ANDROID APPLICATION INVESTIGATION

See what an application does while it is running

Observe application behavior, capture important events, and connect every finding to its supporting evidence.

From APK to signed behavior evidenceThis row shows the stages the lab runs; it is not a result. Opening a signed bundle replaces it with the real directed acyclic graph (DAG) of nodes and edges.
  1. 01APK + SHA-256
  2. 02Bounded static inspection
  3. 03FIFO scenario queue
  4. 04AOSP replay + Frida
  5. 05Normalize events
  6. 06Graph + signed evidence bundle

Open signed evidence bundle

Select or drop the .evidence.zip file produced by the local analysis tool.

Local-first: up to 160 MB • never uploaded

This view never generates sample or mock results. It remains empty until a lab output is opened.