SecurityCipher
Home Blog About Us

Learn Paths, courses, and reference docs

  • 🚀 Start Here Beginner path through the site
  • 🗺️ Penetration Testing Roadmap Structured path to become a pentester
  • 🎓 Free Security Courses Current free Udemy coupon listings
  • 📄 Secure Code Explain Vulnerable vs secure code side by side
  • 🎯 Penetration Testing Tricks Field notes for real engagements
  • 📖 Vulnerability Explain How common vulns actually work

Checklists Interactive reviews and LLM risks

  • ✅ Security Checklists Hub All interactive security checklists
  • 📋 Writeup Checklists Steps derived from real writeups
  • 🧠 LLM AI Security Checklist Controls for LLM apps
  • 🤖 OWASP LLM Top 10 LLM Top 10 risks mapped out
  • 🧰 Burp Suite Guide Step-by-step Burp tutorials
  • 📘 Payload Field Manual Safe-first probes and signals

Practice Browser labs, games, and explorers

  • 🔬 Interactive Labs SQL injection, AI, architecture review
  • 🎮 Security Games Phishing, JWT, WAF, and more
  • 🚗 On-Call Drive Neon-city arcade security missions
  • • Shift Zero SOC desk: phish, OTP, malware, tickets
  • ❓ Application Security Quiz Web, secure coding, and cloud quizzes
  • 🗺️ OWASP Top 10 Explorer Clickable risk map with signals
  • 🔀 Interactive Attack Paths Recon-to-impact chains

Tools & Career Databases, jobs, and community

  • 🛠️ Security Tools Curated recon, SAST, and bounty tools
  • 🔎 CVE Lookup Multi-source CVE intelligence
  • 💰 Bug Bounty Programs Live public scopes to search
  • 💼 Cybersecurity Jobs Roles from company career pages
  • 🧑‍💻 Security Researchers Community profiles and submissions
  • 🎤 Security Conferences Upcoming and past events
Browse all Security resources hub Freelance Security →
My Resume
Freelance SecurityFreelance
New Security Researchers Join the directory - submit your profile for review Submit profile →
← Security Tools View on GitHub

androguard

Reverse-engineering and analysis toolkit for Android apps and DEX/APK files.

Androguard

Androguard

Androguard: Reverse engineering and pentesting for Android applications

Powered By: Androguard

PyPI Upload PyPI - Version Static Badge

Androguard 5 is a Python toolkit for Android reverse engineering: open an APK, inspect the manifest and DEX, disassemble or decompile code, hunt references and vulnerabilities, and optionally patch or analyze native ARM — from the CLI, a high-level Application API, Claude Code skills, or an MCP server for LLM hosts.

Main features

  • APK / DEX analysis — package metadata, permissions, classes, methods, strings (apkparser-ag, dexparser-ag, axml)
  • Dalvik disassembly & CFG — method-level bytecode via androguard[disasm]
  • Java decompilation — methods, classes, or whole packages via androguard[decompile]
  • Cross-refs & vulns — findrefs, vulnerability scanners, method emulation
  • Native ARM64 — disassemble / decompile .so code via androguard[arm]
  • APK patch — decode / rebuild project trees via androguard[patch]
  • LLM integration — Claude Code agent & skills, plus an MCP server (androguard-mcp) for Claude Code, Cursor, and other MCP clients
  • MASTG demo coverage — status of every OWASP MASTG Android demo vs scan_vulns in docs/mastg-coverage.md

Do you think your phone has been pwned? Please check IsMyPhonePwned.

Installation

Androguard 5 is this repository. It is not the package currently published on PyPI (androguard 4.1.4). From a checkout, install the local tree. A bare pip install androguard or pip install 'androguard[full]' downloads 4.1.4 and uninstalls 5.0.0.

# from this repo (Rust toolchain required for the optional extras)
# Python 3.14+ needs the PyO3 forward-compat flag (bindings use PyO3 0.23, max 3.13)
export PYO3_USE_ABI3_FORWARD_COMPATIBILITY=1
# Rust apk-parser + dex-parser (siblings under ../)
pip install -e ../apk-parser
pip install -e ../dex-parser
pip install -e .
pip install -e '.[full]'

After 5.0.0 is published, the same extras install from PyPI:

pip install androguard
pip install 'androguard[full]'

[!IMPORTANT] Versions >= 4.0.0 are new releases after a long time, where the project has substantial differences from the previous stable version 3.3.5 from 2019. This means that certain functionalities have been removed. If you notice an issue with your project using the latest version, please open up an issue.

Ecosystem

Androguard v5 is built on dedicated libraries:

LayerLibraryRole
APK archive apk-parser (apkparser-ag)ZIP structure, signatures, manifest hooks
DEX structure dex-parser (dexparser-ag)Rust core + Python bindings: classes, methods, fields, bytecode
Binary XML / ARSC axml / axml-parser (Rust) AndroidManifest.xml, resources.arsc
Bytecode (optional)dex-bytecodeDalvik disassembly / CFG / patch via androguard[disasm]
Decompiler (optional)dex-decompilerDEX → Java, ASC getclass/findrefs, vulns via androguard[decompile]
ARM64 (optional) arm_disassembler / arm_decompilerNative code via androguard[arm]
APK patch (optional)apk-patchIn-memory decode/build via androguard[patch]

Examples

Runnable demos live in examples/ and are also executed by the test suite (tests/test_examples.py):

python -m examples.application_summary
python -m examples.disassemble      # androguard[disasm]
python -m examples.decompile       # androguard[decompile]
python -m examples.arm             # androguard[arm]
python -m examples.patch_decode    # androguard[patch]
python -m examples.run_all

See examples/README.md.

Claude Code

This repo ships Claude Code project support (similar in spirit to areclaw, but driven by Androguard itself):

PathRole
CLAUDE.mdProject instructions for the agent
.claude/agents/androguard-analyst.mdAnalyst agent
.claude/skills/ /analyze-apk, /decompile-apk, /find-refs, /scan-vulns
workspace/Samples, decompiled output, reports
claude /agent androguard-analyst
claude /analyze-apk path/to/app.apk
claude /decompile-apk path/to/app.apk com.example.app

MCP server

Androguard can run as an MCP server so LLM hosts (Claude Code, Cursor, …) call typed analysis tools instead of shelling out to the CLI.

pip install -e '.[mcp,decompile]'   # add [disasm] for disassembly tools
androguard-mcp                     # or: python -m androguard.mcp

Example client config:

{
  "mcpServers": {
    "androguard": {
      "command": "androguard-mcp",
      "env": {
        "ANDROGUARD_MCP_ROOTS": "/path/to/androguard"
      }
    }
  }
}

Typical flow: open_apk → session_id → list_classes / find_refs / decompile_method / scan_vulns.

On launch the server prints a stderr banner (versions, tools, path roots, extras). Use --log-tools to log each tool call, and --log-level DEBUG for more detail.

Full tool list, env vars, and security notes: docs/mcp-server.md. Design background: docs/mcp-server-plan.md.

Quick start

Command line

# Summary: package, main activity, dex count, classes, methods
androguard -i my.apk

# List classes or methods
androguard -i my.apk --list-classes
androguard -i my.apk --list-methods

# Disassemble methods matching regex (requires androguard[disasm])
androguard -i my.apk --disasm --class 'TestActivity' --method 'onCreate'
androguard -i my.apk --disasm --class 'Ltests/androguard/.*' --method '<init>'
androguard -i my.apk --disasm --method 'onCreate' --limit 10
androguard -i my.apk --disasm --class TestActivity --method onCreate --cfg

# Decompile to Java (requires androguard[decompile])
androguard -i my.apk --decompile-method 'tests.androguard.TestActivity#onCreate'
androguard -i my.apk --decompile --class TestActivity --method onCreate
androguard -i my.apk --decompile -o out.java
androguard -i my.apk -d decompiled/ --only-package tests.androguard
androguard -i my.apk --getclass tests.androguard.TestActivity
androguard -i my.apk --findrefs string --findrefs-value password
androguard -i my.apk --scan-vulns
androguard -i my.apk --emulate 'tests.androguard.TestActivity#onCreate'

# Decode project tree (requires androguard[patch])
androguard -i my.apk --decode-project

CLI smoke test (bundled sample)

After pip install -e '.[full]', exercise the main CLI features against the repo sample APK (tests/data/APK/TestActivity.apk):

# from the androguard repo root
APK=tests/data/APK/TestActivity.apk
CLS=tests.androguard.TestActivity
METH="$CLS#onCreate"

androguard -i "$APK"                                    # summary
androguard -i "$APK" --list-classes | head
androguard -i "$APK" --list-methods | head

# disasm (androguard[disasm])
androguard -i "$APK" --disasm --class TestActivity --method onCreate
androguard -i "$APK" --disasm --class TestActivity --method onCreate --cfg

# decompile / ASC / vulns / emulate (androguard[decompile])
androguard -i "$APK" --decompile-method "$METH"
androguard -i "$APK" --getclass "$CLS"
androguard -i "$APK" -d /tmp/androguard-decompiled/ --only-package tests.androguard
androguard -i "$APK" --findrefs string --findrefs-value "this is a test"
androguard -i "$APK" --scan-vulns                       # MASWE / MASVS / MASTG ids
androguard -i "$APK" --emulate "$METH"

# patch (androguard[patch])
androguard -i "$APK" --decode-project

Or run the Python demos (same coverage, including optional ARM):

python -m examples.run_all

MASTG demo coverage

Androguard’s vulnerability scanner is validated against all OWASP MASTG Android demos. The checked-in results live in:

docs/mastg-coverage.md

It lists every MASTG-DEMO-* with validate status (pass / gap / skip), Frida static assessment when relevant, and the scan_vulns categories found.

# regenerate after a validate run (needs JDK 17 + ANDROID_HOME for a full rebuild)
python scripts/mastg_validate.py --setup
python scripts/mastg_validate.py            # builds/scans demos → JSON + refreshes docs/mastg-coverage.md
python scripts/mastg_coverage_doc.py        # refresh the markdown from the latest JSON only

High-level API (Application)

from androguard import Application

app = Application("my.apk")

print(app.summary())
# {'app_name': '...', 'main_activity': '...', 'package': 'com.example',
#  'dex_files': ['classes.dex', ...], 'classes': 1234, 'strings': 5678,
#  'methods': 8900, 'signed': True}

for name in app.class_names[:10]:
    print(name)

for method in app.methods:
    if method.get_code():
        print(method.class_name, method.name, method.get_code().insns_size)

APK layer (apkparser-ag)

import io
from apkparser import APK, OPTION_AXML, OPTION_SIGNATURE, OPTION_PERMISSION

with open("my.apk", "rb") as f:
    apk = APK(
        io.BytesIO(f.read()),
        {
            OPTION_AXML: True,
            OPTION_SIGNATURE: True,
            OPTION_PERMISSION: True,
        },
    )

print(apk.get_app_name())
print(apk.get_main_activity())
print(apk.axml.package if apk.axml else "")  # from decoded manifest
print(list(apk.get_dex_names()))  # classes.dex, classes2.dex, ...

manifest_xml = apk.get_android_manifest()
raw_manifest = apk.get_file("AndroidManifest.xml")

Or through Androguard re-exports:

from androguard.core.apk import APK, OPTION_AXML

DEX layer (dex-parser)

From an APK’s DEX blobs:

from dexparser import DEX, DEXHelper, DEX_from_source

# From APK bytes (via apkparser)
raw = apk.get_file("classes.dex")
dh = DEXHelper.from_string(raw)

# From a .dex file on disk
d = DEX.from_path("classes.dex")
dh = DEXHelper.from_rawdex(d)

# Path, bytes, or stream
dh = DEXHelper.from_rawdex(DEX_from_source("classes.dex"))

Iterate structure:

for cls in dh.get_classes():
    print("CLASS", cls.name, "extends", cls.sname)

for method in dh.get_methods():
    print("METHOD", method.class_name, method.name, method.proto)
    code = method.get_code()
    if code:
        insns = code["insns"].value   # raw Dalvik bytecode (bytes)
        print("  insns:", code.insns_size, "bytes:", len(insns))

for field in dh.get_fields():
    print("FIELD", field.class_name, field.name, field.type_field)

for s in dh.get_strings():
    if "password" in s.lower():
        print(s)

Header as a dict:

d = DEX(bytes_data)
print(d["header"])  # file_size, class_defs_size, string_ids_size, ...

Androguard shortcuts:

from androguard.misc import AnalyzeAPK, AnalyzeDex

apk_obj, dex_helpers, app = AnalyzeAPK("my.apk")
dh = AnalyzeDex("classes.dex")       # path or bytes

Dalvik disassembly (dex-bytecode, optional)

from androguard.core.bytecode import (
    disassemble,
    disassemble_method_code,
    basic_blocks,
    cfg_edges,
    patch_branch,
    encode_instruction,
    encode_nop,
)

# Raw bytecode
for ins in disassemble(b"\x00\x00\x0e\x00"):
    print(f"{ins['offset']:08x}  {ins['mnemonic']} {ins['operands']}")

# CFG / basic blocks
print(basic_blocks(b"\x00\x00\x28\x00\x0e\x00"))  # nop; goto +0; return-void
print(cfg_edges(b"\x00\x00\x28\x00\x0e\x00"))

# Encode / patch
print(encode_instruction("const/4", "v0, 1").hex())
print(encode_nop().hex())
mutated = patch_branch(b"\x28\x01\x0e\x00", 0, 2)

# From a parsed method
code = method.get_code()
if code:
    for ins in disassemble_method_code(code):
        print(ins["disasm"])

Through Application:

for method in app.methods:
    code = method.get_code()
    if not code:
        continue
    for line in app.iter_disassembly(method):
        print(line)
    print(app.method_basic_blocks(method))
    print(app.method_cfg_edges(method))

Java decompilation (dex-decompiler, optional)

from androguard.core.decompiler import (
    parse_dex,
    decompile_method,
    getclass,
    findrefs,
    scan_vulns,
    method_cfg,
    emulate_method,
    descriptor_to_java,
)

raw = apk.get_file("classes.dex")
dex = parse_dex(raw)

# Entire DEX as one Java source string
print(dex.decompile()[:2000])

# One method (Java class names)
java = dex.decompile_method("tests.androguard.TestActivity", "onCreate")

# Package layout on disk
dex.decompile_to_dir("out/")

# ASC helpers (APK or DEX bytes)
print(getclass(apk_bytes, "tests.androguard.TestActivity")[:500])
print(findrefs(apk_bytes, "string", "password")[:5])
print(scan_vulns(raw)[:3])
rows, nodes, edges = method_cfg(raw, "tests.androguard.TestActivity", "onCreate")
print(emulate_method(raw, "tests.androguard.TestActivity", "onCreate"))

# Dalvik descriptor → Java name
print(descriptor_to_java("Ltests/androguard/TestActivity;"))
# tests.androguard.TestActivity

Through Application:

# CLASS#METHOD selector (Java names, same as dex-decompiler CLI)
print(app.decompile_method_selector("tests.androguard.TestActivity#onCreate"))

# Regex on Dalvik descriptors / method names
for method, source in app.iter_decompiled_methods(
    class_pattern=r"TestActivity",
    method_pattern=r"onCreate",
):
    print(method.class_name, "→", len(source), "chars")

# All DEX files from the APK → decompiled/ classes/ classes2/ …
app.decompile_apk_to_dir("decompiled/", only_package="tests.androguard")

# ASC + analysis
print(app.getclass("tests.androguard.TestActivity")[:500])
print(app.findrefs("type", "Landroid/app/Activity;"))
print(app.scan_vulns()[:3])
print(app.emulate("tests.androguard.TestActivity", "onCreate"))

ARM64 (arm_disassembler / arm_decompiler, optional)

from androguard.core import arm

print(arm.decode_one(0xD503201F))  # nop
for ins in arm.disassemble(bytes.fromhex("1f2003d5c0035fd6")):
    print(ins["text"])

out = arm.decompile(bytes.fromhex("1f2003d5c0035fd6"), name="foo")
print(out["source"])

APK patch (apk-patch, optional)

from androguard.core import patch

project = patch.decode(apk_bytes, no_res=True)
# edit project["files"]["project/AndroidManifest.xml"] etc.
rebuilt = patch.build(project["files"], project_root=project["project_root"])

# or one-shot
rebuilt = patch.roundtrip(apk_bytes, sign=True)
# via Application
project = app.decode_project(only_manifest=True)
rebuilt = app.rebuild(sign=True, no_res=True)

Legacy entry point

Scripts that used AnalyzeAPK in older Androguard versions can keep the same call pattern; the third return value is now a full Application instead of a cross-reference Analysis object (not yet restored in v5):

from androguard.misc import AnalyzeAPK

apk_obj, dex_list, app = AnalyzeAPK("my.apk")
print(app.summary())

Documentation

Documentation contains outdated information — in progress of updating

The Github Pages Documentation is the most up to date source.

Additional documentation that contains outdated information is available at ReadTheDocs.

Authors: Androguard Team

Androguard + tools: Anthony Desnos (anthony at 42.bzh).

Projects using Androguard

In alphabetical order:

  • AndroPyTool
  • AppKnox
  • Cuckoo Sandbox
  • Deckard
  • Droidbot
  • Droidstatx
  • εxodus
  • F-Droid Server
  • gplaycli
  • Koodous
  • MobSF
  • qiew
  • Quark-Engine
  • Virustotal
  • Viper Framework
  • ... and many more!

You are using Androguard and are not listed here? Just create a ticket or send us a pull request with your project!

Licenses

Androguard

Copyright (C) 2012 - 2026, Anthony Desnos (anthony at 42.bzh) All rights reserved.

Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at

 http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS-IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.

Press Escape to close the search panel.

Donate

Buy me a Coffee

Penetration Testing Services

penetration Testing Services

Web Application Security Quiz

Web Application Security Quiz

Daily Bug Bounty Writeups - Twitter

Daily Bug Bounty Writeups

Download our Latest Android Application

Guide for Penetration Testing

Daily Bug Bounty Writeups - Telegram

Daily Bug Bounty Writeups

Author

Piyush
Senior Product Security Engineer

Ethical Hacker || Penetration Tester || Gamer || Blogger || Product Security Engineer || AI Security

READ ARTICLE

Donate

Buy me a Coffee

Recent Posts

  • AI-Generated Code Security Bugs: A Vibe Coding Case Study
    AI-Generated Code Security Bugs: A Vibe Coding Case Study
    October 7, 2026/
    0 Comments
  • Cloud Misconfig Bounty Hunting in 2026: Open Buckets, Firebase, and Secrets
    Cloud Misconfig Bounty Hunting in 2026: Open Buckets, Firebase, and Secrets
    September 8, 2026/
    0 Comments
  • DevSecOps From Laptop to Production: A Practical Security Pipeline Guide
    DevSecOps From Laptop to Production: A Practical Security Pipeline Guide
    August 27, 2026/
    0 Comments

Follow Us

SecurityCipher

Practical security guides, vulnerability deep-dives, and hands-on resources for bug bounty hunters and penetration testers.

Useful Links

  • Security Checklists
  • Cybersecurity Jobs
  • Blogs
  • About
  • Contact
© 2026 Security Cipher. All rights reserved. Privacy Policy · Terms & Conditions