# How MobileAudit Extracts and Analyzes APK Components: A Technical Deep Dive

> Discover how MobileAudit extracts and analyzes APK components like activities, services, and certificates using Androguard and Celery. Get a technical deep dive into security analysis.

- Repository: [Mónica Pastor/mobileaudit](https://github.com/mpast/mobileaudit)
- Tags: deep-dive
- Published: 2026-03-07

---

**MobileAudit leverages the Androguard library within a Celery-driven pipeline to decompile APK files, extract cryptographic hashes, permissions, activities, services, broadcast receivers, content providers, intent filters, and digital certificates, persisting all findings into Django ORM models for security analysis.**

The open-source project `mpast/mobileaudit` provides a web-based platform for automated Android application security auditing. Understanding how MobileAudit extracts and analyzes APK components requires examining its Python backend architecture in [`app/analysis.py`](https://github.com/mpast/mobileaudit/blob/main/app/analysis.py), which orchestrates static analysis through a series of specialized extraction functions against the uploaded binary.

## The Analysis Pipeline Architecture

### Task Initialization and APK Loading

In [`app/worker/tasks.py`](https://github.com/mpast/mobileaudit/blob/main/app/worker/tasks.py), the Celery task `task_create_scan` initiates the workflow by calling `analysis.analyze_apk` with the uploaded file path constructed as `settings.BASE_DIR + scan.apk.url`. This entry point triggers the complete static analysis sequence, delegating to specialized functions for hash computation, metadata extraction, and certificate analysis.

### Cryptographic Hash Verification

Before component analysis begins, the system computes file integrity hashes. The `set_hash_app` function in [`app/analysis.py`](https://github.com/mpast/mobileaudit/blob/main/app/analysis.py) (lines 20-38) reads the APK in chunks to calculate MD5, SHA-1, and SHA-256 checksums, storing these values on the `Scan` model to ensure file authenticity tracking and duplicate detection.

## Component Extraction Methodology

### Core Metadata and Manifest Parsing

The `get_info_apk` function serves as the primary extraction engine in [`app/analysis.py`](https://github.com/mpast/mobileaudit/blob/main/app/analysis.py) (lines 35-74). It utilizes Androguard's `APK` class to retrieve the package name, version information, minimum and target SDK ranges, and the raw manifest XML. This function creates `Component` records for every activity, service, receiver, and provider discovered in the AndroidManifest.xml.

### Permission Analysis

Within `get_info_apk`, the system iterates through `a.get_permissions()` to process security permissions (lines 48-57). For each permission string encountered, MobileAudit either fetches or creates a `PermissionType` record, then associates it with the current scan through a `Permission` entity. This relational structure enables severity classification and risk scoring based on the protection level of each permission.

### Intent Filter and Component Detail Extraction

The helper function `get_intent_filter` in [`app/analysis.py`](https://github.com/mpast/mobileaudit/blob/main/app/analysis.py) (lines 76-95) handles complex component metadata. It creates `Component` records with type classification (activity, service, receiver, or provider), then walks through every intent filter to store `IntentFilter` rows with action and category data. For activity components specifically, it detects the main launcher entry point by identifying the combination of `android.intent.action.MAIN` and `android.intent.category.LAUNCHER`, setting the `main=True` flag on the corresponding `Activity` record.

### Digital Certificate Inspection

When `a.is_signed()` returns true, `get_info_certificate` (lines 97-119) extracts X.509 certificate data. The function iterates all signing certificates to capture version numbers, SHA-1 and SHA-256 fingerprints, issuer and subject distinguished names, signature algorithms, and hash algorithms. Each certificate generates a corresponding `Certificate` record linked to the scan, enabling validation of the APK's signing identity.

## Data Persistence and Model Structure

All extracted data persists through Django ORM operations. The [`app/models.py`](https://github.com/mpast/mobileaudit/blob/main/app/models.py) file defines the schema relationships, where `Scan` objects parent collections of `Permission`, `Component`, `IntentFilter`, `Activity`, and `Certificate` entities. Each extraction function calls `.save()` on its respective model instances, making the analyzed APK structure immediately available to the REST API and web interface without requiring manual database queries.

## Implementation Examples

### Triggering a Scan via Celery

```python
from app.worker.tasks import task_create_scan

# scan_id refers to a Scan object with an uploaded APK file

task_create_scan.delay(scan_id)

```

### Manual Component Extraction

```python
from app.analysis import APK, get_info_apk, get_info_certificate
from django.conf import settings
from app.models import Scan

scan = Scan.objects.get(pk=42)
apk_path = settings.BASE_DIR + scan.apk.url

# Initialize Androguard APK parser

apk = APK(apk_path)

# Extract metadata, permissions, and components

scan = get_info_apk(apk, scan)

# Extract signing certificates if present

certs = get_info_certificate(apk, scan)
print(f"Discovered {len(certs)} signing certificates")

```

### Querying Extracted Components

```python

# Retrieve all activities for a specific scan

activities = Activity.objects.filter(scan_id=42)
for activity in activities:
    print(f"{activity.name} - Main launcher: {activity.main}")

# List all declared permissions with severity levels

perms = Permission.objects.filter(scan_id=42)
for perm in perms:
    print(f"{perm.permission.name}: {perm.severity}")

```

## Summary

- MobileAudit uses **Androguard** as its core APK parsing engine within a Celery task framework defined in [`app/worker/tasks.py`](https://github.com/mpast/mobileaudit/blob/main/app/worker/tasks.py)
- The `task_create_scan` function orchestrates the analysis workflow through `analysis.analyze_apk`
- **File integrity** validation occurs first through `set_hash_app` with MD5, SHA-1, and SHA-256 hashing
- Component extraction happens in `get_info_apk` and `get_intent_filter` within [`app/analysis.py`](https://github.com/mpast/mobileaudit/blob/main/app/analysis.py)
- **Permissions**, **activities**, **services**, **receivers**, and **providers** are stored as separate Django model instances with full intent filter relationships
- **Digital certificates** are parsed and stored only when `a.is_signed()` confirms APK signing
- All data persists through Django ORM to enable web interface visualization and REST API access

## Frequently Asked Questions

### What Python library does MobileAudit use to parse APK files?

MobileAudit relies on **Androguard**, a powerful Python framework for Android application reverse engineering. The `APK` class from Androguard provides the foundation for manifest parsing, component enumeration, and certificate extraction in [`app/analysis.py`](https://github.com/mpast/mobileaudit/blob/main/app/analysis.py), enabling deep static analysis without requiring the Android SDK.

### How does MobileAudit detect the main entry point of an Android application?

During component extraction in `get_intent_filter`, MobileAudit checks for the specific intent filter combination of `android.intent.action.MAIN` and `android.intent.category.LAUNCHER`. When found in an activity, the system creates an `Activity` record with `main=True`, marking it as the application entry point for launcher icon generation.

### Where does MobileAudit store the extracted APK analysis data?

All extracted information persists through Django ORM models defined in [`app/models.py`](https://github.com/mpast/mobileaudit/blob/main/app/models.py). The system creates separate records for `Scan`, `Permission`, `Component`, `IntentFilter`, `Activity`, and `Certificate`, linking them through foreign key relationships to maintain structural integrity and enable complex querying across security scans.

### Can MobileAudit analyze unsigned APK files?

Yes, MobileAudit can process unsigned APKs, but certificate extraction is conditional. The `get_info_certificate` function only executes when `a.is_signed()` returns true, skipping certificate analysis for unsigned applications while still extracting all other components, permissions, and intent filters through the standard pipeline.