How MobileAudit Extracts and Analyzes APK Components: A Technical Deep Dive

MobileAudit leverages the Androguard library within a Celery-driven pipeline to decompile APK files, extract cryptographic hashes, permissions, activities, services, broadcast receivers, content providers, intent filters, and digital certificates, persisting all findings into Django ORM models for security analysis.

The open-source project mpast/mobileaudit provides a web-based platform for automated Android application security auditing. Understanding how MobileAudit extracts and analyzes APK components requires examining its Python backend architecture in app/analysis.py, which orchestrates static analysis through a series of specialized extraction functions against the uploaded binary.

The Analysis Pipeline Architecture

Task Initialization and APK Loading

In app/worker/tasks.py, the Celery task task_create_scan initiates the workflow by calling analysis.analyze_apk with the uploaded file path constructed as settings.BASE_DIR + scan.apk.url. This entry point triggers the complete static analysis sequence, delegating to specialized functions for hash computation, metadata extraction, and certificate analysis.

Cryptographic Hash Verification

Before component analysis begins, the system computes file integrity hashes. The set_hash_app function in app/analysis.py (lines 20-38) reads the APK in chunks to calculate MD5, SHA-1, and SHA-256 checksums, storing these values on the Scan model to ensure file authenticity tracking and duplicate detection.

Component Extraction Methodology

Core Metadata and Manifest Parsing

The get_info_apk function serves as the primary extraction engine in app/analysis.py (lines 35-74). It utilizes Androguard's APK class to retrieve the package name, version information, minimum and target SDK ranges, and the raw manifest XML. This function creates Component records for every activity, service, receiver, and provider discovered in the AndroidManifest.xml.

Permission Analysis

Within get_info_apk, the system iterates through a.get_permissions() to process security permissions (lines 48-57). For each permission string encountered, MobileAudit either fetches or creates a PermissionType record, then associates it with the current scan through a Permission entity. This relational structure enables severity classification and risk scoring based on the protection level of each permission.

Intent Filter and Component Detail Extraction

The helper function get_intent_filter in app/analysis.py (lines 76-95) handles complex component metadata. It creates Component records with type classification (activity, service, receiver, or provider), then walks through every intent filter to store IntentFilter rows with action and category data. For activity components specifically, it detects the main launcher entry point by identifying the combination of android.intent.action.MAIN and android.intent.category.LAUNCHER, setting the main=True flag on the corresponding Activity record.

Digital Certificate Inspection

When a.is_signed() returns true, get_info_certificate (lines 97-119) extracts X.509 certificate data. The function iterates all signing certificates to capture version numbers, SHA-1 and SHA-256 fingerprints, issuer and subject distinguished names, signature algorithms, and hash algorithms. Each certificate generates a corresponding Certificate record linked to the scan, enabling validation of the APK's signing identity.

Data Persistence and Model Structure

All extracted data persists through Django ORM operations. The app/models.py file defines the schema relationships, where Scan objects parent collections of Permission, Component, IntentFilter, Activity, and Certificate entities. Each extraction function calls .save() on its respective model instances, making the analyzed APK structure immediately available to the REST API and web interface without requiring manual database queries.

Implementation Examples

Triggering a Scan via Celery

from app.worker.tasks import task_create_scan

# scan_id refers to a Scan object with an uploaded APK file

task_create_scan.delay(scan_id)

Manual Component Extraction

from app.analysis import APK, get_info_apk, get_info_certificate
from django.conf import settings
from app.models import Scan

scan = Scan.objects.get(pk=42)
apk_path = settings.BASE_DIR + scan.apk.url

# Initialize Androguard APK parser

apk = APK(apk_path)

# Extract metadata, permissions, and components

scan = get_info_apk(apk, scan)

# Extract signing certificates if present

certs = get_info_certificate(apk, scan)
print(f"Discovered {len(certs)} signing certificates")

Querying Extracted Components


# Retrieve all activities for a specific scan

activities = Activity.objects.filter(scan_id=42)
for activity in activities:
    print(f"{activity.name} - Main launcher: {activity.main}")

# List all declared permissions with severity levels

perms = Permission.objects.filter(scan_id=42)
for perm in perms:
    print(f"{perm.permission.name}: {perm.severity}")

Summary

  • MobileAudit uses Androguard as its core APK parsing engine within a Celery task framework defined in app/worker/tasks.py
  • The task_create_scan function orchestrates the analysis workflow through analysis.analyze_apk
  • File integrity validation occurs first through set_hash_app with MD5, SHA-1, and SHA-256 hashing
  • Component extraction happens in get_info_apk and get_intent_filter within app/analysis.py
  • Permissions, activities, services, receivers, and providers are stored as separate Django model instances with full intent filter relationships
  • Digital certificates are parsed and stored only when a.is_signed() confirms APK signing
  • All data persists through Django ORM to enable web interface visualization and REST API access

Frequently Asked Questions

What Python library does MobileAudit use to parse APK files?

MobileAudit relies on Androguard, a powerful Python framework for Android application reverse engineering. The APK class from Androguard provides the foundation for manifest parsing, component enumeration, and certificate extraction in app/analysis.py, enabling deep static analysis without requiring the Android SDK.

How does MobileAudit detect the main entry point of an Android application?

During component extraction in get_intent_filter, MobileAudit checks for the specific intent filter combination of android.intent.action.MAIN and android.intent.category.LAUNCHER. When found in an activity, the system creates an Activity record with main=True, marking it as the application entry point for launcher icon generation.

Where does MobileAudit store the extracted APK analysis data?

All extracted information persists through Django ORM models defined in app/models.py. The system creates separate records for Scan, Permission, Component, IntentFilter, Activity, and Certificate, linking them through foreign key relationships to maintain structural integrity and enable complex querying across security scans.

Can MobileAudit analyze unsigned APK files?

Yes, MobileAudit can process unsigned APKs, but certificate extraction is conditional. The get_info_certificate function only executes when a.is_signed() returns true, skipping certificate analysis for unsigned applications while still extracting all other components, permissions, and intent filters through the standard pipeline.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →