Self-hosted service
rednaga/APKiD avatar
rednaga/APKiD

APKiD: YARA-Based Fingerprinting of Android APK Compilers, Packers, and Obfuscators

Android Application Identifier for Packers, Protectors, Obfuscators and Oddities - PEiD for Android

2,583 stars344 forksYARANOASSERTION

At a glance

What is it?
APKiD is a command-line tool from RedNaga that tells you how an Android APK was built. It identifies the compiler, packer, obfuscator, and any unusual properties by running a set of YARA rules against the APK and its DEX files. The README describes it as PEiD for Android.
Who is it for?
APKiD is a well-defined tool for a specific task: determining how an Android APK was produced. Security researchers, malware analysts, and app store reviewers who need to quickly classify APKs by compiler or protection mechanism will find it useful.
Can I use it commercially?
Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
Is it still maintained?
Yes. The repository last received commits 29 days ago.
What is it written in?
Mainly YARA, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What APKiD Identifies and Who Needs It

When a security researcher receives an Android APK, one of the first questions is how it was built. A standard app compiled with the Google Play SDK looks different from an app packed with a commercial app-shielding product, which in turn looks different from an app obfuscated with a third-party tool. Knowing the provenance often determines the next analysis step.

APKiD answers this question automatically. It runs a set of YARA rules against the APK file and its DEX classes and reports which compiler, packer, obfuscator, or anti-analysis technique it recognizes. The README summarizes the output category: many compilers, packers, obfuscators, and other 'weird stuff.'

The README references several published talks that describe specific use cases: detecting pirated and malicious apps by compiler fingerprint (rednaga.io, 2016), fast identification of commercial AppShielding products (NowSecure Connect 2019), and fast identification of Mobile RASP SDKs (BlackHat USA Arsenal 2023). These presentations reflect a security-focused audience: malware analysts, app store policy enforcement teams, and reverse engineering researchers.

The YARA Rule Architecture

APKiD's detection capability lives in its YARA rule files. YARA is a pattern-matching language used in malware research; APKiD applies it to Android bytecode rather than native code. The rules identify byte patterns in DEX files that correspond to specific compilers or protection tools.

The rule files are compiled from source before installation using the `prep-release.py` script. This compilation step is what makes the package installable; the raw `.yar` files require compilation into a format that the `yara-python-dex` library can load and execute. When new rules are added (either by the maintainers or by contributors), the compilation step must be re-run before the changes take effect.

The project accepts contributions for new detection rules. The README asks contributors to provide a file hash (MD5, SHA1, or SHA256) of the APK or DEX that the new rule targets, so the maintainers can verify the rule matches the intended target before merging. The README explicitly welcomes detections beyond packers: anti-disassembler tricks, anti-VM checks, and other 'interesting' behaviors are in scope.

The dependency on `yara-python-dex` rather than the standard `yara-python` is notable. `yara-python-dex` is a fork that adds DEX-specific scanning capabilities not present in the upstream YARA Python bindings. This means APKiD's YARA rules can match patterns inside DEX bytecode structures in ways that would not work with a standard YARA installation. The fork is maintained by MobSF (Mobile Security Framework) and is a runtime dependency rather than a build-time tool, so it must be installed on any system running APKiD.

Installing and Running APKiD

The simplest installation path is pip:

bash
pip install apkid

The package is published on PyPI and available for Python 3.10 and 3.11 according to the classifiers in setup.py. After installation, the basic usage runs APKiD against an APK, a DEX file, or a directory:

code
usage: apkid [-h] [-v] [-t TIMEOUT] [-r] [--scan-depth SCAN_DEPTH]
             [--entry-max-scan-size ENTRY_MAX_SCAN_SIZE] [--typing {magic,filename,none}] [-j]
             [-o DIR]
             [FILE [FILE ...]]

The `-j` flag produces JSON output, and `-o DIR` writes results to a directory. The `--typing` flag controls how APKiD determines whether a file is an APK or DEX: `magic` uses file headers, `filename` uses the extension, and `none` tries both. The `-t TIMEOUT` flag sets the YARA scan timeout in seconds per entry, which matters when scanning deeply nested archives or unusually large DEX files.

On Windows, APKiD requires a specific installation sequence to resolve the Yara dependency:

bash
pip uninstall -y yara-python yara-python-dex
pip install yara-python==3.11.0 wheel
pip wheel --wheel-dir=yara-python-dex git+https://github.com/MobSF/yara-python-dex.git
pip install --no-index --find-links=yara-python-dex yara-python-dex

The README notes that yara-python-dex conflicts with the standard yara-python package on Windows, so both must be removed before installing the pinned versions in order.

Running APKiD with Docker

Docker provides a clean environment that avoids the dependency issues described above. The README documents the complete Docker workflow:

bash
git clone https://github.com/rednaga/APKiD
cd APKiD/
docker build . -t rednaga:apkid
docker/apkid.sh ~/reverse/targets/android/example/example.apk

The `docker/apkid.sh` wrapper script mounts the target file into the container and runs APKiD against it. The README includes example output from this workflow:

code
[+] APKiD 2.1.0 :: from RedNaga :: rednaga.io
[*] example.apk!classes.dex
 |-> compiler : dx

The output structure identifies the archive entry (`example.apk!classes.dex`) and the detected attribute (`compiler : dx`). When multiple attributes are detected, each appears on a separate line under the entry. The container is built from the official Dockerfile which creates a non-root `appuser` and mounts `/input` as the working scratch directory.

Adding Custom Rules and Developing with APKiD

Teams that need to detect proprietary packers or internal build tools not covered by the public rule set can add their own YARA rules and recompile. The development workflow from the README:

bash
git clone https://github.com/rednaga/APKiD
cd APKiD
python prep-release.py
pip install -e .[dev,test]

The `-e` flag installs the package in editable mode, so changes to the Python source take effect immediately. Changes to YARA rules require re-running `prep-release.py` to recompile them before they are active.

If the dev install fails with permission errors, the README suggests adding `--user` to the pip command:

bash
pip install -e .[dev,test] --user

The test suite uses pytest and includes several test categories. Package maintainers publishing a new release must update the version in `apkid/__init__.py` and run `prep-release.py readme` to update the compiled rules before building the wheel and uploading to PyPI.

Dual License and Comparison with Androguard

APKiD uses a dual license structure. The GPL-3.0 license covers open-source use: projects distributed under GPL-compatible terms can include APKiD without a commercial agreement. The commercial license covers proprietary software: apps, services, or tools that are not released under a GPL-compatible license must obtain a commercial license from RedNaga. The README points to `LICENSE.COMMERCIAL` and `LICENSE.GPL` for the full terms of each.

This dual license model is common in security tooling and is more restrictive than permissive licenses like MIT or Apache-2.0. Teams embedding APKiD in a commercial product, an app scanning service, or any closed-source tool should contact RedNaga for the commercial license before deployment.

Androguard is a well-known alternative for Android application analysis. It focuses on decompilation, code flow analysis, and call graph generation rather than on compiler fingerprinting. Androguard tells you what the code does; APKiD tells you how it was built and protected. Teams performing full reverse engineering typically use both in sequence: APKiD first to understand the protection layer, then Androguard to analyze the underlying logic once the obfuscation approach is known. For teams that only need the provenance question answered, APKiD's focused rule set and fast YARA scan are the more efficient choice. Androguard does not produce compiler fingerprints or identify commercial app-shielding products, so these tools complement rather than replace each other.

Editorial conclusion

APKiD is a well-defined tool for a specific task: determining how an Android APK was produced. Security researchers, malware analysts, and app store reviewers who need to quickly classify APKs by compiler or protection mechanism will find it useful. It is not a static analysis engine or a decompiler; it answers the provenance question, not the code analysis question. Before using APKiD in a commercial product, confirm that the commercial license from RedNaga covers the intended use. The last push was on 2026-09-02.

Frequently asked questions

How do I add a new packer or obfuscator rule to APKiD?

The README asks contributors to open a GitHub issue with the file hash (MD5, SHA1, or SHA256) of an APK or DEX that demonstrates the new pattern, along with a description of what it is (obfuscated, packed, etc.). Pull requests with new YARA rules are welcome and must include the file hash so the maintainers can verify the rule before merging. After adding rules locally, re-run prep-release.py to recompile them.

Does APKiD require a commercial license for business use?

APKiD uses a dual license. The GPL-3.0 license covers open-source projects distributed under compatible terms. The commercial license is required for proprietary software, closed-source tools, or commercial services that embed APKiD. The LICENSE.COMMERCIAL file in the repository documents the commercial terms.

What is the difference between APKiD and a tool like Androguard?

APKiD answers the provenance question: how was the APK compiled, and is it packed or obfuscated? It uses YARA rules against DEX files and does not decompile code. Androguard answers the code analysis question: what does the code do, and how does control flow through the application? The two tools address different stages of Android reverse engineering.

Official sources

  1. Issues
  2. README
  3. rednaga/APKiD on GitHub
  4. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/rednaga-apkid.svg)](https://hysenlabs.com/projects/rednaga-apkid)