smali-dex-patching
Installation
SKILL.md
Smali / DEX Patching
Patch the managed-code side of an Android APK: locate the check, edit the smali, rebuild, re-sign, install. Pair with mobile-technique for triage and target identification, offensive-tools/rev/jadx for the readable Java view, android-jni-ndk when the check lives in a native .so, and reversing-technique for deep obfuscated / packed samples.
Use only against APKs you are authorized to test.
When to activate
- Confirmed pentest scope on an Android APK you can extract from a device or ship a build of.
- Frida hook exists in theory but the target detects Frida (
ptrace,/proc/self/status,TracerPid) — static patching is a resilient alternative. - Bug bounty writeup requires PoC via a rebuilt APK.
- CTF challenge distributes a single
.apkfile with the flag or a check to defeat. - Confirming a vulnerability class ("this crypto key is embedded") by editing the check-in-place.
Not for: dynamic-only findings, native-code-only checks (use JNI/NDK skill + Frida + Ghidra), or app resigning without authorization on Play-distributed software.