
Android-Sicherheitseinblicke im gesamten Spektrum.
Android-Sicherheitseinblicke im vollen Spektrum.
Funktionen • Erkennung auf einen Blick • Installation • Verwendung • Berichte
Vorgestellt auf Black Hat MEA 2023 und Black Hat ASIA 2024

APKDeepLens ist ein Python-basiertes statisches Analysetool für Android-APK-Dateien. Es dekompiliert APKs mit JADX und führt einen tiefgehenden mehrschichtigen Sicherheitsscan durch, der das OWASP Mobile Top 10 (2024) abdeckt. Jeder Fund wird mit einem Schweregrad (CRITICAL / HIGH / MEDIUM / LOW / INFO) und einer OWASP-Kategorie versehen, und die Ergebnisse werden im JSON-, HTML-, PDF- oder TXT-Format exportiert.
| Kategorie | Prüfungen | Schweregradbereich | OWASP |
|---|---|---|---|
| Manifest-Sicherheit | 10 | CRITICAL → MEDIUM | M3–M9 |
| Kryptografie | 7 | CRITICAL → MEDIUM | M1, M10 |
| WebView-Sicherheit | 6 | CRITICAL → HIGH | M4, M5, M7, M9 |
| SSL / TLS | 5 | CRITICAL → MEDIUM | M5 |
| Dynamische Codeausführung | 4 | HIGH → MEDIUM | M4, M7 |
| Unsicherer Datenspeicher | 6 | HIGH → LOW | M4, M6, M9 |
| Logs / Privatsphäre | 3 | MEDIUM → LOW | M6 |
| Intent-Sicherheit | 2 | HIGH → MEDIUM | M4 |
| Zip-Pfad-Traversal | 1 | HIGH | M4 |
| Fest codierte Geheimnisse | 16+ | — | M1 |
| Unsichere Kommunikation | — | — | M5 |
Für vollständige Prüf-IDs, Regex-Muster und Belegbeispiele siehe DETECTION.md.
Voraussetzungen: Python 3.10+, Java / OpenJDK
git clone https://github.com/d78ui98/APKDeepLens.git
cd APKDeepLens
python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txt
python APKDeepLens.py --help
git clone https://github.com/d78ui98/APKDeepLens.git
cd APKDeepLens
python3 -m venv venv
.\venv\Scripts\activate
pip install -r requirements.txt
python APKDeepLens.py --help
docker build -t apkdeeplens .
docker run --rm -v /path/to/apk/files:/apk apkdeeplens -apk /apk/file.apk
# Basic scan — outputs JSON report
python APKDeepLens.py -apk app.apk
# Skip decompilation when source is already extracted
python APKDeepLens.py -apk app.apk -source_code_path /path/to/source
# Generate HTML report
python APKDeepLens.py -apk app.apk -report html
# Generate PDF report
python APKDeepLens.py -apk app.apk -report pdf
# Generate plain-text report
python APKDeepLens.py -apk app.apk -report txt
# Specify output directory
python APKDeepLens.py -apk app.apk -report json -o /path/to/output/
# Skip virtualenv check (CI/CD)
python APKDeepLens.py -apk app.apk --ignore_virtualenv
Alle Berichte werden in einem reports/-Unterverzeichnis des Ausgabepfads gespeichert.
| Format | Beschreibung |
|---|---|
| JSON (Standard) | Maschinenlesbar. Alle Funde enthalten id, severity, owasp, description und evidence. Ideal für Pipeline-Integration. |
| HTML / PDF | Farbcodierte Schweregradtabellen – CRITICAL in Rot, HIGH in Orange, MEDIUM in Bernstein. |
| TXT | Menschenlesbar, nach Schweregrad sortierte Funde mit Dateipfaden und Beschreibungen. |
Siehe DETECTION.md für das vollständige JSON-Ausgabeschema.
APKDeepLens/
├── APKDeepLens.py # Hauptprogramm
├── report_gen.py # Berichtsgenerierung (JSON, HTML, PDF, TXT)
├── report_template.html # HTML-Berichtsvorlage
├── requirements.txt
└── static_tools/
├── code_scanner.py # Tiefenscanner für Codemuster (40+ Prüfungen)
├── scan_android_manifest.py # Manifest-Parser + Sicherheitsprüfer
├── sensitive_info_extractor.py # Scanner für fest codierte Geheimnisse + unsichere URLs
├── known_false_positives.txt # Kuratierte Liste von Fehlalarmen
└── utility/
└── utility_class.py # Gemeinsame Konstanten (DANGEROUS_PERMISSIONS, util)
Feature-Anfragen, Fehlerberichte und Pull-Requests sind willkommen unter github.com/d78ui98/APKDeepLens/issues.