Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
apk-reverse — مهارة وكيل لهندسة عكس تطبيقات Android APK: تعديل dex، وفك الحزم، وإعادة تجميعها، وإزالة الإعلانات والجدران المدفوعة، وتحليل ملفات .so الأصلية، والقياس الآلي أثناء التشغيل باستخدام Frida. | Kitploit
أدوات/GitHubGitHub/newliver666/apk-reverse
أمان أندرويدالتحليل الثابتالتحليل الديناميكي (عزل)تحليل الكوداختبار اختراق تطبيقات الجوالالهندسة العكسيةالبرمجة النصية والأتمتةتحليل البرمجيات الخبيثةأمن الجوالتحليل الملفات الثنائيةالتعلم والتعليم
1.4k3792منذ يوم واحدلم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
GitHub
newliver666/apk-reverse

apk-reverse

مهارة وكيل لهندسة عكس تطبيقات Android APK: تعديل dex، وفك الحزم، وإعادة تجميعها، وإزالة الإعلانات والجدران المدفوعة، وتحليل ملفات .so الأصلية، والقياس الآلي أثناء التشغيل باستخدام Frida.

عرض المستودع

apk-reverse

English · 简体中文

stars forks license python android ci

القدرات · البنية · التثبيت · المتطلبات · فهرس الأخطاء · النطاق · الصيانة · إخلاء المسؤولية

apk-reverse

مهارة وكيل (Agent Skill) لهندسة عكس تطبيقات Android APK، وإزالة الحشو، وإزالة الإعلانات، وترقيع dex الجراحي، وإعادة التغليف، وتحليل وقت التشغيل/الخادم.

إنها مهارة، وليست درسًا تعليميًا: كُتبت ليحمّلها وكيل (Claude Code أو Codex أو أي إطار يدعم صيغة Agent Skills) أثناء عمله، لذا فهي منظّمة للإفصاح التدريجي — ملف SKILL.md قصير موجّه نحو القرار، ومراجع مفصّلة تُحمَّل فقط عندما تحتاجها خطوة ما، وسكربتات ذات معاملات يمكنك تشغيلها مباشرة.

كيف يُتوقَّع من الوكيل أن يستهلك هذا

كُتب SKILL.md عمدًا كـإجراء ذي بوابات لا كنصيحة، لأن نمط الفشل الملاحَظ ليس الجهل — بل نموذج يقرأ كل شيء، ويوافق عليه، ثم يستنتج من المبادئ الأولى على أي حال.

لذا هناك أربعة أشياء في المتن يُقصد بها أن يُعمَل بها، لا أن تُقرأ فقط:

  • أربع قواعد تجاوز (R1–R4). حيث تتعارض مع الخطة الحالية، فهي تفوز حتى تُبطلها الأدلة.
  • فهرس الأعراض. كل صف هو فشل دُفع ثمنه بالفعل. الصف المطابق إشارة توقف: حمّل ذلك الملف قبل تشغيل أمر آخر، لا بعد بضع محاولات إضافية. الاستنتاج متجاوزًا عرَضًا معروفًا هو كيف تُهدر الساعات نفسها مرتين.
  • أربع بوابات (G1–G4)، كل منها إجراء له معيار نجاح. "أفهم الفكرة" لا يجتاز بوابة. وُجدت لكي يحدث التصنيف وحقيقة البيئة وبناء الضابط قبل الترقيع الأول، لا بعد الفشل الثالث.
  • قاعدة الضربتين وشروط التوقف. فشلان من الشكل نفسه يعنيان أن النموذج مخطئ، لا المعاملات. أما المتغير الثالث لفرضية فشلت مرتين بالفعل فهو حيث تذهب الجولات لتموت.

وشيء واحد في النهاية يُقصد به أن يُحجَب: "تم" له تعريف (ستة بنود). وسجل نظيف ليس أحدها. أي شيء أقل من الستة كلها هو نقطة تحقق، وينبغي الإبلاغ عنه كنقطة تحقق مع ما تبقّى.

إن كنت وكيلًا تقرأ هذا: أرخص أمر أول ممكن هو python skills/apk-reverse/scripts/doctor.py. يخبرك أي من هذه الأدوات موجود هنا، وأي السكربتات يمكنها العمل فعلًا، وما إذا كان شيء في البيئة يسمّم قياساتك بالفعل.

ما تجيده

  • تقرير بسرعة ما إذا كان الطلب قابلًا للتحقيق أصلًا من جهة العميل، بدلًا من إهدار ساعات على جدار دفع يفرضه خادم.
  • تقرير الشكل الذي يجب أن يتخذه المُسلَّم قبل بدء أي عمل — فمخرَج مكتفٍ بذاته وغير مُجذَّر مشكلة مختلفة عن "اجعله يعمل على هذا الجهاز"، والخلط بين الاثنين هو أغلى انحراف في هذا المجال.
  • اختيار أكثر طبقة ترقيع أمانًا لتغيير معيّن، وتجنّب الطبقات التي تكسر التطبيق.
  • التقاط فشل إعادة التغليف الذي يبدو كنجاح: تطبيق يُثبَّت ويُشغَّل ويُعرض بشكل مثالي بينما يُرفض كل طلب موقَّع، لأن العميل يستمد مفتاح توقيع طلباته من شهادة توقيعه الخاصة.
  • الفصل بين أخطائك أنت ومشكلات التطبيق أو الخادم — فالفشل المحصور بميزة (تسجيل الدخول، التسجيل، الدفع) غالبًا مشكلة TLS/شهادة في مسار برمجي واحد، لا نتيجة للترقيع الذي بنيته للتو. وحالة الجهاز، وخادم جهاز ميت، وانحراف الساعة تتنكّر بالشكل نفسه.
  • إثبات أي معمارية وأي مكتبة تُنفَّذ فعلًا، بدلًا من الثقة بما يورده المانيفست أو بما يدّعيه الجهاز.
  • العمل عبر أهداف محزومة/محصّنة: تحديد الحازم (packer)، وفك الحزم، وتحويل تفريغ ذاكرة إلى APK مرقَّع قابل للتثبيت.
  • التعامل مع مكتبة محصّنة تُنهي العملية عن قصد — بما في ذلك شكل الانهيار المتعمَّد (fault addr 0x4) الذي يبدو تمامًا كخطأ إلغاء مرجع فارغ عادي، وقاعدة "عطّله، لكن ليس أبدًا بجعله لا يعود" التي تحدد ما إذا كان الإصلاح ينجح أم يجمّد التطبيق كله بطريقة لا تشبه السبب إطلاقًا.
  • معرفة أي الأدوات يُستعان بها وأين تكذب كل واحدة — بما في ذلك تلك التي توجد فقط كواجهة رسومية، فتطلب إنسانًا بدلًا من استبدال طريقة أضعف بصمت.
  • جعل البناء المرقَّع يبقى مرقَّعًا: تعطيل فحوص الإصدار، وحوارات الترقية القسرية، ومثبّتات التحديث الذاتي بحيث لا يمكن إيقاف العمل عن بُعد — والتعرّف على قناة التحديث الساخن/الإعدادات عن بُعد التي قد تلغيه بهدوء دون أي تغيير في الإصدار.
  • الفصل بين بوابة تسجيل دخول من جهة العميل (قابلة للترقيع) ومورد محصور بالحساب (فارغ لأن الخادم لا يملك ما يجيب به)، ومعرفة أن تزوير جلسة يُنتج حالة أسوأ من كونك مسجَّلًا خارج الحساب.
  • إبقاء مهمة طويلة صادقة: سجل حيّ، واستنتاجات مُقيَّمة، ومهلات معايَرة، وانتظارات محدودة، بحيث لا يُفقد التقدم ولا يُرتكب الخطأ نفسه مرتين.
  • تجنّب الأخطاء المحددة التي تُنتج APK يُبنى بشكل مثالي ويموت في وقت التشغيل.
  • تقرير ما ينبغي أن يكون المُسلَّم عندما لا يكون APK خيارًا — فإعادة تغليف ترفضها عدة فحوص مستقلة هي محجوبة، لا مكلفة، وسلّم البدائل هو وحدة على مستوى النظام، أو خدمة RPC محلية، أو تقرير صادق بحدود معلنة.

البنية

SKILL.md وreferences/ وscripts/ كلها داخل دليل المهارة، skills/apk-reverse/. وكل ما في جذر المستودع هو أدوات صيانة مشتركة بين المهارات، وليس جزءًا من مهارة مثبَّتة.``` SKILL.md a procedure with gates, not background reading: how-to-use -> four override rules (R1-R4) symptom index (a matching row is a stop signal) four gates (G1-G4, actions with pass criteria) thirteen classification questions the workflow, with a per-step skip condition and a two-strike rule what "done" means -> stop conditions -> constraints -> indexes references/ loaded on demand, one topic each recon.md identify packer, SDKs, code location, tamper checks; unpacking server-config-and-updates.md the most common shape of "ad" and the one usually mis-diagnosed: the server supplies UI the client renders (launch screen, popup, announcement, tab set). The two-layer fetch that proves it, how to find the config DTOs by the field names data classes keep, why you patch the decision and not the data, deciding the scope of "remove", and remote re-enable / cached config durability byte-level-patching.md equal-length byte edits: why they beat method rebuilding (measured), locating an instruction's exact offset without scraping listings, the instruction width traps that desynchronise a decode, neutralise a branch vs redirect it, dex header integrity field order, and the verifier's move-result rule packers.md hardened targets: rejection signals, measuring the validation boundary with single-variable tests, choosing a native host code-virtualization-and-custom-linkers.md the layer between "packed" and "clean": whole classes turned into native declarations, a private loader whose SONAME does not match its filename, an embedded self-decrypting payload, a Java-layer "signature killer" that logs success while a native check kills you. The keep-it/drop-it deadlock, how to separate the checker from the implementation, and the string-redirect technique that ends it without neutralizing anything framework-runtimes.md Flutter / React Native / Unity: which layer owns the UI, and how to find logic when there are no symbols (string encoding traps) dart-aot.md Dart AOT in depth: version pinning and building a matching decompiler, the object pool and reference indexes, register/boolean conventions, the three signatures that identify business logic, locating, patching. Begins with the snapshot-decoding front end it depends on (aotopsy or blutter) because the pool listing is an input, not something this skill produces itself native-and-so.md .so hosts, DT_NEEDED vs JNI_OnLoad, relocation limits, relocation-free bootstrapping, replacing Java methods natively, and which ABI/library is native-tamper-and-suicide.md how a hardened library kills its own process: the visible mechanisms, how to tell which one actually fires, how to find the site, forged section headers, function boundaries from PT_GNU_EH_FRAME, scanner traps, and neutralising safely detection-and-anti-analysis.md when the app fights back or the tool cannot run here: telling detection apart from a broken environment, deciding by cost instead of escalating, recognising an environment where dynamic analysis simply does not work, and keeping the "blocks my analysis" question separate from "blocks the deliverable" toolchain.md what to install, how to invoke it non-interactively, which tools are GUI-only, version-alignment traps, working offline, , and which signer to use long-task-discipline.md live record, conclusion grading, drift control, timeout and wait calibration, deliverable-form drift, captures-you-never-looked-at, long-context decay, handover ad-removal.md ad taxonomy, wrapper mapping, callback trap, global gates, verification updates-and-forced-upgrade.md keeping a patched build alive: locating the version check, the two-layer patch (no-op the routine, neutralise the comparison), what not to touch (manifest version, installer permission, host blocking), self-update and hot-update/remote-config channels, verifying that no version request is issued at all account-gates.md sign-in walls, forced phone binding, guest mode: telling a client-side gate (patchable) apart from an account-scoped resource (not), why fabricating a session is worse than staying signed out, and the unavoidable session loss after a reinstall signature-derived-keys.md when the app's own signing certificate is used as key material: detection greps, why offline extraction is unreliable, the hardcode-then-verify procedure membership-and-limits.md server vs client authority; what is and is not patchable server-api.md probe an app's API; prove who owns the gate tls-and-cert.md feature-scoped network failures: expired certs, dual trust chains third-party-builds.md auditing a "cracked"/"modded" APK before trusting it dex-patching.md patch-layer table + dexlib2 technique in depth patch-audit.md proving a patch and is : length-vs-bytes comparison, the equal-length-replacement blind spot, verifier-level legality (move-result adjacency) checked statically, text-matching patch traps, and reporting a missing patch repack-and-sign.md repack rules, unpack-and-repack, signing, post-install hazards runtime-data.md DataStore / SharedPreferences / SQLite / protobuf; when the app rewrites your edit, and decoding a value that looks encrypted dynamic-frida.md Frida setup, version pinning, the four-layer probe, hook strategy environment.md device/emulator setup, root, ADB, offline devices, log signals, emulator console control and recovery, preflight, look-at-the-screen verification.md the claim ladder; what "done" means desensitization-and-leak-scans.md publishing discipline: what must be desensitized and what must stay, the do-not-anonymize list, the leak scanner and its exit states, and the entry-point file as a prompt surface precedents/ the positive case library: route including dead ends, a grade per assertion, measured pit-falls, and the write-back checklist routing.md the on-demand inventory: every reference with when to load it, every script with what it does, and a mirror of the symptom index rasc-and-droidsaw.md the Rust re-implementation of the ASC indexer: measured speedup and identical class sets, the enum shape where it silently drops bodies, and how to build and verify it evidence-summary.md the condensation that ships with the skill: capability, one-line conclusion, strength, and the evidence you can actually open in an installed copy

../evals/ NOT a spec directory either, but the location the Agent Skills guidance recommends: evals.json holds the with-skill / without-skill cases this skill has not run, with the method for running them written into the file ../evidence/ NOT a spec directory: the machine-readable companions to the evidence summary reference above -- capability-matrix.json (the same rows with more fields), tested-tool-versions.json (versions and the probe behind each), known-limitations.md (the installer-facing limit list). Shipped inside the skill so an installed copy can answer "was this verified, and how strongly" without the repository pitfalls.md the failure catalogue -- read before building advanced-unpacking.md the dump landed but the bodies are empty: extraction-shell diagnosis by trivial-body ratio, FART-style active invocation and why its classic hooks died on Android 12-16, code_item splicing, the root-side dump for when frida itself is refused, and the honest VMP boundary lsposed-and-modules.md the repack is refused, so deliver a system-level hook module instead: module anatomy, a gradle-free build chain, scope configuration and how to verify injection, and the layer a Java module cannot reach emulation-and-rpc.md call the routine instead of reading it: Unidbg/Unicorn emulation and its environment-filling cost, versus service-ifying a live function over Frida RPC native-dbi-and-deobfuscation.md OLLVM shapes, Frida-Stalker traces, the trace-to-CFG route, the Stalker/QBDI/emulation decision, and two measured boundaries (a follow that delivers no events, and a crash from following a hot libc export) protocol-reverse.md protobuf without a schema, schema recovery from decompiled code, gRPC frame capture, the QUIC/HTTP3 limit, and native-side certificate pinning kernel-and-environment-hardening.md userspace hooking provably cannot reach the check: raw svc, init_array-early detection, what each root scheme hides, the kernel-route map with its version gate, and when to stop escalating on-device-tooling.md working from the phone itself: MT Manager edit/repack/sign and its APK MCP, LSPosed Manager, Termux+frida, on-device data inspection java2c-and-jni-sinking.md Java2C and JNI sinking, the two hardening shapes most easily confused with an extraction shell: the table that separates landing shell / extraction shell / VMP / Java2C / JNI sinking, why the code is in the and in a dumped dex, and why a symbol search comes back empty (dynamic registration, ) split-apk.md App Bundle / split APK sets: what the set is, pulling it off a device, merging into one APK vs signing the set as a unit, the install refusals and what each means, and making an installable fixture from a pulled set vmp-differential-analysis.md the known-plaintext differential for a real Dex VMP: which links can be automated and which cannot (the upload is the bottleneck), the coverage a compiled fixture can reach, how to a derived private-opcode table, smali generation, and when the route is closed coverage-and-limits.md the claim ladder applied to the skill itself: the evidence behind each covered item, the dependencies this skill does not ship, and what was never exercised handoff-boundaries.md where this skill ends and another discipline begins: the JNI form table, the packer-versus-loader split, and what "verified" means for each of the four deliverable forms scripts/ parameterized, path-agnostic doctor.py run this first: capability report + per-script runnability, finds tools installed off-PATH or as runnable jars, and surfaces the environment facts that poison experiments (clock skew, leftover adb forward / proxy, a device-side frida process already running) dexutil.py dependency-free dex reader: structural walk + exact instruction decode, dex header recompute/verify (correct checksum/signature order), branch-target and operand helpers. Library shared by the dex scripts, also runs standalone to dump one method with offsets dex_find_insn.py locate an instruction by decoded semantics and print its exact byte offset with context and both sides of any branch -- how you find a patch site instead of guessing offsets dex_patch_bytes.py equal-length byte patches from a JSON spec: semantic match, polarity pin via expect_next, equal-length enforcement, verifier check, dex header recompute, re-decode to prove it landed (--dry-run first) dex_check_verifier.py tier-3 check: does any conditional branch target a move-result (bypassing its producer)? Compares two builds and separates pre-existing findings from regressions your patch introduced coldstart.py cold-launch capture: timed screenshot burst + logcat signals + installed-build facts + launch timing, and warns when the foreground activity is not your app so_constpatch.py same-length in-place rewrite of an isolated string constant, for redirecting a library load instead of defeating a check smtool.py baksmali/smali wrapper with a configurable classpath dexpatch/ dexlib2 method-level rewriter (for changes that need new instructions) patch_smali.py method-body replacement in a smali tree dex_strpatch.py byte-level string patch with a string_ids ordering guard dex_classdiff.py prove a dex edit was surgical dex_strings.py strings/URLs/SDK markers without a decompiler dart_pool_strings.py recover literals from a Dart AOT snapshot (framed entries, the one-byte vs UTF-16 split, file offsets, run-length noise filter) dart_pprefs.py build/query the object-pool -> code-site index for a Dart snapshot dart_disasm.py annotated windowed disassembly of Dart AOT code + B/BL caller index find_refs.py count callers of a method before patching it repack.py rebuild APK, strip only signatures, keep META-INF/services/, write a 4-byte-aligned archive (resources.arsc STORED+aligned), sign, verify; also split APK / App Bundle sets: inventory, sign every member with one keystore, or merge code/native members into a standalone APK devsh.py quoting-safe ADB shell helper usb_net_proxy.py give an offline device network over USB datastore_inject.py encode/inject AndroidX DataStore preferences safely probe_api.py probe an HTTP API with the right headers grab_crash.py recover stacks hidden by a crash-reporter SDK install_test.py install + launch health check with logcat signal scan frida_probe.js four-layer runtime probe (app net layer + OkHttp + java.net + exceptions) run_probe.py inject the probe, stream it to a log file, stay resident tls_check.py strict certificate check for one or more hosts preflight.py environment check before every experiment block (device, root, ABI/translation, clock skew, leftover proxy/forwards, dead server) lib_map.py what is into a live process: per-library path, base, architecture, and whether it came from the APK or was materialized at runtime elf_plt.py resolve a PLT stub to its imported symbol (x86_64 + aarch64) from the relocation table; list a symbol's callers; byte-diff two libraries and name the symbol each changed stub belongs to apk_diff.py entry-level diff of two builds: changed / added / removed, by content hash so same-size replacements are caught native_crash.py locate a native death from a log or tombstone: signal, fault address, registers, frames split app vs system, the faulting instruction, and a flag when the fault looks blob_decode.py search, don't guess, the framing of a stored value (base64/hex x rotation x deflate); re-encode the edited payload snap.py bounded burst screenshots + control-tree capture with a stall detector, and a verdict on whether the tree is usable at all sig_probe.py find the exact signatures[0].toCharsString() value — offline candidates from an APK, or the authoritative read from a device spawn_patch_detach.py spawn under a Frida probe, detach, then launch and capture: under spawn mode the Activity stack often never comes up, and memory writes survive detach while hooks do not hook_patch_only.js the minimal probe for spawn_patch_detach.py — neutralise one native death site by offset and report PATCHED dex_dump_validate.py dedupe, validate and rank a directory of dumped dex images: sha256 grouping, header integrity, the trivial-body ratio that separates a real dump from an extraction-shell skeleton, and a most-likely-original ranking (--trim for page-aligned /proc//mem captures) dex_mem_scan.py search memory captures for embedded dex images and extract each at the size its own header declares -- for a decrypted dex sitting in an anonymous mapping no maps entry names lsposed_scaffold.py generate a minimal LSPosed/Xposed module project (manifest with the xposed meta-data, assets/xposed_init, hook class, gradle-free build notes) frida_rpc_serve.py bridge a Frida script's rpc.exports to a local caller with reconnect handling, so a live native function can be called rather than reversed rpc_template.js the editable companion to frida_rpc_serve.py stalker_trace.js instruction-level tracing with Frida Stalker: configurable targets, trigger selection, the event stream, and output-size rules stalker_report.py reduce a stalker_trace.js log to block histograms and call sequences, with an explicit diagnostic for the measured zero-event case mt_mcp_probe.py probe MT Manager's on-device APK MCP (Streamable HTTP, port 8787): JSON-RPC handshake plus the grouped tool inventory java2c_probe.py collect the evidence that separates Java2C from an extraction shell, a VMP and ordinary JNI sinking: native density and stub ratio from the dex, JNI_OnLoad / dynamic registration / toolchain strings from the , each item labelled strong/medium/weak protobuf_decode_raw.py schema-free protobuf decode: hex / file / stdin to a JSON tree, every length-delimited field kept as a candidate set with ties labelled rather than guessed, plus a byte-exact re-encode to check a round trip vmp_diff_harness.py build a labelled opcode-coverage fixture, derive a candidate private- opcode map from an original/hardened dex pair, verify the comparison in a closed loop, and render a restored stream as a smali skeleton kernelsu_syscall_mask.py generate a KernelSU/APatch syscall-masking scaffold: an installable userspace module skeleton plus KPM/LKM/eBPF kernel-side templates, each with its version gate and an explicit unverified label rasc_build.py build and verify rasc, the Rust ASC re-implementation: --check what is present, --build clone plus cargo, --verify an APK against droidasc and fail on any class-set difference scan_leaks.py scan a repository for target identity before publishing it: bundle ids in manifest / / contexts, serial-shaped tokens, PATs, inline appkey assignments, literal endpoints, host user paths. Exemptions for everything that must stay (tools, libraries, CVEs, hardening products, public crackmes, placeholders), findings carry their context, prints why a hit was suppressed, exit 0/1/2 svc_scan.py name the syscall behind an inline and the segment it sits in, which decides whether a libc-level hook can observe the call at all; shows neighbours because a byte scan also matches data anti_detect_probe.js observer-only Frida probe (patches nothing): path/loader/thread/kill hooks with caller module + offset, an environment self-report (, frida-named mappings), and live streaming so a sub-second self-destructing target still yields evidence

root@kitploit:~
يحتوي المستودع أيضًا على طبقة اختبار **قابلة للتنفيذ**، وهي شيء مختلف عن سجل الأدلة: يؤكد `tests/` على ما تفعله السكربتات (اختبار الوحدة، عقد CLI، التكامل بدون جهاز) ويسجّل `tests/benchmark.md` ما فعله مسار على هدف حقيقي. يوضّح `tests/README.md` هذا التقسيم، ويشغّل `.github/workflows/ci.yml` البوابات بالإضافة إلى مجموعة الاختبارات.

## التثبيت

هذا المستودع هو **مستودع مهارات**: توجد المهارة في `skills/apk-reverse/`، وهو التخطيط الذي يحلّه `skills` CLI، ويتم تثبيتها بالاسم بدلاً من نسخ دليل:```
npx skills add newliver666/apk-reverse              # install every skill in the repo
npx skills add newliver666/apk-reverse --list       # list what is here, install nothing
npx skills add newliver666/apk-reverse --skill apk-reverse -y
npx skills use  newliver666/apk-reverse@apk-reverse # use it once, without installing

يقوم CLI بإنشاء روابط رمزية للمهارة داخل دليل مهارات الوكيل افتراضيًا (--copy يجعلها نسخًا مستقلة بدلًا من ذلك)، و-g يثبّتها لكل مشروع بدلًا من المشروع الحالي. مع وجود مهارة واحدة في المستودع، فإن --skill apk-reverse زائد عن الحاجة اليوم؛ وقد كُتب هنا صراحةً لأنه هو ما يحدّد مهارة واحدة بمجرد وجود مهارة ثانية.

بعد التثبيت، يحمّل الوكيل SKILL.md عندما تطابق مهمةٌ وصفَه، ويستدعي references/* عند الحاجة فقط. لا حالة عامة، ولا مسارات خاصة بالجهاز، ولا خطوة بناء.

المتطلبات

لا شيء إلزامي؛ كل سكربت يتحقق مما يحتاجه. يوضّح skills/apk-reverse/scripts/doctor.py أيًّا من هذه موجود هنا، وبالتالي أي السكربتات يمكن تشغيلها، ومفيدًا — أي الأدوات موجودة في مكان آخر غير PATH.

إذا كانت سلسلة أدواتك خارج PATH (دليل tools/ محلي في المشروع، أو مجلد SDK بإصدار محدد، أو ملف .jar قابل للتشغيل بدلًا من أمر)، فاضبط APKREV_TOOLS على دليل واحد أو أكثر وسيجدها doctor.py:``` set APKREV_TOOLS=

; # Windows, e.g. an SDK or project-local tools dir export APKREV_TOOLS=: # POSIX

root@kitploit:~
السكربتات نفسها هي `python3` عادي ويُقصد بها أن تعمل بشكل متطابق على Windows وmacOS و
Linux؛ وحيثما يكون المقطع خاصًا بـ POSIX فقط يُوسَم بذلك. لا شيء هنا يفترض وجود صدفة Unix.

| الأداة | تُستخدم لـ |
|---|---|
| Python 3.9+ | جميع السكربتات |
| **`droidasc`** (ASC) (**اختياري لكنه موصى به بشدة — ثبّته أولًا**) | فهرس الإسناد المرجعي لكامل الـ APK: `findrefs` / `listclass` / `getclass` / `getmanifest`. أمر `pip install droidasc` واحد، بلا JVM، بلا SDK، بلا بناء فهرس. يحوّل سؤال "أي من آلاف الفئات N يذكر هذه السلسلة" إلى استعلام في أقل من ثانية، وهو المسار الوحيد إلى فئة شوّه R8 اسمها. **هذه هي الأداة التي ينبغي للوكيل أن يلجأ إليها قبل أي تفكيك كامل** — انظر `skills/apk-reverse/references/toolchain.md` §droidasc (ASC) — اسأل APK "من يشير إلى هذا؟"، في استعلام واحد |
| `ddc` (اختياري لكنه موصى به بشدة) | مفكّك dex→Java ثنائي واحد مع أوامر فرعية للاستعلام (`info`، `findrefs`، `strings --with-locations`، تفكيك لكل فئة). بلا JVM. **يقرأ** ما **يحدده** ASC؛ كما يبلّغ عن هوية الحزمة بشكل موثوق — انظر `skills/apk-reverse/references/toolchain.md` §ddc — dex-to-Java مع أوامر فرعية للاستعلام (يستحق التبنّي) |
| `baksmali` / `smali` + jars الخاصة بـ `dexlib2` | التفكيك، التجميع، الترقيع الجراحي |
| JDK (`javac`، `java`) | بناء/تشغيل مُرقّع dexlib2؛ كما يوفّر `keytool`/`jarsigner` |
| Android SDK build-tools (`aapt`، `zipalign`، `apksigner`) | معلومات الـ manifest، المحاذاة، التوقيع. **`apksigner` هو الموقّع الذي يجب استخدامه** — `jarsigner` يعيد كتابة الأرشيف ويكسر المحاذاة التي يتطلبها Android R+ |
| `uber-apk-signer` (اختياري) | محاذاة + توقيع بخطوة واحدة |
| ADB | العمل على الجهاز |
| Frida (حزمة المضيف + خادم مطابق على الجهاز) | التحليل الديناميكي |
| جهاز مروّت أو محاكي | أي شيء يتجاوز التحليل الساكن |

لا يحتاج أي من هذه إلى أن يكون على `PATH`: كل سكربت يقبل مسارًا صريحًا للأدوات التي
يستدعيها، ويغطي `skills/apk-reverse/references/toolchain.md` كيفية العثور
على تثبيت لا يعرفه `PATH` (الحالة الشائعة لـ `apksigner` و
`keytool`).

## اقرأ هذا أولًا

**هذا المشروع منشور للتعلّم والبحث واختبار الأمان المصرّح به فقط.** لا يشحن
أي حِمل استغلال، ولا بيانات أهداف، ولا ثنائيات طرف ثالث — إنه منهجية، ومجموعة سكربتات
وسجل أدلة. أنت مسؤول عن امتلاك الحق في تحليل أي شيء توجّهه إليه؛
انظر **إخلاء المسؤولية** في نهاية هذا الملف.

`skills/apk-reverse/references/pitfalls.md`. إنه الملف الأكثر قيمة هنا — كل مدخل فيه هو
فشل أنتج أثرًا معطوبًا بينما كان يبدو سليمًا تمامًا.

الأربعة الأكثر إيلامًا:

1. تجريد كامل `META-INF/` أثناء إعادة التغليف يحذف تسجيلات ServiceLoader
   فيموت التطبيق عند بدء التشغيل بخطأ يسمّي مكتبة غير ذات صلة.
2. ترقيع سلسلة على مستوى البايت دون الحفاظ على ترتيب `string_ids` يؤدي إلى رفض
   الـ dex بأكمله، بينما تتحقق المجاميع الاختبارية والتواقيع بشكل مثالي.
3. إعادة بناء dex بدورة smali كاملة الشجرة يُلحق ضررًا غير مرئي بمخرجات R8 —
   تبدو جداول الفئات نظيفة عند المقارنة، ولا ينفجر الأمر إلا في وقت التشغيل.
4. تحييد مسار إنهاء أصلي بجعله **لا يعود**. كتلة دوّارة لا
   تكبت الفحص؛ بل تجمّد المستدعي وكل خيط خلفه. يتعلّق التطبيق *بلا
   سجل انهيار على الإطلاق*، ويُنسب الموت النهائي إلى أي شيء قتل العملية المجمّدة.

## النطاق

مبني للعمل على تطبيقاتك الخاصة، وعلى عينات مصرّح لك بتحليلها،
وفي بيئات CTF/المسابقات المعزولة. لا يحتوي على أي ثنائيات طرف ثالث مُضمّنة ولا
بيانات خاصة بأهداف.

ما يغطيه، وما لا يغطيه عمدًا، مذكور في أعلى `SKILL.md`
تحت **التغطية**. النسخة المختصرة: Android فقط (لا iOS)، وعمق في الطبقات
التي جرى العمل عليها فعليًا — ترقيع dex، إعادة التغليف، الحزم والمحمّلات المخصصة،
استجابة التلاعب الأصلية، وFlutter/Dart AOT. أضافت جولة توسعة طبقة ثانية
من المسارات الموثّقة: **التسليم من جانب الوحدة** عندما تُحظر إعادة التغليف،
**استعادة غلاف الاستخراج** وحدوده مع VMP، **المحاكاة وRPC الحيّ** للاستدعاء
بدلًا من القراءة، **التتبع على مستوى التعليمات** ضد OLLVM، **عكس البروتوكولات**
بما يتجاوز REST، خريطة **المسار من جانب النواة** عندما يكون ربط مساحة المستخدم
خارج المتناول بشكل مُثبت، و**أدوات على الجهاز**. ثم وضعت **جولة معيارية** أهدافًا عامة
تحت تلك المسارات (`tests/benchmark.md`): أضافت **تمييز Java2C** (التشخيص الخاطئ
الذي يدفع الوكيل للبحث عن DEX مفكوك لا وجود له أصلًا)، **التعامل مع APK المجزّأ /
App Bundle**، **فك ترميز protobuf بلا مخطط**، منصة **تفاضلية Dex-VMP**،
و**قوالب وحدات النواة مع بوابات إصداراتها** — وصحّحت ادّعاءين سابقين
خالفت قياساتهما ما جاء فيهما. استعادة منطق Unity/IL2CPP،
وداخليات React Native/Hermes bytecode، وهزيمة سلطة من جانب الخادم **غير**
مغطاة، والسِّكِل مكتوب ليقول ذلك ويتوقف بدلًا من تطبيق أقرب
إجراء موثّق على هدف لم يُكتب من أجله.

أربعة تحفظات يذكرها قسم التغطية بالكامل وتنتمي إلى هنا أيضًا:

- **تحليل Flutter/Dart AOT له تبعية.** يبدأ سير العمل من إدراج مجمّع
  (مخرجات من فئة `pp.txt`). يتطلب إنتاج ذلك مفكّكًا لفك ترميز اللقطة — aotopsy (ثنائي
  ساكن، بلا سلسلة أدوات) أو blutter (يُبنى من المصدر، ~80 ثانية) — وهذا المستودع لا يحتوي
  على أحدهما. إنه مذكور كمتطلب مسبق بدلًا من تركه ضمنيًا.
- **ليست كل ادّعاءات هذا المستودع لها تشغيل خلفها.** يسجّل `docs/tool-verification/`
  ما جرى قياسه فعليًا، وعلى أي هدف، وبأي تحقق متقاطع مستقل؛ وأي شيء غير
  مغطى هناك موثّق من الخبرة وينبغي قراءته على أنه *مُستنتَج*، وفق سلّم
  الادّعاءات الخاص بهذا السِّكِل نفسه.
- **جولة التوسعة مسجّلة بشكل منفصل وهي في معظمها *مُستنتَجة*.** أدلتها في
  `docs/tool-verification/EXTENSION-*.md`، ملف واحد لكل موضوع، مع ملاحظة قوتها
  الخاصة. الشكل الشائع هناك هو *قيسَت الأداة، ولم يُقَس المسار* — لذا اقرأ تلك
  الملفات قبل التعامل مع أي من الوثائق الأحدث كمسار مُتحقَّق منه.
- **الجولة المعيارية مسجّلة صفًا بصف، بقوة كل صف الخاصة به.** يسمّي `tests/benchmark.md`
  كل هدف عام، والسكربتات التي يمارسها الصف، وما حدث فعليًا (بما في ذلك
  الصفوف التي فشلت والصفوف التي لم يشغّلها أحد)، ومدى قوة الأدلة. الصفوف المعلّمة
  `unverified` هي عبارات عن الأدلة في هذا المستودع، لا عن الآلية.

## صيانة المستودع

توجد أربع أدوات في الجذر وليست جزءًا من السِّكِل المثبَّت:```
check_repo.py      every skill discovered, frontmatter valid, scripts runnable,
                   documented paths resolve, README paths explicit and existing,
                   and -- on the tracked surface only -- no target identity
                   (delegates the rules to skills/apk-reverse/scripts/scan_leaks.py
                   so there is one place to argue with the exemption list)
check_refs.py      every cross-reference that names a section of another
                   document reaches a real heading in that document
check_routing.py   the on-demand inventory still matches the entry point: the
                   symptom mirror agrees with SKILL.md, every reference file is
                   named in skills/apk-reverse/references/routing.md, and every
                   script is too
check_commands.py  every command a document tells you to run is checked against
                   the script's own argparse table -- a documented flag that does
                   not exist is a drift the anchor checks cannot see
check_budget.py    keep the always-loaded part from creeping: SKILL.md's whole
                   body (index lines included, because they load too) measured in
                   lines and tokens, index-row length, long files with no
                   navigable head, and hedged rules reported as a trend
build_scripts.py   audit for machine-specific leftovers (absolute paths, credentials)

الاتساق له ضغط مضاد طبيعي -- المسار المعطوب يفشل بصوت عالٍ، ويقوم شخص ما بإصلاحه. الانتفاخ ليس له ذلك، ولهذا السبب توجد الأداة الثالثة: كل تمريرة تضيف مرجعًا وصفًا في الفهرس وادعاء تغطية، وبدون قياس لا يلاحظ أي شيء في المستودع ذلك.

يحتوي tests/benchmark.md على مصفوفة الانحدار: البُعد -> الهدف العام -> السكربتات التي يمارسها الصف -> النتيجة المقاسة -> تصنيف القوة. إنها قائمة التحقق التي يجب إعادة تشغيلها قبل الوثوق بأي ادعاء تحت docs/tool-verification/. يتم تنزيل العينات إلى tools/_work/ ولا يتم إيداعها أبدًا، لذا يذكر كل صف مصدره العام ويسجل التجزئة التي شُغّل مقابلها.

docs/tool-verification/ ليس جزءًا من المهارة المثبَّتة أيضًا. إنه سجل الأدلة لتمريرة قياس واحدة مقابل هدف حقيقي: ما فعله كل سكربت فعليًا، وأي طريقة مستقلة أكدته، وأي عيوب وُجدت، وأي سيناريوهات لم يتمكن الهدف من ممارستها. إنه موجود حتى يمكن التحقق من ادعاءات التغطية في SKILL.md مقابل عمليات التشغيل بدلًا من الوثوق بها، وحتى تُكتب الفجوات حيث سيجدها الشخص التالي.


مدعوم بفخر من مجتمع LINUX DO.

إخلاء المسؤولية

للتعلم والبحث واختبار الأمان المصرح به فقط. كل سكربت ومرجع ونتيجة مسجلة في هذا المستودع موجودة لشرح كيف يعمل تحليل تطبيقات Android، حتى يتمكن الممارسون من التفكير في الأدوات التي يملكونها بالفعل. لا شيء هنا خدمة، أو منتج، أو تأييد لأي استخدام معين.

  • الأهداف المصرح بها فقط. استخدم هذا على التطبيقات التي تملكها أو سُمح لك صراحةً بتحليلها، أو على مواد CTF/التحديات العامة، أو في بيئة معزولة تتحكم بها. تحليل البرمجيات التي لا يحق لك تحليلها قد يكون غير قانوني حيث تعيش، وهذا التحديد مسؤوليتك أنت، وليس مسؤولية هذا المستودع.
  • لا ضمان، ولا ملاءمة لأي غرض. المواد مقدمة كما هي، دون ضمان من أي نوع. تُسجَّل النتائج كما قيست على جهاز واحد في وقت واحد؛ لا شيء هنا يعد بأن مسارًا سيعمل على هدفك، أو جهازك، أو سلسلة أدواتك أو إصدار التطبيق اليوم.
  • تحقق قبل أن تثق؛ انسخ احتياطيًا قبل أن تتصرف. عدة سكربتات تعدل المخرجات (dex، APK، .so، بيانات التطبيق المخزنة) وبعضها يعمل على جهاز مُروَّت. احتفظ بنسخك الخاصة، واعمل على نسخ مكررة، واقرأ بوابات SKILL.md قبل تشغيل أي شيء ضد شيء تهتم به.
  • استخدامك مسؤوليتك. لا يتحمل المؤلفون والمساهمون أي مسؤولية عن أي خسارة، أو ضرر، أو نتيجة قانونية أو انقطاع خدمة ناتج عن استخدام أو إساءة استخدام هذا المستودع، وليسوا تابعين لأي تطبيق، أو بائع أو منصة قد يُستخدم لفحصها، ولا معتمدين من قِبَلها، ولا يتصرفون نيابة عنها.
  • بيانات الاختبار غير موزعة هنا. العينات والمستخرجات ومخرجات الأجهزة غائبة عمدًا من الشجرة (يستثنيها .gitignore) وتوجد فقط في مساحة عمل محلية متجاهلة. أي شيء تحصل عليه للمتابعة هو مسؤوليتك للحفاظ عليه وحذفه عندما تنتهي منه — اتبع قواعدك المحلية والشروط التي جاءت مع العينة. ما ينشره هذا المستودع هو الطريقة والأدلة، مع إزالة كل هوية الهدف.
  • لا انتماء. تظهر أسماء الأدوات والمكتبات ومنتجات التقوية وأهداف التحديات العامة فقط لجعل المواد قابلة لإعادة الاستخدام؛ إنها تنتمي إلى أصحابها respective وهذا المشروع غير مرتبط بها.
تنزيل الأداة
  • التمييز بين تفريغ ذاكرة حقيقي وهيكل قشرة استخراج، ومعرفة مسار الاستعادة المنطبق — بما في ذلك التفريغ من جهة الجذر عندما يُرفض frida نفسه. وما يمكن للقياس رؤيته وما لا يمكن موجود في skills/apk-reverse/references/advanced-unpacking.md.
  • استدعاء روتين بدلًا من عكسه عندما يكلف العكس أكثر من الاستدعاء: تنفيذ محاكى على المضيف، أو دالة حية تُحوَّل إلى خدمة عبر Frida RPC.
  • قراءة أدلة التنفيذ على مستوى التعليمات عندما تكون دالة أصلية قد سُطّحت إلى آلة حالة بواسطة OLLVM — بما في ذلك الطريقتان اللتان ثبت أن Stalker يردّ بهما الضربة على جهاز حقيقي.
  • التعرّف على متى لا يمكن للاعتراض في مساحة المستخدم الوصول إلى الفحص إطلاقًا (استدعاءات svc الخام، الكشف المبكر عبر init_array)، وما يمكن للطبقة الأعلى والأدنى فعله فعلًا، ومتى يكون التصعيد هو الجواب الخاطئ.
  • العمل على بروتوكولات ليست REST — protobuf بلا مخطط، وgRPC، وQUIC/HTTP3 — وتثبيت الشهادات من جهة الأصل الذي يتجاهل مخزن الثقة في النظام.
  • العمل من الهاتف نفسه: تدفق التحرير/إعادة التغليف/التوقيع في MT Manager وسطح APK MCP الخاص به، وLSPosed Manager، وفحص البيانات على الجهاز، جنبًا إلى جنب مع سلسلة أدوات الحاسوب لا بدلًا منها.
  • التمييز بين Java2C وقشرة استخراج قبل إهدار ساعات في البحث عن DEX مفكوك لا وجود له في أي نقطة من عمر العملية — فقد جُمع الكود في ملف .so.
  • التعامل مع بناء يصل كـمجموعة APK مقسّم / App Bundle: قراءة المجموعة من جهاز، وتوقيع كل عضو بمخزن مفاتيح واحد لـ pm install-multiple، أو دمج أعضاء الكود/الأصل في APK مستقل عندما يكون ذلك قانونيًا.
  • العمل على Dex VMP حقيقي بالفارق مع النص الصريح المعروف — أي الروابط يمكن أتمتتها وأيها لا، وما يمكن لعيّنة مُجمَّعة الوصول إليه وما لا، وكيف تُثبِت جدول أوامر برمجية خاصة مشتقًا بدلًا من ادّعائه.
  • نشر ما يتعلمه دون نشر الهدف — ماسح يبلّغ عن أشكال الهوية بسياقها، وقائمة صريحة بما يجب ألّا يُحجب (الأدوات، والمكتبات، وحقول البروتوكول، وCVEs، ومنتجات التحصين، وcrackmes العامة) لأن حجبها يدمّر الجزء القابل لإعادة الاستخدام، ورموز خروج تُبوّب الالتزام.
  • قراءة سابقة قبل تكرار عمل تقارب إليه هذا المستودع بالفعل: النصف الإيجابي من السجل، مع المسار بما فيه من طرق مسدودة، وتقييم على كل تأكيد، والملفات التي يقول الحالة إنه يجب الكتابة إليها.
  • actually loaded and executing
    "not on PATH" is not "not installed"
    landed
    legal
    .so
    never
    Java_*
    -fvisibility=hidden
    prove
    actually mapped
    arranged
    .so
    pm
    ps
    --show-exempt
    svc
    --context
    TracerPid