Pinned apps, captured. No favours from the dev team.
Read an APK before it runs, then capture it live on an emulator that already trusts you.
Run the Android target
An emulator you never had to prepare.
Android target
Launch the bundled Android target, install the app you want to explore, and drive it on the embedded screen. Its traffic flows into this workbench.
A headless Android 13 emulator. No adb, no rooting. It's an add-on: download it in the app when you first need it.
Read an APK
Its endpoints, straight from the code.
APK analysis
Point the engine at an APK on this machine and run the pipeline. Each stage contributes facts; the fused surface is assembled from all of them.
- 1Unpack
- 2Decompile · jadx
- 3Extract network facts
- 4Dynamic pass
- 5Fuse into the surface
APK, split APKs or XAPK. The analysis runtime is an add-on you download once, in one click.
Or pair a real phone
A rooted device joins the same session.
Devices
Pair a rooted Android device with this workbench. Arm a device to show a QR the client scans, then accept its request to join the session.
Show a pairing code for a rooted Android device, 7.0 or newer.
The details
- Android
- 13 (API 33), AOSP image, no Google Play Services
- Devices
- Rooted, Android 7.0 (API 24) and newer, paired by QR code
- Virtualization
- KVM on Linux; Hyper-V, WHPX or AEHD on Windows. Slower software mode without it
- Recommended
- 8 GB RAM, 4 vCPUs
- Add-on
- The Android target (about 1.3 GB) downloads from apiaxess.dev when you click to get it: resumable, checked against its SHA-256, and installed for your user only
$ apiaxess analyze ./northwind-4.2.1.apk --allow-target api.northwind-retail.io --json
--allow-target is the same authorisation affirmation capture uses.