Tool demonstration

Android,
made analyzable.

FMD automates the extraction and scanning of pre-installed Android apps—turning device images into structured inventories and analysis results for security research.

GPL-3.0 Docker-based GraphQL API
install.sh
Docker Compose

Check system & launch with one command:

curl -fsSL https://firmwaredroid.github.io/install.sh | bash
1
Preflight CheckValidates Docker, ports, OS & disk space
2
Zero-Config InitAutomated bootstrap for TLS & credentials
3
Run & Output PasswordsDeploys stack & prints admin secrets
01

The challenge

Streamlining Android firmware research

Android device images contain proprietary binaries, pre-installed applications, and heterogeneous file formats. Studying them repeatedly requires extraction, indexing, tool orchestration, and a consistent way to retrieve results.

FMD automates that process. It can scan individual APK files, but its primary focus is the analysis of pre-installed apps extracted from Android firmware.

Built for

  • Security researchersInvestigating pre-installed Android software
  • Empirical researchersBuilding repeatable analysis studies
  • Software Engineers & Tool developersAdding analyzers, benchmarking, or querying collected results
02

End-to-end workflow

From a device image to research-ready results.

01

Import

Place a firmware archive in FMD storage and start an extraction job.

02

Extract

Workers unpack supported formats and locate files and pre-installed APKs.

03

Inventory

Paths, hashes, firmware metadata, and application metadata become structured records.

04

Analyze

Queue APKs for static analyzers, decompilers, fuzzy hashing, or custom tooling.

05

Query

Retrieve inventories and reports through GraphQL or the underlying database.

Docker Compose Redis Queue workers Django + React MongoDB + blob storage
03

Modular by design

Multiple analysis perspectives in one pipeline.

Static analysis

Integrations include AndroGuard, APKiD, Exodus-Core, FlowDroid, MobSFScan, Trueseeing, and Quark-Engine.

Firmware extraction

Extraction tooling includes Binwalk, Unblob, payload dumpers, lpunpack, and imgpatchtools.

Identification

Create file inventories and cryptographic metadata with support for TLSH fuzzy hashing.

Extensibility

Use GraphQL, database records, and worker architecture to integrate custom analyses.

Supported tooling changes over time. Consult the project README for the authoritative list and deprecation notes.

04

Research data

A structured foundation for device studies.

Research data modelRepresentative API field groups
Android firmwarevendor · detected version · file size · indexed date · hashes · storage paths
Android applicationspackage name · filename · firmware path · file size · hashes · report references
Analysis reportsscanner name/version · manifest data · SDK targets · permissions · tool-specific findings

Designed for reuse

FMD stores extracted firmware, APKs, metadata, and scanner output in blob storage and MongoDB. GraphQL enables programmatic exploration and downstream research tooling.

PUBLIC DATASETRelease forthcoming

No official downloadable FMD dataset is currently linked from the project resources.

Supports studies ofSupply chainsPatch gapsSoftware evolutionOver-privileged componentsPrivacyMalwareCompliance
05

Tool demonstration

Follow the complete analysis pipeline.

Recorded walkthrough forthcoming

The documentation below provides a reproducible path through the demo today.Start with the setup guide

Demonstration path

  1. 01Deploy the Docker-based FMD environment
  2. 02Import an Android firmware image
  3. 03Monitor extraction and inventory jobs
  4. 04Queue selected APKs for analysis
  5. 05Query and inspect resulting reports

Research prototype. FMD has a minimal set of security features and is not production-ready. Dynamic analysis remains work in progress. Firmware redistribution, provenance, privacy, licensing, and the resource footprint of large-scale analyses require study-specific consideration.