Library and tools are compiled at once using cargo:
$ cargo build --release --workspace
The DroidWorks project includes a library, which can be used to build analysis and apk crawling tools, and several tools that are build upon this library.
To build and open the documentation for all the crates included in the DroidWorks library, simply run:
$ cargo doc --workspace --no-deps --open
Then, the droidworks crate can be imported in your project, and used after importing it with:
use droidworks::prelude::*;
The DroidWorks tools are accessible via different subcommands from the main binary:
$ cargo run --release -- -h
Here is a list of android application tools that are provided with droidworks:
aresourcesprints apk resources in aapt form.callgraphgenerates dex code callgraph.dexdissectdumps dex tables.disasis objdump for dex bytecode, and can also generate control flow graphs.hierarchygenerates classes hierarchy graph.manifestprints package manifest in classic xml format.nscprints apk network security configuration if there is.packageinfoprints various information about the given file.permissionsallow listing and manipulation of permissions list in an apk.statsprints basic statistics about found and missing classes.stripbuild a callgraph and iteratively strip methods that could lookup unknown class, method or field.typecheckruns a typechecking pass onto dalvik bytecode.
Moreover, it provides the two following utility commands:
gen-completionsgenerates completions file for shells.helpprints the complete command help.
$ cargo run --release -- <file> callgraph -r bytecode -o callgraph.dot
The generated dot file is generally too big to be processed by graphviz or other dot viewing tool. To address this issue, filters can be applied at the object (the fully qualified class name) and method level (name of the method solely, no argument), independently. The parameter is a (single-line mode) regex whose syntax is described here. The resulting callgraph then contains all the paths of method calls leading to all the selected object methods.
For example:
$ cargo run --release -- <file> callgraph -r bytecode -o callgraph.dot \
--target-object '^com/example/' \
--target-method 'string$'