASTG Android demo vs scan_vulns in docs/mastg-coverage.md

Do you think your phone has been pwned? Please check IsMyPhonePwned.

Installation

Androguard 5 is this repository. It is not the package currently published on PyPI (androguard 4.1.4). From a checkout, install the local tree. A bare pip install androguard or pip install 'androguard[full]' downloads 4.1.4 and uninstalls 5.0.0.

# from this repo (Rust toolchain required for the optional extras)
# Python 3.14+ needs the PyO3 forward-compat flag (bindings use PyO3 0.23, max 3.13)
export PYO3_USE_ABI3_FORWARD_COMPATIBILITY=1
# Rust apk-parser + dex-parser (siblings under ../)
pip install -e ../apk-parser
pip install -e ../dex-parser
pip install -e .
pip install -e '.[full]'

After 5.0.0 is published, the same extras install from PyPI:

pip install androguard
pip install 'androguard[full]'

[!IMPORTANT] Versions >= 4.0.0 are new releases after a long time, where the project has substantial differences from the previous stable version 3.3.5 from 2019. This means that certain functionalities have been removed. If you notice an issue with your project using the latest version, please open up an issue.

Ecosystem

Androguard v5 is built on dedicated libraries:

LayerLibraryRole
APK archiveapk-parser (apkparser-ag)ZIP structure, signatures, manifest hooks
DEX structuredex-parser (dexparser-ag)Rust core + Python bindings: classes, methods, fields, bytecode
Binary XML / ARSCaxml / axml-parser (Rust)AndroidManifest.xml, resources.arsc
Bytecode (optional)dex-bytecodeDalvik disassembly / CFG / patch via androguard[disasm]
Decompiler (optional)dex-decompilerDEX → Java, ASC getclass/findrefs, vulns via androguard[decompile]
ARM64 (optional)arm_disassembler / arm_decompilerNative code via androguard[arm]
APK patch (optional)apk-patchIn-memory decode/build via androguard[patch]

Examples

Runnable demos live in examples/ and are also executed by the test suite (tests/test_examples.py):

python -m examples.application_summary
python -m examples.disassemble      # androguard[disasm]
python -m examples.decompile       # androguard[decompile]
python -m examples.arm             # androguard[arm]
python -m examples.patch_decode    # androguard[patch]
python -m examples.run_all

See examples/README.md.

Claude Code

This repo ships Claude Code project support (similar in spirit to areclaw, but driven by Androguard itself):

PathRole
CLAUDE.mdProject instructions for the agent
.claude/agents/androguard-analyst.mdAnalyst agent
.claude/skills//analyze-apk, /decompile-apk, /find-refs, /scan-vulns
workspace/Samples, decompiled output, reports
claude /agent androguard-analyst
claude /analyze-apk path/to/app.apk
claude /decompile-apk path/to/app.apk com.example.app

MCP server

Androguard can run as an MCP server so LLM hosts (Claude Code, Cursor, …) call typed analysis tools instead of shelling out to the CLI.

pip install -e '.[mcp,decompile]'   # add [disasm] for disassembly tools
androguard-mcp                     # or: python -m androguard.mcp

Example client config:

{
  "mcpServers": {
    "androguard": {
      "command": "androguard-mcp",
      "env": {
        "ANDROGUARD_MCP_ROOTS": "/path/to/androguard"
      }
    }
  }
}

Typical flow: open_apk → session_id → list_classes / find_refs / decompile_method / scan_vulns.

On launch the server prints a stderr banner (versions, tools, path roots, extras). Use --log-tools to log each tool call, and --log-level DEBUG for more detail.

Full tool list, env vars, and security notes: docs/mcp-server.md. Design background: docs/mcp-server-plan.md.

Quick start

Command line

# Summary: package, main activity, dex count, classes, methods
androguard -i my.apk

# List classes or methods
androguard -i my.apk --list-classes
androguard -i my.apk --list-methods

# Disassemble methods matching regex (requires androguard[disasm])
androguard -i my.apk --disasm --class 'TestActivity' --method 'onCreate'
androguard -i my.apk --disasm --class 'Ltests/androguard/.*' --method '<init>'
androguard -i my.apk --disasm --method 'onCreate' --limit 10
androguard -i my.apk --disasm --class TestActivity --method onCreate --cfg
Download Tool