
droidground v1.0.13
A flexible playground for Android CTF challenges.
DroidGround
In traditional CTF challenges, it's common to hide flags in files on a system, requiring attackers to exploit vulnerabilities to retrieve them. However, in the Android world, this approach doesn't work well. APK files are easily downloadable and reversible, so placing a flag on the device usually makes it trivial to extract using static analysis or emulator tricks. This severely limits the ability to create realistic, runtime-focused challenges.
DroidGround is designed to solve this problem.
It is a custom-built platform for hosting Android mobile hacking challenges in a controlled and realistic environment, where attackers are constrained just enough to require solving challenges in the intended way.
Importantly, participants may be jailed inside the app environment. The modularity of the tool allows to set if the user can or cannot spawn a shell, read arbitrary files, or sideload tools. Everything can be setup so that the only way to retrieve the flag is through understanding and exploiting the app itself.
📋 Table of Contents
- 🧭 Overview
- ✨ Features
- 📸 Screenshots
- ⚙️ Configuration
- 🧩 Use Cases
- ⚙️ Usage
- 💡 Tips
- 🛠 Development
- 🤝 Contributing
- 📚 Credits
- 🪪 License
🧭 Overview
DroidGround enables a wide variety of Android challenges that are otherwise hard to implement in traditional CTF setups. For example, in a remote code execution (RCE) challenge, players might receive an APK for local analysis. After discovering a vulnerability, they can develop a Frida script and run it through DroidGround on the real target device to extract the flag from internal storage. Other challenge types can involve hidden activities, custom broadcast intents, service exploitation, or dynamic analysis using preloaded tools.
With real-time device streaming, fine-grained control over features, Frida integration, and customizable setup and reset scripts, DroidGround empowers CTF organizers to build secure, flexible, and realistic Android challenges that go far beyond what is typically possible.
✨ Features
DroidGround provides a rich set of server-controlled features.
- Real-Time Device Screen (via
scrcpy), with optional mouse, touch, and keyboard control - Reset Challenge State
- Restart App / Start Activity / Start Service
- Send Broadcast Intent
- Shutdown / Reboot Device
- Download Bugreport (bugreportz)
- Frida Scripting
- Run from preloaded library (jailed mode)
- Run arbitrary scripts (full mode)
- File Browser
- Terminal Access
- APK Management
- Logcat Viewer
- Exploit Server (if team mode is enabled)
Almost all features are modular and defined via environment variables, ensuring precise control over the challenge scope.
📸 Screenshots
![]() | ![]() |
|---|---|
| Overview | Start Activity |
![]() | ![]() |
| Frida Jailed Mode | Frida Full Mode |
![]() | ![]() |
| File Browser | App Manager |
![]() | ![]() |
| Terminal | Logs |
⚙️ Configuration
The .env.sample file in the root directory is a good starting point. This is the full list of all env variables currently supported:







