| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
| Name | Name | Last commit date | ||
|---|---|---|---|---|
DuckDetector is an Android security detection application focusing on local, on-device evidence collection. It is designed to identify Root-related tampering, runtime Hooks, Mount operations, KeyStore integrity (Attestation Trust), and virtualized execution environments. This application combines a Jetpack Compose UI interface, modular Kotlin detection packages, and low-level C++ / assembly probes to present detailed detection results, method coverage, and scanning status summaries through structured cards.
Please read the DuckDetector coding standards before submitting changes to the codebase, workflows, or git history.
The app currently supports heuristic detection in the following security domains:
Bootloader · Custom ROM · Dangerous Apps · Kernel Check · LSPosed · Memory · Mount · Native Root · Play Integrity Fix · SELinux · SU · System Properties · TEE · Virtualization · Zygisk
In addition, the project contains helper modules such as dashboard, settings, and deviceinfo to provide data aggregation, user controls, and device context visualization.
| Dimension / Target | Notes |
|---|---|
| Android Version | Supports Android 10+ (minSdk 29), built based on targetSdk 37 / compileSdk 37.0. |
| Architecture (ABI) | Low-level probes are implemented via the NDK layer; some low-level trap paths are optimized primarily for the arm64-v8a architecture. |
| Environment Requirements | Runs without root permissions, suitable for stock official systems as well as various customized/modified environments. |
| Coverage Performance | When OEM manufacturers or strict sandbox rules restrict access, some checks may downgrade to support, unavailable, or low-coverage status. |
| Network Dependency | Completely local by default. Built-in TEE revocation credentials run offline, generating traffic only during a manual network refresh. |
Duck-Detector-Refactoring/
├─ app/
│ ├─ src/main/java/com/eltavine/duckdetector/
│ │ ├─ core/ # Core common components and foundations
│ │ ├─ features/ # Individual detection feature modules
│ │ └─ ui/ # Global common UI and themes
│ └─ src/main/cpp/ # Low-level C++ / Assembly probe source code
├─ build-logic/ # Gradle composite build logic
├─ gradle/ # Gradle wrapper configuration
├─ scripts/ # Automation or helper scripts
├─ build.gradle.kts
└─ settings.gradle.kts
Most detection feature modules (features) strictly follow this clear package structure:
💡 All native probes are located under app/src/main/cpp and are ultimately compiled into a single shared dynamic link library (.so). This is used for preload capture, mount checks, virtualization snapshots, renderer validation, and low-level trap path interceptions.
Compile Debug Version:
# Windows environment
gradlew.bat :app:assembleDebug
# Linux / macOS environment
./gradlew :app:assembleDebugDaily Development Validation Command (Recommended):
# Validate Kotlin compilation, run unit tests, and package the app
./gradlew :app:compileDebugKotlin :app:testDebugUnitTest :app:assembleDebug🔐 Signing Note: Automatic signing for the Release version is controlled by the environment variables ANDROID_KEYSTORE_PATH, ANDROID_KEYSTORE_PASSWORD, ANDROID_KEY_ALIAS, and ANDROID_KEY_PASSWORD. When these four variables are fully present, the build system will automatically enable the ciRelease signing configuration.
This software is provided "as is", without warranty of any kind. It is designed for educational, diagnostic, and security research purposes only. The developers assume no liability for direct or indirect damage, data loss, or system instability resulting from use of this application. Relying on heuristic security detection is at your own risk.
This project is open-sourced under the Apache License 2.0.
| Back | FazBrowse Home | New Git URL |