mirror of
https://github.com/QM4RS/FridaBox.git
synced 2026-09-16 06:02:22 +02:00
5140bfc6a7ad6840f7b0027befbd141c6fb0cecb
Integrate Frida Gadget into BlackBox guest startup, add the host workflow and controller tooling, and validate the complete sample hook flow on ARM64 Android 16.
FridaBox
FridaBox is an authorized mobile-security research MVP that runs an original,
unmodified APK inside BlackBox virtual processes and loads Frida Gadget before
the guest Application is created. It requires no root, frida-server, Magisk,
Zygisk, system-image changes, real PackageManager installation, APK patching,
repacking, or resigning.
The foundation is ALEX5402/NewBlackbox commit
89b59836c66f173756a4ae258cf379a957649820. The host application ID is
com.qm4rs.fridabox; existing engine namespaces remain unchanged.
MVP capabilities
- SAF import of one base APK into app-private, read-only storage.
- SHA-256 verification before and after BlackBox virtual installation.
- ARM64 native-library inspection; pure Java/Kotlin guests are accepted and
native guests without
arm64-v8aare rejected. - Per-guest instrumented or non-instrumented launches with virtual process stop before mode changes.
- Frida Gadget 17.16.0 bound to loopback, default port 27042, with conflict
fallback and
on_load=waitfor pre-Application.onCreate()hooks. - Process-local guest registry and controller-side ClassLoader selection.
- Debug sample guest proving
Target.add(2, 3)can be replaced with1337. - Reproducibly bundled Frida 17 Java agents using pinned
frida-java-bridge7.0.13 andfrida-compile19.0.5.
Start with docs/BUILDING.md, docs/USAGE.md, and docs/FRIDA_CONNECTION.md.
FridaBox is not undetectable. See docs/DETECTION_SURFACES.md and docs/LIMITATIONS.md.
The complete Android 16 device transcript is in docs/device-validation.log.
Description
Android research workspace for per-app Frida Gadget instrumentation: on-device JavaScript, desktop attach, and clean launches without root or APK patching.
androidandroid-securityarm64dynamic-analysisfridafrida-gadgetinstrumentationkotlinmobile-securityresearchreverse-engineeringvirtualization
Readme
Apache-2.0
23 MiB
Releases
2
Languages
Java
85.7%
Kotlin
6.2%
C++
2.8%
C
2.5%
AIDL
1.7%
Other
1%