Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
NinjaDroid — Ninja Reverse Engineering on Android APK packages | Kitploit
Tools/GitHubGitHub/rovellipaolo/ninjadroid
Android SecurityStatic AnalysisReverse EngineeringMobile SecurityBinary Analysis
GitHubrovellipaolo/ninjadroid

NinjaDroid

Ninja Reverse Engineering on Android APK packages

View Repository
28748224 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

NinjaDroid

NinjaDroid is a simple tool to reverse engineering Android APK packages.

Published at: https://snapcraft.io/ninjadroid

$ snap install ninjadroid --channel=beta

Build Status: GitHub Actions Test Coverage: Coveralls License: GPL v3

Get it from the Snap Store

NinjaDroid

Overview

NinjaDroid uses AXMLParser together with a series of Python scripts based on aapt, keytool, string and such to extract a series of information from a given APK package, such as:

  • List of files of the APK: file name, size, MD5, SHA-1, SHA-256 and SHA-512
  • AndroidManifest.xml info: app name, package name, version, sdks, permissions, activities, services, broadcast-receivers, ...
  • CERT.RSA/DSA digital certificate info: serial number, validity, fingerprint, issuer and owner
  • List of URLs, shell commands and other generic strings hard-coded into the classes.dex files

Furthermore, NinjaDroid uses apktool and dex2jar to extract and store:

  • JSON report file, which contains all the extracted APK info
  • AndroidManifest.xml file (thanks to apktool)
  • CERT.RSA/DSA digital certificate file
  • classes.dex files
  • translated .jar file (thanks to dex2jar)
  • disassembled smali files (thanks to apktool)
  • assets/ and res/ folders together with their content (thanks to apktool)

Build

The first step is cloning the NinjaDroid repository, or downloading its source code.

$ git clone https://github.com/rovellipaolo/NinjaDroid
$ cd NinjaDroid

NinjaDroid has several ways to be executed: natively in your local environment, in Docker, as a Flatpak (experimental) and as a Snap (experimental).

Native

To execute NinjaDroid in your local machine, you need to install Python 3.5 or higher, Java 8 or higher and binutils.

Optionally, if you have the Android SDK installed locally, you can use the SDK version of aapt instead of the included one. In order to do so, you need to change the aapt location in ninjadroid/aapt/Aapt.py (i.e. __AAPT_EXEC_PATH = "ninjadroid/aapt/aapt").

Linux

Just launch the following commands, which will install all the Python dependencies (making sure that aapt, apktool and dex2jar have executable permissions) and add a ninjadroid symlink to /usr/local/bin/.

$ make build-linux
$ make install
$ ninjadroid --help

MacOS

Just launch the following commands, which will install all the needed Python dependencies (making sure that aapt, apktool and dex2jar have executable permissions) and add a ninjadroid symlink to /usr/local/bin/.

$ make build-macos
$ make install
$ ninjadroid --help

Docker

To execute NinjaDroid in Docker, you need Docker installed. To build the Docker image, launch the following commands:

$ make build-docker
$ docker run --name ninjadroid ninjadroid:latest ninjadroid --help

Note that you need to bind the directory containing the target APK package to the Docker image:

$ mkdir apks
$ cp /path/to/your/package.apk apks/package.apk
$ docker run --name ninjadroid -it --rm -v $(pwd)/apks:/apks ninjadroid:latest ninjadroid /apks/package.apk -aj

And the same applies also to the output directory when using the -e/--extract option, to which you also need to grant permissions:

$ mkdir output
$ chmod 777
$ docker run --name ninjadroid --rm -v $(pwd)/apks:/apks -v $(pwd)/output:/output ninjadroid:latest ninjadroid /apks/package.apk -ae /output

Flatpak (experimental)

To execute NinjaDroid as a Flatpak, you need Flatpak and flatpak-builder installed. Just launch the following commands, which will install all the needed Flatpak dependencies:

$ make build-flatpak
$ flatpak-builder --run flatpak/build flatpak/com.github.rovellipaolo.NinjaDroid.yaml ninjadroid --help

NOTE: The -e/--extract option does not work correctly at present (see: https://github.com/rovellipaolo/NinjaDroid/issues/21).

Snap (experimental)

To execute NinjaDroid as a Snap, you need Snap and snapcraft installed. Just launch the following commands, which will install all the needed Snap dependencies:

$ make build-snap
$ make install-snap
$ ninjadroid --help

NOTE: The -e/--extract option does not work correctly when the snap is installed without using the --devmode option (see: https://github.com/rovellipaolo/NinjaDroid/issues/20).

Test

Once you've configured it (see the "Installation" section), you can also run the tests and checkstyle as follows.

Native

To run them in your local machine, launch the following commands:

$ make test
$ make regression
$ make checkstyle

You can also run the tests with coverage by launching the following command:

$ make test-coverage

And/or configure the checkstyle to run automatically at every git commit by launching the following command:

$ make install-githooks

Docker

To run them in Docker, launch the following commands:

$ make test-docker
$ make regression-docker
$ make checkstyle-docker

Flatpak

To run the regression tests in Flatpak, launch the following command:

$ make regression-flatpak

Snap

To run the regression tests in Snap, launch the following command:

$ make regression-snap

Usage

The following are examples of running NinjaDroid against the sample APK package.

Download Tool