daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

apk-decompilers.md (9084B)


      1 ---
      2 title: "APK decompilers"
      3 section: "Mobile"
      4 sectionSlug: "mobile-pentesting"
      5 sourcePath: "src/mobile-pentesting/android-app-pentesting/apk-decompilers.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/mobile-pentesting/android-app-pentesting/apk-decompilers.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # APK decompilers
     14 
     15 The comparative decompilation guide in the references provides further details on the tools and their tradeoffs.<sup>[[3]](#references)</sup>
     16 
     17 ### JD-Gui<sup>[[4]](#references)</sup>
     18 
     19 As the pioneering GUI Java decompiler, **JD-Gui** allows you to investigate Java code within APK files. It's straightforward to use; after obtaining the APK, simply open it with JD-Gui to inspect the code.
     20 
     21 ### Jadx<sup>[[5]](#references)</sup>
     22 
     23 **Jadx** offers a user-friendly interface for decompiling Java code from Android applications. It's recommended for its ease of use across different platforms.
     24 
     25 - To launch the GUI, navigate to the bin directory and execute: `jadx-gui`
     26 - For command-line usage, decompile an APK with: `jadx app.apk`
     27 - To specify an output directory or adjust decompilation options: `jadx app.apk -d <path to output dir> --no-res --no-src --no-imports`
     28 
     29 #### AI-assisted static analysis with jadx-mcp
     30 
     31 [**jadx-mcp**](https://github.com/0xdad0/jadx-mcp) is a jadx-gui plugin that exposes the analysis model of the currently loaded APK, DEX, or JAR as 27 schema-validated MCP tools over Streamable HTTP. Unlike copying decompiled text into an LLM, the client can request Java or Smali, methods and fields, decoded manifest components and resources, cross-references, and jadx rename operations as structured results.<sup>[[14]](#references)</sup>
     32 
     33 The plugin targets jadx-gui 1.5.6 and requires jadx to run on Java 17 or later. Install its fat JAR, open the target in jadx-gui, start the server from **Plugins → jadx-mcp: Settings...**, and register the default endpoint with an HTTP-capable MCP client:<sup>[[14]](#references)</sup>
     34 
     35 ```bash
     36 jadx plugins --install-jar jadx-mcp-0.1.0.jar
     37 claude mcp add --transport http jadx-mcp http://localhost:8090/mcp
     38 ```
     39 
     40 A compact Android review/deobfuscation loop is:<sup>[[14]](#references)</sup>
     41 
     42 1. Call `status`, then inspect `get_android_manifest`, `get_manifest_component`, `get_main_activity_class`, `get_strings`, and selected resource files to map exported entry points, deep links, hardcoded endpoints, and security configuration.
     43 2. Use `search_classes`, `search_method_by_name`, or `search_classes_by_keyword`, then retrieve only the relevant class/method source or Smali. Supply a `signature` fragment to method tools when overloads are ambiguous.
     44 3. Follow `xrefs_to_class`, `xrefs_to_method`, and `xrefs_to_field`, retrieving method source at each hop to reconstruct call paths and field-access flows.
     45 4. Rename inferred symbols with `rename_class`, `rename_method`, `rename_field`, or `rename_package`, reload, and repeat. These aliases use jadx's normal deobfuscation system; `rename_variable` is session-local and is not stored in saved `.jadx` metadata.
     46 
     47 Paginated tools accept `offset` and `limit` (default 50, maximum 500). Prefer targeted queries over `get_main_application_classes_code`, whose full-source responses are token-heavy.<sup>[[14]](#references)</sup>
     48 
     49 > [!WARNING]
     50 > The server has **no authentication**. Its safe default is `127.0.0.1:8090`; Origin/Host validation helps against browser and DNS-rebinding access but does not authenticate network clients. Never bind it to `0.0.0.0` or a LAN address, and do not port-forward the endpoint: connected clients can extract loaded code/resources and mutate project aliases.<sup>[[14]](#references)</sup>
     51 
     52 ### GDA Android Reversing Tool<sup>[[6]](#references)</sup>
     53 
     54 **GDA**, a Windows-only tool, offers extensive features for reverse engineering Android apps. Install and run GDA on your Windows system, then load the APK file for analysis.
     55 
     56 ### Bytecode Viewer<sup>[[7]](#references)</sup>
     57 
     58 With **Bytecode-Viewer**, you can analyze APK files using multiple decompilers. After downloading, run Bytecode-Viewer, load your APK, and select the decompilers you wish to use for simultaneous analysis.
     59 
     60 ### Enjarify<sup>[[8]](#references)</sup>
     61 
     62 **Enjarify** translates Dalvik bytecode to Java bytecode, enabling Java analysis tools to analyze Android applications more effectively.
     63 
     64 - To use Enjarify, run: `enjarify app.apk` This generates the Java bytecode equivalent of the provided APK.
     65 
     66 ### CFR<sup>[[9]](#references)</sup>
     67 
     68 **CFR** is capable of decompiling modern Java features. Use it as follows:
     69 
     70 - For standard decompilation: `java -jar ./cfr.jar "app.jar" --outputdir "output_directory"`
     71 - For large JAR files, adjust the JVM memory allocation: `java -Xmx4G -jar ./cfr.jar "app.jar" --outputdir "output_directory"`
     72 
     73 ### Fernflower<sup>[[10]](#references)</sup>
     74 
     75 **Fernflower**, an analytical decompiler, requires building from source. After building:
     76 
     77 - Decompile a JAR file: `java -jar ./fernflower.jar "app.jar" "output_directory"` Then, extract the `.java` files from the generated JAR using `unzip`.
     78 
     79 ### Krakatau<sup>[[11]](#references)</sup>
     80 
     81 **Krakatau** offers detailed control over decompilation, especially for handling external libraries.
     82 
     83 - Use Krakatau by specifying the standard library path and the JAR file to decompile: `./Krakatau/decompile.py -out "output_directory" -skip -nauto -path "./jrt-extractor/rt.jar" "app.jar"`
     84 
     85 ### Procyon<sup>[[12]](#references)</sup>
     86 
     87 For straightforward decompilation with **procyon**:
     88 
     89 - Decompile a JAR file to a specified directory: `procyon -jar "app.jar" -o "output_directory"`
     90 
     91 ### frida-DEXdump<sup>[[13]](#references)</sup>
     92 
     93 This tool can be used to dump the DEX of a running APK in memory. This helps to beat static obfuscation that is removed while the application is executed in memory.
     94 
     95 ### androidReverse
     96 
     97 **androidReverse** is an **on-device Android reverse-engineering suite**: useful when you need to triage an APK directly from a phone/tablet **without ADB or a desktop workstation**.<sup>[[1]](#references)</sup><sup>[[2]](#references)</sup>
     98 
     99 Useful workflow:
    100 
    101 - **Extract** `.apk`, `.xapk`, and split `.apks` from **installed apps** or storage, then inspect Java/Kotlin, Smali, resources, and `lib/*.so` in the same session.
    102 - **Compare the same class across multiple engines** instead of trusting a single decompiler output. It includes **Jadx**, **Jadx Fallback**, **Jadx IR**, **CFR**, **Procyon**, **JD-Core**, **Krakatau**, and **Vineflower**. In practice, use **Jadx/CFR/Procyon** for readability and switch to **Krakatau** or **Jadx IR** when obfuscation, malformed bytecode, Kotlin artifacts, lambdas, or flattened control flow make the reconstructed Java suspicious.
    103 - **Validate resources/manifests** when normal viewers fail: the suite decodes **binary AXML** and parses **ARSC** tables, which is useful to recover **permissions**, **exported components**, **intent filters**, **deep links**, **feature flags**, **URLs**, and other strings hidden in resources.
    104 - **Pivot into native code** when the real logic lives in JNI: it embeds **radare2** for **pseudo-C**, **assembly**, **hex**, **CFGs**, **call graphs**, and **xrefs**, which is handy to inspect JNI entry points, anti-analysis checks, crypto routines, and string decryption inside Android `.so` files.
    105 - For **Flutter** apps, prefer its **Unflutter** support; for **Unity** apps, inspect the recovered **`il2cpp` metadata** instead of relying only on Java decompilation.
    106 
    107 This is especially practical for **field triage**, **mobile malware static analysis**, and **quick review of customer-provided APKs** when you only have an Android device available.
    108 
    109 ## References
    110 
    111 - [1] [androidReverse repository](https://github.com/UltraSina/androidReverse)
    112 - [2] [androidReverse latest release (release11 / version 11, June 21, 2026)](https://github.com/UltraSina/androidReverse/releases/tag/release11)
    113 - [3] [How to Break Your JAR in 2021 - Decompilation Guide for JARs and APKs](https://eiken.dev/blog/2021/02/how-to-break-your-jar-in-2021-decompilation-guide-for-jars-and-apks/#cfr)
    114 - [4] [JD-GUI repository](https://github.com/java-decompiler/jd-gui)
    115 - [5] [Jadx repository and usage](https://github.com/skylot/jadx)
    116 - [6] [GDA Android Reversing Tool](https://github.com/charles2gan/GDA-android-reversing-Tool)
    117 - [7] [Bytecode Viewer releases](https://github.com/Konloch/bytecode-viewer/releases)
    118 - [8] [Enjarify repository](https://github.com/Storyyeller/enjarify)
    119 - [9] [CFR repository](https://github.com/leibnitz27/cfr)
    120 - [10] [JetBrains Java decompiler engine](https://github.com/JetBrains/intellij-community/tree/master/plugins/java-decompiler/engine)
    121 - [11] [Krakatau repository](https://github.com/Storyyeller/Krakatau)
    122 - [12] [Procyon repository](https://github.com/mstrobel/procyon)
    123 - [13] [FRIDA-DEXDump repository](https://github.com/hluwa/FRIDA-DEXDump)
    124 - [14] [jadx-mcp: MCP server plugin for jadx-gui](https://github.com/0xdad0/jadx-mcp)