AppSecNews
Mobile Security Open source Established

Drozer

by Reversec

Android security assessment framework that uses an on device agent to enumerate and interact with exported app components and IPC endpoints.

Visit labs.reversec.com (leaves AppSecNews, opens in a new tab) Leaves AppSecNews for the vendor's own site.

No endorsements yet

Run Drozer in production? A named recommendation helps the next team shortlisting it.

Recommend this tool

Endorsers verify their identity through LinkedIn. Titles and companies are self declared, shown as they were when each person signed, and reviewed by an editor before anything is published. Endorsements are never paid for.

What we still need to verify : 2 points in this profile are not yet confirmed against vendor documentation.
  • Compatibility with current Android releases: confirm, as agent based tooling is sensitive to platform changes
  • Current maintainer and project home after the move to Reversec: confirm

Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.

What it does

Drozer splits into two halves: a console on your workstation and an agent application installed on the Android device. The console connects to the agent, and every command you type executes inside the agent's process on the device. That matters because Android's security model is built around inter process communication, and the only way to exercise an exported activity, service, broadcast receiver or content provider the way a malicious app would is to be an app on the same device.

From that position you enumerate the attack surface. Drozer lists installed packages and their declared components, shows which are exported and what permissions guard them, then lets you interact with them: start an activity with attacker chosen extras, bind to a service and send it messages, query or update a content provider, and broadcast intents. It can read a provider that forgot to set a permission, traverse paths through one that builds file paths from untrusted input, and fuzz component inputs to find crashes. The module system is extensible in Python, so an assessor can codify a new check and reuse it.

Where it fits

This is a manual assessment tool for a penetration tester or an Android engineer validating their own component exposure, run against a test device or emulator with a debug build or a repackaged release build installed. It complements static review rather than replacing it: you read the manifest to form a hypothesis about what is exposed, then use Drozer to prove whether the exposure is exploitable. You need physical or emulated device access and the ability to install the agent, so it does not run against production handsets.

Strengths

  • Executes from an on device app context, which is the only faithful way to test IPC exposure.
  • Turns manifest reading into demonstrated exploitation, producing evidence a developer cannot dismiss as theoretical.
  • Content provider testing, including permission and path traversal checks, is thorough and quick to run.

Limitations

  • Agent based tooling is tightly coupled to Android internals, and platform changes across releases have repeatedly caused compatibility friction. Check it works on your target version before planning around it.
  • Maintenance has been intermittent across changes of ownership, so it does not track new Android features as quickly as commercial tooling.
  • Scope is deliberately narrow. It says nothing about native code, transport security, cryptography or backend APIs, so it is one instrument in a larger kit.

Who it suits

Android penetration testers and platform security engineers who need to prove exported component issues. Teams looking for automated scanning across a portfolio, or any iOS coverage at all, are in the wrong place.

Used Drozer? Recommend it under your own name and title.

Recommend this tool