Fast dex dump in memory based on frida.
Project description
FRIDA-DEXDump
Features
- support fuzzy search broken header dex.
- fix struct data of dex-header.
- compatible with all android version(frida supported).
- support loading as objection plugin ~
- pypi package has been released ~
Requires
Installation
From pypi
pip3 install frida-dexdump
frida-dexdump -h
From source
git clone https://github.com/hluwa/FRIDA-DEXDump
cd FRIDA-DEXDump/frida-dexdump
python3 main.py -h
Usage
-
Run
frida-dexdump
orpython3 main.py
to attach current frontmost application and dump dexs. -
Or, use command arguments:
-n: [Optional] Specify target process name, when spawn mode, it requires an application package name. If not specified, use frontmost application. -p: [Optional] Specify pid when multiprocess. If not specified, dump all. -f: [Optional] Use spawn mode, default is disable. -s: [Optional] When spawn mode, start dump work after sleep few seconds. default is 10s. -d: [Optional] Enable deep search maybe detected more dex, but speed will be slower. -h: show help.
-
Or, loading as objection plugin
- clone this repo and move
frida_dexdump
into your plugins folder, eg:git clone https://github.com/hluwa/FRIDA-DEXDump ~/Downloads/FRIDA-DEXDump; mv ~/Downloads/FRIDA-DEXDump/frida_dexdump ~/.objection/plugins/dexdump
- start objection with
-P
or--plugin-folder
your plugins folder, eg:objection -g com.app.name explore -P ~/.objection/plugins
- run command:
plugin dexdump search
to search and print all dexplugin dexdump dump
to dump all found dex.
- clone this repo and move
Project details
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
frida-dexdump-1.0.3.tar.gz
(20.0 kB
view hashes)
Built Distribution
Close
Hashes for frida_dexdump-1.0.3-py3-none-any.whl
Algorithm | Hash digest | |
---|---|---|
SHA256 | e4e06aad19c496ef73729fa763e41b795e119d85e30231b44b4527a5d490741c |
|
MD5 | 94e231b6fa102e88cffecaa709d00730 |
|
BLAKE2b-256 | 7042515446a68560b373631f53777c1afd1cade23532eaaf033de3657dad0658 |