Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
dexfinder — Cross-platform APK/DEX method finder with call chain tracing, ProGuard deobfuscation, and hidden API detection | Kitploit
Tools/GitHubGitHub/junelegency/dexfinder
Android SecurityStatic AnalysisVulnerability AnalysisCode AnalysisReverse EngineeringInformation GatheringDevSecOpsMobile SecurityBinary Analysis
GitHubjunelegency/dexfinder

dexfinder

Cross-platform APK/DEX method finder with call chain tracing, ProGuard deobfuscation, and hidden API detection

9210205 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

dexfinder

English | 中文 | Website dexfinder demo


Website: junelegency.github.io/dexfinder

Cross-platform APK/DEX method & field reference finder with call chain tracing, ProGuard/R8 deobfuscation, and Android hidden API detection.

Inspired by Android's veridex tool, reimplemented in Go with enhanced capabilities: faster reflection detection, call chain tracing (veridex only shows one level), and flexible output formats.

Features

  • APK/DEX/JAR scanning — Parse DEX bytecode, extract all method/field/string references
  • Multi-format query — Search by Java name, DEX/JNI signature, or simple keyword
  • Call chain tracing — Trace callers up to N levels deep, merged tree or flat list, with cycle detection
  • ProGuard/R8 deobfuscation — Load mapping.txt, display original names alongside obfuscated
  • Hidden API detection — Load hiddenapi-flags.csv, detect blocked/unsupported APIs
  • Reflection detection — Cross-match classes × strings to find reflection-based hidden API usage
  • Flexible output — text / json / model / html / sarif, tree / list layout, java / dex name style — all orthogonal
  • Color terminal output — Auto-detected ANSI colors for tags, tree connectors, and API levels
  • APK diff — Compare two APK/DEX versions, detect added/removed/changed API references
  • HTML reports — Self-contained interactive HTML with collapsible trees, search, and dark theme
  • SARIF output — SARIF 2.1.0 for GitHub Code Scanning, VS Code, and CI pipelines
  • CI integration — --fail-on blocked exits non-zero when restricted APIs are found
  • Config file — .dexfinder.yaml for project defaults, CLI flags override
  • Zero external dependencies — Pure Go, self-contained DEX parser
  • Cross-platform — macOS (Intel / Apple Silicon), Linux (amd64 / arm64), Windows

Install

Homebrew (macOS / Linux):

brew install junelegency/tap/dexfinder

Script (auto-detects OS/arch):

curl -sSL https://raw.githubusercontent.com/JuneLeGency/dexfinder/main/install.sh | bash

Go install:

go install github.com/JuneLeGency/dexfinder/cmd/dexfinder@latest

Binary: download from Releases.

Quick Start

# Show APK overview
dexfinder --dex-file app.apk --stats

# Find all calls to getDeviceId (IMEI)
dexfinder --dex-file app.apk --query "getDeviceId"

# Trace call chains as merged tree
dexfinder --dex-file app.apk --query "getDeviceId" --trace

# Trace as flat call stacks (Java crash style)
dexfinder --dex-file app.apk --query "getDeviceId" --trace --layout list

# Exact JNI signature query
dexfinder --dex-file app.apk \
  --query "Landroid/telephony/TelephonyManager;->getDeviceId()Ljava/lang/String;" \
  --trace --depth 8

# Hidden API detection
dexfinder --dex-file app.apk --api-flags hiddenapi-flags.csv

Query Formats

The --query flag accepts multiple input styles. dexfinder auto-detects and converts between them.

FormatExampleBehavior
Simple namegetDeviceIdFuzzy substring match across all APIs
Java classandroid.telephony.TelephonyManagerAll methods/fields of that class
Java class#methodandroid.telephony.TelephonyManager#getDeviceIdAll overloads of that method
Java full signature...TelephonyManager#getDeviceId()Exact + overload fallback
DEX/JNI signatureLandroid/telephony/TelephonyManager;->getDeviceId()Ljava/lang/String;Exact match only
# All equivalent — find requestLocationUpdates in LocationManager:
dexfinder --dex-file app.apk --query "requestLocationUpdates"
dexfinder --dex-file app.apk --query "android.location.LocationManager#requestLocationUpdates"
dexfinder --dex-file app.apk --query "Landroid/location/LocationManager;->requestLocationUpdates(Ljava/lang/String;JFLandroid/location/LocationListener;)V"

Output Control

Three independent axes, freely combinable:

--format  (text / json / model / html / sarif)    what to output
--layout  (tree / list)                           how to arrange traces
--style   (java / dex)                            how to display names
--color   (auto / always / never)                 terminal colors

--format

ValueDescription
textPlain text output with colored tags (default)
jsonJSON — scan results or trace with tree/list layout
modelStructured JSON with full MethodInfo/FieldInfo types (for IDE/CI)
htmlSelf-contained HTML report with collapsible trees and search
sarifSARIF 2.1.0 static analysis format (GitHub / VS Code)

--layout (used with --trace)

ValueDescription
treeMerged tree — shared call paths collapsed into one tree (default)
listFlat list — each unique call chain shown as independent stack

--style

ValueExampleUse case
javacom.example.Foo.method(Foo.java)Human-readable (default)
dexFoo.method(Ljava/lang/String;)VPrecise signature analysis

--scope (search scope)

Controls what kind of references the query matches against. This is critical for understanding results.

ValueWhat it searchesQuestion it answersOutput tag
allCallee APIs + fields + code strings"Who calls this API?" (default)[METHOD] [FIELD] [STRING]
calleeOnly target API signatures in invoke-* / get/put instructions"Who calls this specific method/field?"[METHOD] [FIELD]
callerOnly the calling method's signature"What does this method call internally?"[CALLER→]
stringString constants in const-string instructions"Where is this string used in code?"[STRING]
string-tableCode strings + full DEX string table"Does this string exist anywhere in DEX?" (includes annotations, dead code)[STRING] [STRING_TABLE]
everythingAll of the above combinedFull pictureall tags

Understanding callee vs caller:

scope=callee: "Who calls finish()?"
    onCreate ──calls──→ finish()     ← these callers are shown
    onResume ──calls──→ finish()

scope=caller: "What does finish() call internally?"
    finish() ──calls──→ Log.i()      ← these callees are shown
    finish() ──calls──→ super.finish()

--scope=all (default) = callee + string. The caller direction is intentionally excluded from default because it answers a fundamentally different question. Use --scope=caller or --scope=everything explicitly when you need it.

Understanding output tags:

TagMeaning
[METHOD]A method being called matches your query (callee match). Indented lines are the callers.
[FIELD]A field being accessed matches your query. Indented lines are the accessors.
[CALLER→]A calling method matches your query. The indented line shows what API it's calling.
[STRING]A string constant in code matches your query. Indented lines are where it's used.
[STRING_TABLE]String exists in DEX string table but has no const-string reference in code (may be in annotations, optimized out by R8, etc.)

Examples

1. Scan APK statistics

dexfinder --dex-file app.apk --stats
Loaded 31 DEX file(s): 183913 classes, 1250566 method refs
Method references: 680610
Field references:  625572
String constants:  654353
Referenced types:  192586
Time: 3.9s

2. Find all location tracking calls

Download Tool