Contents
No source yetSelect a method — or open All methods and click a method header / Open CFG
.so from Native or FilesNo source yetSelect an ARM64 function to decompile
Manifest (APK) or XML (AXML)
Semgrep rules
Edit Semgrep-style YAML below (Java/XML patterns + optional native: SSA hints). Default builtin is All (starter + OWASP MASTG). Findings link to matching MASTG-KNOW articles. Applied rules are included in Scan and stored in localStorage.
Findings
Decode an APK to an editable project (dex-txt / manifest / res / apkpatch.yml), edit with syntax highlighting, rebuild and sign in the browser. dex-txt is assembled from scratch. Host aapt2 is unavailable — keep original resources.arsc or enable pure-Rust rebuild. Use the Device tab to install and debug on a phone.
- 1 Connect
- 2 Pick app
- 3 Attach
- 4 Script / trace
WebUSB ADB · Chrome/Edge · quit host adb first. Flow: connect → select package → Attach agent → ScriptLoad / Rpc / Post. The Contents panel on the left mirrors the phone while the console stays live — click it to start. Syscall trace needs root (detaches the agent).
Target
Not attachedIf the APK already embeds the goauld agent: connect → (install/launch) → Attach agent. Stock apps need Live inject (root) first.
Stock apps without an embedded agent (Calculator, …): inject first, then Attach. Needs Magisk/su.
Binary overrides (optional)
Bundled arm64 goauld binaries are used by default.
Quick trace
For apps that already include the goauld agent. Interact with the app on the phone while tracing.
Auto-attach → ART invoke stubs → collect android-api events.
Detaches agent stream, pushes injector, runs PTRACE_SYSCALL (Magisk/su).
Script & protocol
Attach agent firstSame WebUSB session as the Device tab. Quit host adb first. Detach the goauld agent before Start — one ADB stream at a time. Click the picture to type; Ctrl-V pastes. PNG saves the current frame; GIF and MP4 record until you click them again.