
droidbox
Dynamic analysis sandbox for Android apps that monitors network traffic, file operations, cryptographic API usage, permission circumvention, and…

Dynamic analysis sandbox for Android apps that monitors network traffic, file operations, cryptographic API usage, permission circumvention, and…

DECAF (short for Dynamic Executable Code Analysis Framework) is a binary analysis platform based on QEMU. This is also the home of the DroidScope…

A pattern based Dalvik deobfuscator which uses limited execution to improve semantic analysis

Automated pre-analysis tool for Android apps that disassembles samples, extracts properties via configurable pattern matching, and organizes output…

An strace-like program for the Windows 'native' API

Tool for leaking and bypassing Android malware detection system

Droidefense: Advance Android Malware Analysis Framework

Django application that performs SAST and Malware Analysis for Android APKs

Slide decks from my conference presentations

A framework for automated extraction of static and dynamic features from Android applications



Malware detection using learning and information retrieval for Android

Fuzzy comparison tool for deobfuscating Android APKs by identifying renamed functions across versions, generating mapping files and interactive HTML…

Simple framework to extract "actionable" data from Android malware (C&Cs, phone numbers etc.)

A machine learning malware analysis framework for Android apps.

Static and dynamic Android application security analysis

Live Hidden Camera is a library which record live video and audio from Android device without displaying a preview.