How MobileAudit Extracts and Analyzes APK Components: A Technical Deep Dive
MobileAudit leverages the Androguard library within a Celery-driven pipeline to decompile APK files, extract cryptographic hashes, permissions, activities, services, broadcast receivers, content providers, intent filters, and digital certificates, persisting all findings into Django ORM models for security analysis.
The open-source project mpast/mobileaudit provides a web-based platform for automated Android application security auditing. Understanding how MobileAudit extracts and analyzes APK components requires examining its Python backend architecture in app/analysis.py, which orchestrates static analysis through a series of specialized extraction functions against the uploaded binary.
The Analysis Pipeline Architecture
Task Initialization and APK Loading
In app/worker/tasks.py, the Celery task task_create_scan initiates the workflow by calling analysis.analyze_apk with the uploaded file path constructed as settings.BASE_DIR + scan.apk.url. This entry point triggers the complete static analysis sequence, delegating to specialized functions for hash computation, metadata extraction, and certificate analysis.
Cryptographic Hash Verification
Before component analysis begins, the system computes file integrity hashes. The set_hash_app function in app/analysis.py (lines 20-38) reads the APK in chunks to calculate MD5, SHA-1, and SHA-256 checksums, storing these values on the Scan model to ensure file authenticity tracking and duplicate detection.
Component Extraction Methodology
Core Metadata and Manifest Parsing
The get_info_apk function serves as the primary extraction engine in app/analysis.py (lines 35-74). It utilizes Androguard's APK class to retrieve the package name, version information, minimum and target SDK ranges, and the raw manifest XML. This function creates Component records for every activity, service, receiver, and provider discovered in the AndroidManifest.xml.
Permission Analysis
Within get_info_apk, the system iterates through a.get_permissions() to process security permissions (lines 48-57). For each permission string encountered, MobileAudit either fetches or creates a PermissionType record, then associates it with the current scan through a Permission entity. This relational structure enables severity classification and risk scoring based on the protection level of each permission.
Intent Filter and Component Detail Extraction
The helper function get_intent_filter in app/analysis.py (lines 76-95) handles complex component metadata. It creates Component records with type classification (activity, service, receiver, or provider), then walks through every intent filter to store IntentFilter rows with action and category data. For activity components specifically, it detects the main launcher entry point by identifying the combination of android.intent.action.MAIN and android.intent.category.LAUNCHER, setting the main=True flag on the corresponding Activity record.
Digital Certificate Inspection
When a.is_signed() returns true, get_info_certificate (lines 97-119) extracts X.509 certificate data. The function iterates all signing certificates to capture version numbers, SHA-1 and SHA-256 fingerprints, issuer and subject distinguished names, signature algorithms, and hash algorithms. Each certificate generates a corresponding Certificate record linked to the scan, enabling validation of the APK's signing identity.
Data Persistence and Model Structure
All extracted data persists through Django ORM operations. The app/models.py file defines the schema relationships, where Scan objects parent collections of Permission, Component, IntentFilter, Activity, and Certificate entities. Each extraction function calls .save() on its respective model instances, making the analyzed APK structure immediately available to the REST API and web interface without requiring manual database queries.
Implementation Examples
Triggering a Scan via Celery
from app.worker.tasks import task_create_scan
# scan_id refers to a Scan object with an uploaded APK file
task_create_scan.delay(scan_id)
Manual Component Extraction
from app.analysis import APK, get_info_apk, get_info_certificate
from django.conf import settings
from app.models import Scan
scan = Scan.objects.get(pk=42)
apk_path = settings.BASE_DIR + scan.apk.url
# Initialize Androguard APK parser
apk = APK(apk_path)
# Extract metadata, permissions, and components
scan = get_info_apk(apk, scan)
# Extract signing certificates if present
certs = get_info_certificate(apk, scan)
print(f"Discovered {len(certs)} signing certificates")
Querying Extracted Components
# Retrieve all activities for a specific scan
activities = Activity.objects.filter(scan_id=42)
for activity in activities:
print(f"{activity.name} - Main launcher: {activity.main}")
# List all declared permissions with severity levels
perms = Permission.objects.filter(scan_id=42)
for perm in perms:
print(f"{perm.permission.name}: {perm.severity}")
Summary
- MobileAudit uses Androguard as its core APK parsing engine within a Celery task framework defined in
app/worker/tasks.py - The
task_create_scanfunction orchestrates the analysis workflow throughanalysis.analyze_apk - File integrity validation occurs first through
set_hash_appwith MD5, SHA-1, and SHA-256 hashing - Component extraction happens in
get_info_apkandget_intent_filterwithinapp/analysis.py - Permissions, activities, services, receivers, and providers are stored as separate Django model instances with full intent filter relationships
- Digital certificates are parsed and stored only when
a.is_signed()confirms APK signing - All data persists through Django ORM to enable web interface visualization and REST API access
Frequently Asked Questions
What Python library does MobileAudit use to parse APK files?
MobileAudit relies on Androguard, a powerful Python framework for Android application reverse engineering. The APK class from Androguard provides the foundation for manifest parsing, component enumeration, and certificate extraction in app/analysis.py, enabling deep static analysis without requiring the Android SDK.
How does MobileAudit detect the main entry point of an Android application?
During component extraction in get_intent_filter, MobileAudit checks for the specific intent filter combination of android.intent.action.MAIN and android.intent.category.LAUNCHER. When found in an activity, the system creates an Activity record with main=True, marking it as the application entry point for launcher icon generation.
Where does MobileAudit store the extracted APK analysis data?
All extracted information persists through Django ORM models defined in app/models.py. The system creates separate records for Scan, Permission, Component, IntentFilter, Activity, and Certificate, linking them through foreign key relationships to maintain structural integrity and enable complex querying across security scans.
Can MobileAudit analyze unsigned APK files?
Yes, MobileAudit can process unsigned APKs, but certificate extraction is conditional. The get_info_certificate function only executes when a.is_signed() returns true, skipping certificate analysis for unsigned applications while still extracting all other components, permissions, and intent filters through the standard pipeline.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →