Arsenal : AndroidTamer

BlackHat USA 2016

03 August 2016

Slides

AI Generated Summary

AI Generated Content Disclaimer

Note: This summary is AI-generated and may contain inaccuracies, errors, or omissions. If you spot any issues, please contact the site owner for corrections. Errors or omissions are unintended.

This presentation is the BlackHat USA 2016 Arsenal demo of Android Tamer, an expanded showcase of the project that has evolved from a single virtual machine into a comprehensive ecosystem for Android security professionals. Android Tamer now encompasses a VM, a Debian 8-compatible tools repository, custom emulator support (work in progress), an F-Droid repository for on-device tools, documentation, and a knowledge base β€” all fully open source. The demo covers the full tool suite, custom features, the repository system, and multiple live demonstrations of key capabilities.

Key Topics Covered

Actionable Takeaways

  1. Use the Android Tamer repository (repo.androidtamer.com) standalone on existing Debian-based systems like Kali Linux to get Android security tools without needing the full VM, enabling integration into your existing workflow.
  2. Leverage the Vagrant/Ansible build scripts to create custom, reproducible lab environments for training sessions or team-wide standardized testing setups.
  3. Use the Droid-FF fuzzing framework included in this edition for discovering vulnerabilities beyond what static and dynamic analysis tools find in Android applications and the platform itself.
  4. Contribute to the open source project by packaging additional Android security tools using the provided build scripts at AndroidTamer/Packaging_Tools, expanding the ecosystem for the entire community.
  5. Reference the Android security enhancements knowledge base when assessing applications across different Android versions to understand which platform-level protections apply.
  6. For training and workshops, use Android Tamer as the standard lab environment β€” it was actively used at BSides LV, DEFCON workshops, and BlackHat Arsenal sessions during the same conference week.

Social chatter