apktool
無料Android APK unpacking and resource extraction tool for reverse engineering. Use when you need to decode APK files, extract resources, examine AndroidManifest.xml, analyze smali code, or repackage modified APKs.
日本語の概要は準備中です。原文の説明を表示しています。
Probe IoT/embedded targets for exposed SWD/JTAG debug interfaces using a SEGGER J-Link. Detects whether debug is OPEN, LOCKED (readout-protected), or DEAD (fused off). Use when assessing whether a target's on-chip debug port can be reached, identifying the silicon vendor from DPIDR/IDCODE, and confirming halt+memory access for full debugger control.
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
You are helping the user determine whether a target's on-chip debug interface is exposed via SWD or JTAG, using the jtagprobe tool. This drives a SEGGER J-Link physically wired to the target.
Three nested access layers are checked, and the target is classified into one of:
OPEN — DP responds, CPU halts, memory reads return plausible data. Full debugger control. Critical finding.LOCKED — DP/IDCODE accessible but memory reads fail or return readout-protection sentinels (0xFFFFFFFF). Indicates STM32 RDP, NXP CRP, Nordic APPROTECT, etc. are engaged. Still a finding — the port should not respond at all in production.DEAD — No DP/IDCODE response on any tested interface/speed. Debug fused off, pins not wired, or wrong target.JLinkExe on PATH — verify with which JLinkExe. If it is installed but not on PATH, point the tool at it with --jlink-binary /path/to/JLinkExe instead of relying on PATH.If JLinkExe cannot be found at all, tell the user to install SEGGER J-Link software from segger.com. Do not attempt to install it without explicit approval.
Default — sweep SWD then JTAG at 4000/1000/100 kHz, halt, read memory, classify:
jtagprobe
Save per-attempt JLinkExe logs as evidence (recommended for pentest writeups):
jtagprobe --evidence-dir ./evidence/jtagprobe-$(date +%Y%m%d-%H%M%S)
JSON for chaining:
jtagprobe --format json
Just run with defaults. The tool will:
jtagprobe --evidence-dir ./evidence
If the user knows the chip, pass --device for a more accurate halt/memory test. Use the same device strings J-Link accepts (STM32F407VG, nRF52840_xxAA, MK64FN1M0xxx12, etc.):
jtagprobe --device STM32F407VG
Some pirate-flagged boards or long ribbon cables need a slower clock. Limit the sweep:
jtagprobe --speeds 1000,100,10
If the target is in a state where halting would crash an active firmware path you care about (rare in pentests, common in live systems), stop after the connect probe:
jtagprobe --skip-memory
jtagprobe --interfaces SWD
jtagprobe --interfaces JTAG --speeds 4000,1000
The text format leads with the classification and reason:
CLASSIFICATION: LOCKED
DP/IDCODE accessible but CPU halt or memory read failed. Typical of RDP / CRP / APPROTECT engaged.
Vendor: STMicroelectronics
SW-DP DPIDR=0x2BA01477 partno=0xBA version=2 designer_identity=0x20
Access test:
Halted: True
CPUID @ 0xE000ED00 = 0x410FC241
0x08000000: 0xFFFFFFFF 0xFFFFFFFF 0xFFFFFFFF 0xFFFFFFFF [all-0xFF, possible RDP]
Protection hint: STM32 RDP Level 1/2 (see RM, FLASH_OPTR bits 15:8).
Key signals:
0xFFFFFFFF flash reads after a successful halt = readout protection. Capture the DPIDR and document the protection mechanism.For a pentest finding under CWE-1191 (improper access control on debug interface) or CWE-1244 (asset exposed via debug):
jtagprobe invocation--evidence-dir for the appendixDefault assumption: they want both SWD and JTAG checked, full halt+memory test, and evidence captured. Run:
jtagprobe --evidence-dir ./evidence/jtagprobe-$(date +%Y%m%d-%H%M%S)
If JLinkExe isn't on PATH, stop and report that the SEGGER tools aren't installed.
--device is passed. Halt/memory access may succeed under a generic device even when the vendor-specific erase/unlock would not.--format json shows what was extracted.unlock commands separately with explicit authorization.まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Android APK unpacking and resource extraction tool for reverse engineering. Use when you need to decode APK files, extract resources, examine AndroidManifest.xml, analyze smali code, or repackage modified APKs.
日本語の概要は準備中です。原文の説明を表示しています。
Static analysis of UEFI/BIOS firmware dumps using Intel's chipsec framework. Decode firmware structure, detect known malware and rootkits (LoJax, ThinkPwn, HackingTeam, MosaicRegressor), generate EFI executable inventories with hashes, extract NVRAM variables, and parse SPI flash descriptors. Use when analyzing firmware .bin/.rom/.fd/.cap files offline without requiring hardware access.
日本語の概要は準備中です。原文の説明を表示しています。
Advanced file finder with type detection and filesystem extraction for analyzing firmware and extracting embedded filesystems. Use when you need to analyze firmware files, identify file types, or extract ext2/3/4 or F2FS filesystems.
日本語の概要は準備中です。原文の説明を表示しています。
IoT network traffic analyzer for detecting IoT protocols and identifying security vulnerabilities in network communications. Use when you need to analyze network traffic, identify IoT protocols, or assess network security of IoT devices.
日本語の概要は準備中です。原文の説明を表示しています。
Android APK decompiler that converts DEX bytecode to readable Java source code. Use when you need to decompile APK files, analyze app logic, search for vulnerabilities, find hardcoded credentials, or understand app behavior through readable source code.
日本語の概要は準備中です。原文の説明を表示しています。
Analyze digital and analog captures from Saleae Logic MSO devices. Decode protocols like UART, SPI, I2C from exported binary files. Use when analyzing logic analyzer captures for CTF challenges, hardware reverse engineering, or protocol decoding.
日本語の概要は準備中です。原文の説明を表示しています。