mirror of
https://github.com/QM4RS/FridaBox.git
synced 2026-09-16 02:11:50 +02:00
bf5f73e07a2e407e4a9f2bd64bf4752cf685db79
FridaBox
FridaBox is an authorized mobile-security research workspace that runs an original,
unmodified APK inside private virtual processes and loads Frida Gadget before
the guest Application is created. It requires no root, frida-server, Magisk,
Zygisk, system-image changes, real PackageManager installation, APK patching,
repacking, or resigning.
The host application ID and Android namespace are both com.qm4rs.fridabox.
Third-party engine provenance is isolated in THIRD_PARTY_NOTICES.md.
MVP capabilities
- SAF import of one base APK into app-private, read-only storage.
- SHA-256 verification before and after private virtual installation.
- ARM64 native-library inspection; pure Java/Kotlin guests are accepted and
native guests without
arm64-v8aare rejected. - Per-guest instrumented or non-instrumented launches with virtual process stop before mode changes.
- Frida Gadget 17.16.0 bound to loopback, default port 27042, with conflict
fallback and
on_load=waitfor pre-Application.onCreate()hooks. - Process-local guest registry and controller-side ClassLoader selection.
- Debug sample guest proving
Target.add(2, 3)can be replaced with1337. - Reproducibly bundled Frida 17 Java agents using pinned
frida-java-bridge7.0.13 andfrida-compile19.0.5.
Start with docs/BUILDING.md, docs/USAGE.md, and docs/FRIDA_CONNECTION.md.
FridaBox is not undetectable. See docs/DETECTION_SURFACES.md and docs/LIMITATIONS.md.
The complete Android 16 device transcript is in docs/device-validation.log.
Description
No description provided
androidandroid-securityarm64dynamic-analysisfridafrida-gadgetinstrumentationkotlinmobile-securityresearchreverse-engineeringvirtualization
Readme
Apache-2.0
22 MiB
Languages
Java
85.7%
Kotlin
6.2%
C++
2.8%
C
2.5%
AIDL
1.7%
Other
1%