Androguard module for Yara Logo

Androguard module for Yara

0
Free
Visit Website

This module for Yara is part of the Koodous project https://koodous.com and it integrates static APK analysis with Yara. You can use it to find APKs by package name, permissions or API level, etc. Find the documentation for this module in the Koodous documentation's site: http://docs.koodous.com/yara/androguard/ Preparing compilation: If you want to use this module, first you need to re-compile Yara with the androguard module. To do so, you need to modify some files. Follow the basic steps in the official docs: http://yara.readthedocs.org/en/latest/writingmodules.html#building-our-hello-world Include the file androguard.c in folder libyara/modules. Modify "libyara/modules/module_list" and add "MODULE(androguard)" in the cuckoo block. The file should look like the following: MODULE(pe) MODULE(elf) MODULE(math) #ifdef CUCKOO MODULE(cuckoo) MODULE(androguard) #endif Modify "libyara/Makefile.am" to add androguard module ("MODULES += modules/androguard.c") in the cuckoo block: MODULES = modules/tests.c MODULES += modules/pe.c if CUCKOO MODULES += modules/cuckoo.c MODULES += modules/androguard.c endif Recompile Yara, but enabling cuckoo module.

FEATURES

ALTERNATIVES

Utility for comparing control flow graph signatures to Android methods with scanning capabilities for malicious applications.

A fast and minimal JS endpoint extractor

Static code analyzer for Infrastructure as Code with 500+ security policies and support for various IaC tools and cloud platforms.

A web-based tool for instrumenting and analyzing Android applications using Flask, Jinja, and Redis.

A collection of mobile security resources with tools, white papers, ebooks, and webinars.

A fake Django admin login screen to detect and notify admins of attempted unauthorized access

A web application firewall and API security platform that combines API discovery, runtime protection, vulnerability testing, and security posture management.

A web application designed to be 'Xtremely Vulnerable' for security enthusiasts to learn application security.