{"repo":"mpast/mobileAudit","free":true,"listed":false,"github":"https://github.com/mpast/mobileAudit","clone":"git clone https://github.com/mpast/mobileAudit.git","description":"Django application that performs SAST and Malware Analysis for Android APKs","language":"HTML","stars":226,"topics":["android-security","sast","malware-analysis","code-security","defect-dojo","virustotal","apk-analysis","docker","django","django-rest-framework"],"license":"GPL-3.0","category":"deployment-docker-iac","readme_excerpt":"Mobile Audit MobileAudit - SAST and Malware Analysis for Android Mobile APKs A Django web application to perform static analysis and detect malicious content inside Android APKs. The project extracts app metadata, scans source code for weaknesses, and aggregates results (SAST findings, best practices, certificate info, strings, databases, files, VirusTotal, and more) into a browsable dashboard and API. DeepWiki documentation: https://deepwiki.com/mpast/mobileAudit - Components - Docker Base images - Main features - Patterns - Models - Installation - API v1 - Usage - Swagger - ReDoc - Endpoints - TLS - Pre-requirements - Nginx configuration - Docker configuration - Environment variables --------------------------------------- In each of the scans, it would have the following information: - APK information and analysis: Application info, security info, components, certificate info, strings, databases, files - SAST findings categorized with CWE and Mobile Top 10 mapping - Pattern engine with toggleable rules - Malware domain checks against MalwareDB & Maltrail - VirusTotal (API v3) lookup & optional upload (disabled by default) - DefectDojo integration (API v2) (optional) for exporting findings - API with Swagger and ReDoc, plus token-based authentication - Export scan reports to PDF - Findings editable with false-positive triage For easy access there is a sidebar on the left page of the scan: Components - db : PostgreSQL 3.11.5 - nginx : Nginx 1.23.3 - rabbitmq : RabbitMQ 3.11.","default_branch":null,"files":null,"tree":[],"storefront":"/r/mpast","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/mpast/mobileAudit/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}