
drozer
drozer is a free dynamic analysis framework used to probe Android app IPC and attack surface for mobile security testers assessing devices they own.
0 upvotes · 0 downvotes
No ratings yet
- Pricing
- Free
- Platforms
- LinuxWindowsmacOS
- License
- Open source
- Reviewed
- Last reviewed 6 October 2026
What it is
A console that lets a tester act like an installed Android app, reaching other apps' exported components and the device itself through its interprocess messaging.
What it helps with
- Mapping the attack surface an app exposes through activities, services, providers, and receivers
- Querying exported content providers and checking them for injection or file access flaws
- Running on emulators or real devices without development mode enabled
Who it's for
Mobile penetration testers and app reviewers assessing Android apps and devices they own or are authorized to test.
Worth knowing
It uses a small agent app on the test device and a console that needs Java 11 or later. The current line is a Python 3 rewrite still marked beta, so building custom agents is out of scope for now.
Who maintains it now?
Reversec, the team previously known as WithSecure Labs.
How does the console reach the test device?
Over the network on a listening port, or over USB using adb port forwarding.
Is there a ready-made container?
Yes. A Docker image is published for running it.
Discussion & reviews
0 comments
No contributions yet. Be the first to review or comment.