A Frida-based Android security research toolkit for extracting and analyzing runtime artifacts — DEX files, IL2CPP binaries, Unity assets, crypto keys, network traffic, and more.
Intended use: penetration testing, CTF challenges, security research, and reverse engineering of apps you own or have explicit permission to analyze.
📖 Full documentation: https://ykus4.github.io/enma
Requires Python 3.12+, uv, ADB in PATH, and a rooted device or emulator.
git clone https://github.com/ykus4/enma
cd enma
uv syncuv run enma setup # push frida-server to the device
uv run enma list # find the target package
uv run enma dump com.example.game -o ./dump # run the agents
uv run enma analyze ./dump # post-dump analysis
uv run enma report ./dump # → dump/report.html| Page | Contents |
|---|---|
| Subcommands | Every CLI command, with flags and examples |
| Agent Reference | What each of the 25 JS agents hooks and emits |
| Output Files | What lands in the dump directory |
| Architecture | System design, data flow, hook layers |
| Development | Project layout, tests, adding an agent |
Docs live in docs/ and are built with MkDocs:
uv sync --group docs
uv run mkdocs serveuv run ruff check src/ tests/
uv run pytestSee the Development guide for the project layout and how to add an agent.
Use only against apps you own or have explicit written authorization to analyze. Dumped files may contain sensitive cryptographic material — handle with care.
Licensed under the MIT License.