Import
Place a firmware archive in FMD storage and start an extraction job.
Tool demonstration
FMD automates the extraction and scanning of pre-installed Android apps—turning device images into structured inventories and analysis results for security research.
Check system & launch with one command:
curl -fsSL https://firmwaredroid.github.io/install.sh | bashThe challenge
Android device images contain proprietary binaries, pre-installed applications, and heterogeneous file formats. Studying them repeatedly requires extraction, indexing, tool orchestration, and a consistent way to retrieve results.
FMD automates that process. It can scan individual APK files, but its primary focus is the analysis of pre-installed apps extracted from Android firmware.
Built for
End-to-end workflow
Place a firmware archive in FMD storage and start an extraction job.
Workers unpack supported formats and locate files and pre-installed APKs.
Paths, hashes, firmware metadata, and application metadata become structured records.
Queue APKs for static analyzers, decompilers, fuzzy hashing, or custom tooling.
Retrieve inventories and reports through GraphQL or the underlying database.
Modular by design
Integrations include AndroGuard, APKiD, Exodus-Core, FlowDroid, MobSFScan, Trueseeing, and Quark-Engine.
Extraction tooling includes Binwalk, Unblob, payload dumpers, lpunpack, and imgpatchtools.
Create file inventories and cryptographic metadata with support for TLSH fuzzy hashing.
Use GraphQL, database records, and worker architecture to integrate custom analyses.
Supported tooling changes over time. Consult the project README for the authoritative list and deprecation notes.
Research data
FMD stores extracted firmware, APKs, metadata, and scanner output in blob storage and MongoDB. GraphQL enables programmatic exploration and downstream research tooling.
No official downloadable FMD dataset is currently linked from the project resources.
Tool demonstration
Recorded walkthrough forthcoming
The documentation below provides a reproducible path through the demo today.Start with the setup guideDemonstration path
Research prototype. FMD has a minimal set of security features and is not production-ready. Dynamic analysis remains work in progress. Firmware redistribution, provenance, privacy, licensing, and the resource footprint of large-scale analyses require study-specific consideration.
Documentation
Case Studies
Unpacking off-the-shelf, uncertified Android TV streaming boxes to uncover pre-flashed click-fraud botnets, trojanized system daemons, and hidden C2 communications.
Read case studyA step-by-step workflow demonstrating how researchers can submit and analyze individual APKs across FMD's parallel analysis workers to generate unified findings.
The peer-reviewed IEEE publication evaluating FirmwareDroid across diverse OEM firmware images, quantifying pre-installed apps and permission over-privileging at scale.
Read case study