# ReversecLabs/drozer

The Leading Security Assessment Framework for Android.

Repository: https://github.com/ReversecLabs/drozer
Canonical: https://ross.abutalabs.com/products/drozer
Homepage: https://labs.reversec.com/tools/drozer
Language: Python
License: NOASSERTION
License Family: other
Topics: drozer, android, security, pentesting, java, mobile, mobsec, reversec
Last push: 2026-04-08T07:54:54+00:00

## Health v2 (maintenance only)
Score: 57/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 76, release rhythm 8, longevity 100
- inputs: {"age_days": 5304, "days_push": 147, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 4597, forks 848 (observed 2026-08-28T04:08:54.775194+00:00)

## What it is
drozer is an open-source security assessment framework for Android that lets testers assume the role of an app and interact with the Android Runtime, other apps' IPC endpoints, and the underlying OS. It automates dynamic analysis tasks, supports exploit sharing, and is extensible with custom modules.

## Use cases
- find security vulnerabilities in Android apps and devices
- test Android app IPC endpoints for exposed attack surface
- run dynamic Java code on an Android device during pentests
- assess Android devices in production state without USB debugging
- automate repetitive tasks in Android security assessments
- extend with custom modules to test for specific weaknesses

## When to choose
- you need dynamic security analysis of Android apps or devices
- you want to probe IPC endpoints and app attack surfaces without writing custom test apps
- you need a scriptable, extensible Android pentesting toolkit

## When to avoid
- you need static-only code analysis of Android apps
- you need a stable release and cannot tolerate beta bugs like broken custom agent building
- you are testing iOS or non-Android mobile platforms

## Facets
- artifact type: framework
- maturity: active
- function: penetration-testing, security, reverse-engineering, cli
- domain: security, mobile-development, penetration-testing, android-tools
- platform: python, windows, cli
- tags: android-security, mobile-pentesting, ipc-testing, dynamic-analysis, exploitation-framework, android, linux, macos, docker

## Member repositories
- ReversecLabs/drozer (main) score 57

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:54.775194+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:19:48.560605+00:00, confidence not recorded.
  - readme: https://github.com/ReversecLabs/drozer (fetched 2026-08-28T04:08:54.775194+00:00, sha 69fbbf6f64a6)
  - homepage: https://labs.reversec.com/tools/drozer (fetched 2026-08-29T09:05:11.135359+00:00, sha 30dce8122865)
  - site_page: https://reversec.com/about-us (fetched 2026-08-29T09:05:11.138388+00:00, sha 865b562d7d2a)
- Data as of 2026-08-30T08:39:29.467469+00:00.
