How to Analyze an APK: A Beginner's Guide to Android Static Analysis
Analyzing an APK means inspecting an Android app's package without running it: reading what permissions it declares, which parts of it other apps can reach, who signed it, and what its code contains. This guide walks through the beginner workflow and the free tools used at each step.
- An APK is a ZIP archive holding the compiled manifest, code (
classes.dex), resources, native libraries and the developer's signature. - Work in order: get the file with adb[3], decode the manifest with aapt2[1], verify the signer with apksigner[2], then decompile code if needed.
- Check permissions, exported components, debuggable/backup/cleartext flags and the signing certificate fingerprint.
- Analyze only apps you are authorized to inspect, and never run a suspicious APK on your everyday phone.
What an APK contains
An APK is a ZIP archive. You can open one with any unzip tool. The parts that matter for analysis:
| File or folder | What it holds |
|---|---|
AndroidManifest.xml | The app's declaration: package name, permissions, components, SDK versions. Stored in a compiled binary XML format. |
classes.dex (and classes2.dex...) | The compiled app code. |
res/ and resources.arsc | Layouts, images and the compiled resource table, including network_security_config if present. |
lib/ | Native libraries per CPU architecture. |
META-INF/ and the signing block | The developer's signature, which proves who built the package. |
Before you start: stay safe and legal
Analyze only apps you own, have permission to test, or may lawfully inspect. Never install an unknown APK on your everyday phone to "see what it does". Use static analysis first, and run anything suspicious only on an emulator or spare device.
Step 1: Get the APK file
If the app is installed on a device you control, use the Android Debug Bridge (adb):[3]
adb shell pm path com.example.app
# package:/data/app/.../base.apk
adb pull /data/app/.../base.apk app.apk
Many apps install as several split APKs (base plus configuration splits). pm path lists all of them; pull each one. The base APK holds the manifest and main code.
Step 2: Read the manifest
The Android SDK's aapt2 tool decodes the manifest:[1]
aapt2 dump badging app.apk
aapt2 dump xmltree app.apk --file AndroidManifest.xml
The first command prints a summary (package, version, SDK levels, permissions). The second prints the full element tree. Look for:
- Permissions that do not match what the app claims to do.
- Exported components (
android:exported="true"): activities, services, receivers and providers other apps can reach. Check whether each is guarded by a permission. Since Android 12, any component with an intent filter must declareandroid:exportedexplicitly, or the app cannot be installed.[5] - Flags such as
android:debuggable="true",android:allowBackup, andusesCleartextTraffic. - Deep links: intent filters with a
VIEWaction and a URI scheme, and whether they are verified App Links. Verification relies on a Digital Asset Links file served at/.well-known/assetlinks.jsonon the linked host.[6] - SDK levels: an old
targetSdkVersionmeans the app opts out of newer platform protections.
Step 3: Check who signed it
The apksigner tool verifies the signature and prints the signing certificate:[2]
apksigner verify --print-certs app.apk
Compare the certificate's SHA-256 fingerprint with the one the developer publishes or with the version from Google Play. A mismatch suggests a repackaged or tampered build. A debug certificate on a release app is also a warning sign.
Step 4: Look at the code and resources
Two free tools go further than the manifest:
- apktool decodes resources and disassembles the code to readable smali:
apktool d app.apk -o out - jadx decompiles the code back to approximate Java:
jadx -d out-src app.apk
Useful things to search for: hard-coded URLs and API endpoints, embedded keys or credentials (which should never ship in an app), the names of analytics and advertising SDKs, and calls related to certificate validation, such as a custom TrustManager. Decompiled output is approximate, so treat it as a lead to confirm, not as proof.
Static versus dynamic analysis
Everything above is static: you inspect files without running the app. It is fast and safe, but it cannot show what the app does at runtime, such as which servers it really contacts or what it sends. Dynamic analysis runs the app in a controlled environment and observes it. The OWASP Mobile Application Security Testing Guide covers both in depth.[4]
The fast route: App Checker
If you only need the manifest-level picture, App Checker's APK analyzer does step 2 in your browser: permissions with risk labels, an exported-components table, deep links, certificate pinning from the network security config, and a reconstructed AndroidManifest.xml you can download. It does not decompile code or check signatures, so use the tools above for those.
Frequently asked questions
Can I analyze an APK without installing it?
Yes. Static analysis reads the file only; the app is never installed or run. Tools like aapt2, apktool, jadx and App Checker work this way.
How do I get the APK of an app on my phone?
Use adb: run "adb shell pm path
Is it legal to decompile an APK?
It depends on the app, your purpose and your country. Analyzing your own apps or apps you are authorized to test is generally fine; check licenses and local law before inspecting third-party software.
What is the difference between an APK and an AAB?
An AAB (Android App Bundle) is the format developers upload to Google Play. Play generates device-specific APKs from it. You analyze APKs, not AABs, from an installed app.
What does "exported" mean in an AndroidManifest?
An exported component can be started or reached by other apps on the device. Android 12 and higher require the exported attribute to be declared explicitly for components that use intent filters.
How can I tell if an APK was signed by the original developer?
Run apksigner with the print-certs option and compare the signing certificate's SHA-256 fingerprint with one the developer publishes or with the Play Store build. A mismatch suggests a repackaged app.
What is a split APK?
Modern apps are often installed as a base APK plus extra "split" APKs for screen density, CPU architecture or language. The base APK contains the manifest and main code.
Which free tools do researchers use for APK analysis?
Common free choices are aapt2 and apksigner from the Android SDK, apktool for resources and smali, and jadx for decompiling code. The OWASP MASTG describes workflows built around them.
Can App Checker analyze an AAB file?
No. The APK analyzer expects an APK. An AAB (Android App Bundle) is an upload format for Google Play, and you analyze the APKs installed on a device instead.
- aapt2 — Android Developers — dumping badging and manifest xmltree from an APK.
- apksigner — Android Developers — verifying signatures and printing certificates.
- Android Debug Bridge (adb) — Android Developers — pulling APK files from a connected device.
- OWASP Mobile Application Security Testing Guide (MASTG) — static and dynamic mobile app testing methodology.
- Behavior changes: Apps targeting Android 12 — Android Developers — explicit android:exported requirement for components with intent filters.
- Verify Android App Links — Android Developers — autoVerify and the Digital Asset Links file at /.well-known/assetlinks.json.