Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Sandroid_Dexray-Intercept — 一款Android恶意软件分析工具,通过挂钩应用程序在密码学、文件系统、数据库、网络通信和进程操作方面的行为,创建全面的运行时配置文件。 | Kitploit
工具/GitHubGitHub/fkie-cad/sandroid_dexray-intercept
Android安全动态分析 (沙盒)动态代码分析 (DAST)逆向工程取证分析信息收集移动取证恶意软件分析密码学移动安全实用工具与框架
931718天前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
GitHub
fkie-cad/sandroid_dexray-intercept

Sandroid_Dexray-Intercept

一款Android恶意软件分析工具,通过挂钩应用程序在密码学、文件系统、数据库、网络通信和进程操作方面的行为,创建全面的运行时配置文件。

查看仓库网站
Dexray Intercept Logo

Android 二进制 API 追踪器

Sandroid - Dexray Intercept

version PyPI version CI Ruff Publish status Documentation

Dexray Intercept 是动态沙箱 Sandroid 的一部分。其目的是创建运行时配置文件以追踪 Android 应用程序的行为。这是通过使用 frida 来实现的。

安装

只需使用 pip 安装:

root@kitploit:~
python3 -m pip install dexray-intercept

这会将 Dexray Intercept 安装为命令行工具 ammm 或 dexray-intercept。 此外,它还会提供一个名为 dexray_intercept 的包。关于如何使用该包的更多信息见下文。

运行

确保你的 Android 设备已 root。frida-server 将自动安装到最新版本。然后你只需调用以下命令即可使用 Dexray Intercept:

root@kitploit:~
dexray-intercept <target app>
# 或使用其旧名称:
ammm <target app>

Hook 选择(新功能)

所有 hook 默认禁用以获得最佳性能。根据你的分析需求启用 hook:

root@kitploit:~
# 启用特定 hook
dexray-intercept --enable-aes <app_name>                    # 启用 AES 加密 hook
dexray-intercept --enable-web <app_name>                    # 启用 web/HTTP hook
dexray-intercept --enable-aes --enable-web <app_name>       # 启用多个 hook

# 启用 hook 组
dexray-intercept --hooks-crypto <app_name>                  # 启用所有加密 hook
dexray-intercept --hooks-network <app_name>                 # 启用所有网络 hook  
dexray-intercept --hooks-filesystem <app_name>              # 启用所有文件系统 hook

# 启用所有 hook(影响性能)
dexray-intercept --hooks-all <app_name>                     # 启用所有可用 hook

# 使用包标识符代替应用名称
dexray-intercept -s com.example.package --hooks-crypto

可用的 Hook 类别

  • Crypto:--hooks-crypto(AES、编码、keystore、证书)
  • Network:--hooks-network(HTTP、socket、SSL/TLS)
  • File System:--hooks-filesystem(文件操作、数据库、shared preferences)
  • IPC:--hooks-ipc(intents、broadcasts、binder、shared preferences)
  • Process:--hooks-process(DEX 脱壳、原生库、运行时)
  • Services:--hooks-services(相机、位置、电话、蓝牙)

以下是在我们的 AVD 上监控 chrome 应用的示例:

root@kitploit:~
dexray-intercept Chrome
        Dexray Intercept
⠀⠀⠀⠀⢀⣀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣀⡀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣀⣀⣀⣀⣀⡀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠙⢷⣤⣤⣴⣶⣶⣦⣤⣤⡾⠋⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣴⠾⠛⢉⣉⣉⣉⡉⠛⠷⣦⣄⠀⠀⠀⠀
⠀⠀⠀⠀⠀⣴⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣦⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣴⠋⣠⣴⣿⣿⣿⣿⣿⡿⣿⣶⣌⠹⣷⡀⠀⠀
⠀⠀⠀⠀⣼⣿⣿⣉⣹⣿⣿⣿⣿⣏⣉⣿⣿⣧⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣼⠁⣴⣿⣿⣿⣿⣿⣿⣿⣿⣆⠉⠻⣧⠘⣷⠀⠀
⠀⠀⠀⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢰⡇⢰⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠀⠀⠈⠀⢹⡇⠀
⣠⣄⠀⢠⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⠀⣠⣄⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢸⡇⢸⣿⠛⣿⣿⣿⣿⣿⣿⡿⠃⠀⠀⠀⠀⢸⡇⠀
⣿⣿⡇⢸⣿⣿⣿Sandroid⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠈⣷⠀⢿⡆⠈⠛⠻⠟⠛⠉⠀⠀⠀⠀⠀⠀⣾⠃⠀
⣿⣿⡇⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠸⣧⡀⠻⡄⠀⠀⠀⠀⠀⠀⠀⠀⠀⢀⣼⠃⠀⠀
⣿⣿⡇⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢼⠿⣦⣄⠀⠀⠀⠀⠀⠀⠀⣀⣴⠟⠁⠀⠀⠀
⣿⣿⡇⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⢸⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⣠⣾⣿⣦⠀⠀⠈⠉⠛⠓⠲⠶⠖⠚⠋⠉⠀⠀⠀⠀⠀⠀
⠻⠟⠁⢸⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡇⠈⠻⠟⠀⠀⠀⠀⠀⠀⣠⣾⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠉⠉⣿⣿⣿⡏⠉⠉⢹⣿⣿⣿⠉⠉⠀⠀⠀⠀⠀⠀⠀⠀⣠⣾⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⣿⣿⣿⡇⠀⠀⢸⣿⣿⣿⠀⠀⠀⠀⠀⠀⠀⠀⠀⣾⣿⣿⠟⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⣿⣿⣿⡇⠀⠀⢸⣿⣿⣿⠀⠀⠀⠀⠀⠀⠀⢀⣄⠈⠛⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
⠀⠀⠀⠀⠀⠀⠈⠉⠉⠀⠀⠀⠀⠉⠉⠁⠀⠀⠀⠀⠀⠀⠀⠀⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
[*] starting app profiling
[*] press Ctrl+C to stop the profiling ...

[*] Filesystem profiling informations:
[*] [Libc::read] Read FD (anon_inode:[eventfd],0x7ac6b67540,8)

[*] Filesystem profiling informations:
[*] [Libc::read] Read FD (anon_inode:[eventfd],0x7fcb41c990,8

作为包运行

新 API(推荐)

将 Dexray Intercept 安装为包并使用新的模块化架构:

root@kitploit:~
from dexray_intercept import AppProfiler, setup_frida_device
from dexray_intercept.services.hook_manager import HookManager

# Connect to device and get process
device = setup_frida_device()
process = device.attach("com.example.app")

# Configure hooks (all disabled by default for performance)
hook_config = {
    'aes_hooks': True,
    'web_hooks': True, 
    'file_system_hooks': True,
    'keystore_hooks': True
}

# Create profiler with new architecture
profiler = AppProfiler(
    process, 
    verbose_mode=True,
    output_format="JSON",
    hook_config=hook_config,
    enable_stacktrace=True
)

# Start profiling
script = profiler.start_profiling()

# ... let app run and collect data ...

# Get results
profile_data = profiler.get_profile_data()
json_output = profiler.get_profiling_log_as_json()

# Runtime hook management
profiler.enable_hook('socket_hooks', True)  # Enable more hooks at runtime
enabled_hooks = profiler.get_enabled_hooks()  # Check what's enabled

# Stop profiling
profiler.stop_profiling()

Hook 类别

根据你的分析需求启用特定的 hook 组:

root@kitploit:~
# Crypto hooks
hook_config = {
    'aes_hooks': True,
    'encodings_hooks': True, 
    'keystore_hooks': True
}

# Network hooks  
hook_config = {
    'web_hooks': True,
    'socket_hooks': True
}

# File system hooks
hook_config = {
    'file_system_hooks': True,
    'database_hooks': True
}

# Enable all hooks (performance impact)
profiler.enable_all_hooks()

# Enable hook groups
profiler.enable_hook_group('crypto')  # Enable all crypto-related hooks

旧版 API(向后兼容)

旧版 API 仍然可用以保持向后兼容:

root@kitploit:~
from dexray_intercept import AppProfilerLegacy
# OR use environment variable: DEXRAY_FORCE_OLD_ARCH=true

profiler = AppProfilerLegacy(process_session, verbose=True, output_format="CMD", 
                           base_path=None, deactivate_unlink=False)
profiler.instrument()  # Old method name
# ... 
profiler.finish_app_profiling()  # Old method name

Sandroid 用法

为了在 Sandroid 中将其作为包运行,请确保你也安装了来自 AndroidFridaManager 的 JobManager。这允许在不同线程中运行多个 frida 会话。 你只需运行以下代码:

root@kitploit:~
from AndroidFridaManager import JobManager
from dexray_intercept import AppProfiler 

job_manager = JobManager()
app_package = "net.classwindexampleyear.bookseapiececountry"
profiler = AppProfiler(job_manager.process_session, True, output_format="JSON", base_path=None, deactivate_unlink=False)
frida_script_path = profiler.get_frida_script()

job_manager.setup_frida_session(app_package, profiler.on_appProfiling_message)
job = job_manager.start_job(frida_script_path, custom_hooking_handler_name=profiler.on_appProfiling_message)

# close only the job and the frida session keeps active to run other frida scripts
# job_manager.stop_job_with_id(job.job_id) 
job_manager.stop_app_with_closing_frida(app_package) # stops the frida session and the app and all frida jobs

profiler.write_profiling_log() # write the log data to profile.json
# instead of writing it to a file the JSON output will just be returned
# profiler.get_profiling_log_as_JSON() 

确保你的代码中没有其他部分尝试连接到 frida server(没有其他 frida 会话)。 为了测试这一点,你可以尝试以下示例:catelites_2018_01_19.apk。包名为 net.classwindexampleyear.bookseapiececountry。确保你的 AVD 运行在 Android 9 上,以便该示例能够执行其所有恶意代码。你可以使用 adb install samples/unpacking/catelites_2018_01_19.apk 简单地安装此示例。

编译与开发

为了编译此项目,请确保 npm 和 frida-compile 在你的系统上运行并已安装到你的路径中。自 frida 17.0 版本起,frida-compile 通过 pip install frida-tools 安装。 然后只需调用以下命令即可编译最新的 frida agent:

root@kitploit:~
$ cd <AppProfiling-Project>
> Dexray [email protected] build
> frida-compile agent/hooking_profile_loader.ts -o src/dexray_intercept/profiling.js

$ npm install frida-java-bridge@latest --save
$ npm install --save-dev @types/frida-gum@latest
> Dexray [email protected] prepare
> npm run build
up to date, audited 75 packages in 6s

19 packages are looking for funding
  run `npm fund` for details

found 0 vulnerabilities

这确保 dexray-intercept 中使用最新的 frida 脚本/hook。

为了对 Python 代码进行调整,建议使用可编辑模式通过 pip 安装 dexray-intercept:

root@kitploit:~
python3 -m pip install -e . 

这样,Python 代码的本地更改无需创建新版本的包即可生效。

📚 文档

提供全面的文档,涵盖安装、使用、API 参考和开发:

  • 📖 完整文档 - 完整文档站点
  • 🚀 快速入门指南 - 几分钟内上手
  • 🐍 Python API 参考 - 编程式用法
  • 🔧 TypeScript API 参考 - 自定义 hook 开发
  • 💻 CLI 使用指南 - 命令行界面
  • ⚙️ Hook 配置 - Hook 类别和选项

要求

只需在此目录中调用以下命令,setup.py 将用于将 dexray-intercept 作为本地 Python 包安装到你的系统:

root@kitploit:~
python3 -m pip install .

开发

为了编译 TypeScript frida hook,我们需要 frida-compile(链接)项目。它将与 frida-tools 捆绑在一起。

root@kitploit:~
python3 -m pip install frida-tools

此外,我们还需要对 frida-java-bridge 和内部 frida 类型的支持:

root@kitploit:~
npm install frida-java-bridge@latest --save
npm install --save-dev @types/frida-gum@latest

深度脱壳

在脱壳时,应用程序可能会将 DexCode(之前指向不同的内存块)加载到 DexFile 中,DexFile 代表正在执行的代码。例如,某些应用程序可能会在执行前立即恢复指令。在这种情况下,Sandroid 无法将指令还原回 DexFile。需要进一步研究以解决此问题。

致谢

Dexray Intercept 建立在 Android 安全和动态分析社区中各种开源项目和研究人员的出色工作之上。我们要感谢以下项目,它们启发了我们的实现或为其做出了贡献:

核心 Frida 框架

  • Frida - 为我们的运行时分析能力提供支持的动态插桩工具包
  • frida-java-bridge - Java/Android 运行时插桩的必备组件

Hook 实现与技术

  • AppMon 由 @dpnishant 开发 - 为运行时分析、IPC 监控、剪贴板访问和数据库操作提供了基础 hook
  • Android-Malware-Sandbox 由 @Areizen 开发 - Base64 编码 hook 和 socket 监控技术
  • RMS-Runtime-Mobile-Security 由 @m0bilesecurity 开发 - Keystore 分析和证书固定检测
  • Medusa 由 @Ch0pin 开发 - 运行时分析模式和 DEX 脱壳技术
  • frida-android-libbinder 由 @Hamz-a 开发 - Android Binder IPC 分析
  • frida-snippets 由 @iddoeldor 开发 - 位置欺骗和实用函数

Android 安全研究

  • BlackDex 由 @CodingGay 开发 - DEX 脱壳和反分析绕过技术
  • Frida-Python-Binding 由 @Mind0xP 开发 - Frida 的 Python 集成模式

SQLite 与数据库分析

  • SQLite Database Hook 由 @ninjadiary 开发 - 数据库监控技术

我们感谢这些项目及其维护者为推进 Android 安全分析水平并将他们的工作提供给社区。

路线图

  • [ x ] 为我们想要安装以获取运行时配置文件的不同 hook 创建模板
  • 创建一个测试应用程序,使用我们想要 hook 的所有不同功能(我们需要某种基准真值来测试我们的 hook)
  • 实现实际的 hook
  • [ x ] 打印监控信息的格式
  • https://attack.mitre.org/matrices/mobile/ 将此作为最终结果添加,以便我们可以说明应用程序正在使用何种攻击
  • 我们还希望追踪诸如“这些是隐私问题”、“这可能导致 bug”之类的内容……
下载工具