RevDroidLive

RevDroid: Android Security Analysis Decompile and scan locally.
Hunt with an AI agent.

RevDroid runs a 12-phase static analysis on your own machine, then an AI agent reasons over the results to build verifiable exploit chains. The APK never leaves your machine.

Buy on Wixzel StoreOne-time license: $29 Regular, $129 Extended.

RevDroid screenshots

1 / 8

What RevDroid does

A self-hosted, AI-assisted Android APK security analyzer. A local agent runs a 12-phase static scan on your machine; an AI agent turns findings into verifiable exploit chains.

Local-first analysis

All decompilation and scanning run on a Node agent on your machine, bound to 127.0.0.1. APK bytes never leave your machine; only findings and small code snippets reach the AI layer.

12-phase static pipeline

Unpack, framework, signing, resources, code, secrets, trackers, files, binaries, packer detection, behaviour, and strings. Each phase streams to the dashboard live.

AI exploit-chain tracking

A per-project AI agent tracks bug-bounty hypotheses as multi-step chains: hypothesis, steps with status, and impact, seeded from canonical Android attack templates. Chains, not checklists.

Framework detection

Detects and adapts to Flutter, React Native, Xamarin, Unity, and native Android apps, including detected ABIs.

Secret and credential scanning

Finds hardcoded API keys and credentials for common cloud and SaaS providers, plus private keys and OAuth tokens.

Manifest and component review

Flags debuggable, allowBackup, cleartext traffic, exported components, deep links, and network security config.

Binary, packer, and signing checks

ELF hardening checks (NX, PIE, RELRO, stack canary, stripped symbols), packer and obfuscator detection, certificate and signature analysis, tracker detection across 40+ SDKs, and behaviour signals.

Device tooling over ADB

Connect Android devices over USB or Wi-Fi, inspect device security posture, browse installed apps, view the live screen with remote input, and pull an installed APK straight into a project.

Who RevDroid is for

Bug bounty hunters

Hunters who want speed to a valid finding and signal over noise, with the target app kept private to their own machine.

Mobile pentesters

Consultants running mobile assessments who need repeatable coverage and evidence, including code snippets, for a report.

AppSec engineers

In-house teams reviewing their own Android builds for secrets, misconfigurations, and risky components before release.

Security teams

Teams that self-host a shared Android-security tool, with Google sign-in and per-conversation AI cost visibility.

Good to know before you buy

  • RevDroid is for authorized security testing only: your own apps, bug-bounty programs you are enrolled in, or intentionally vulnerable and CTF apps.
  • The AI features use your own OpenRouter API key and incur usage costs billed by the provider. RevDroid includes no API credits. Static analysis runs locally and needs no paid service.
  • Android only. RevDroid does not analyze iOS apps and does not test web apps.
  • Self-hosted: you supply and run MongoDB, a Google OAuth client, and the model API key. It is not a hosted account.
How it works

How RevDroid works

Running, in 4 steps.

  1. 01

    Pair the local agent

    Start the Node agent on your machine. It generates a one-time pairing token and listens on 127.0.0.1:8071; paste the token into the dashboard.

  2. 02

    Add an APK

    Upload an APK file, or pull an installed package off a connected Android device over ADB. APKs are de-duplicated by SHA-256.

  3. 03

    Run a scan

    The agent unpacks the APK and runs 12 analysis phases, streaming each result to the dashboard as it completes.

  4. 04

    Hunt with the AI agent

    Open the per-project AI chat. It reads your scan data through the agent, proposes multi-step exploit chains, and tracks verification steps.

Use cases

What RevDroid is used for

Where it earns its place.

Triage an APK for bounty-worthy issues

Upload or pull an APK, run the 12-phase scan, and ask the AI agent for the most promising exploit chain.

Pre-release review of your own build

Scan an internal APK for hardcoded secrets, exported components, cleartext traffic, and weak crypto before it ships.

Framework-aware assessment

Assess Flutter, React Native, Xamarin, Unity, or native apps, with the framework and ABIs detected up front.

Learning Android security on CTF targets

Work intentionally vulnerable apps and let the AI agent explain why a finding matters and how the steps chain together.

Comparison

RevDroid vs. alternatives

How RevDroid compares.

vs.RevDroidAlternative
Cloud APK scannersDecompiles and scans on your own machine; the APK never leaves it.Typically require uploading the APK to a hosted service.
Checklist-style static scannersA 12-phase pipeline plus an AI agent that connects findings into verifiable, multi-step exploit chains.A flat list of isolated findings, without reasoning about how they connect.
Manual reverse engineeringAutomates unpacking and a dozen analysis passes, then adds an AI copilot that tracks hypotheses across a project.Decompiling by hand and grepping through smali, which is slow and easy to miss things in.
FAQ

Frequently asked questions

Common questions about RevDroid.

Does RevDroid upload my APK anywhere?
No. In RevDroid, decompilation and scanning run locally through the agent on your machine. Only findings and small code snippets are used by the AI layer.
Does RevDroid need a paid AI key?
The AI features in RevDroid use a model through your own OpenRouter API key and incur usage costs billed to you by the provider. Static analysis works without any key.
How does RevDroid show AI cost?
RevDroid displays per-conversation token and cost totals in the dashboard, for visibility only. It includes no billing, subscriptions, or credits.
Which app frameworks does RevDroid support?
RevDroid detects and adapts to Flutter, React Native, Xamarin, Unity, and native Android apps, including detected ABIs.
Do I need a physical device to use RevDroid?
No. RevDroid lets you upload an APK directly. A connected device unlocks pulling installed apps and the ADB device tooling.
Does RevDroid analyze iOS apps?
No. RevDroid is Android-specialized by design and does not analyze iOS apps.
What do I need to run RevDroid?
RevDroid needs Node.js 18 or later, a Java JDK for apktool and keytool, Android platform-tools with adb on your PATH, a MongoDB instance, a Google OAuth client for sign-in, and an OpenRouter API key for the AI agent.
Does RevDroid include a report writer or an autonomous hunt mode?
No. This release of RevDroid provides the static pipeline, the AI chat, and exploit-chain tracking. A report writer and an autonomous mode are not part of it.
Is it legal to use RevDroid?
RevDroid is for authorized security testing only: your own apps, bug-bounty programs you are enrolled in, or intentionally vulnerable and CTF apps. You are responsible for having permission to test any app you analyze.
Who makes RevDroid?
RevDroid is built and operated by Wixzel, an independent software company founded in 2018 by Aqeel Shamsudheen and based in Thrissur, Kerala, India.