Skip to content

Repository files navigation

image

Bugbane

Build status Reproducibility status

GitHub Release GitHub license Liberapay patrons Translation status

Caution

This project is under active development and is not recommended for non-technical users at this stage. The installation and usage of Bugbane can be detected by spyware and stalkerware. Do not use it when there is a direct risk of physical harm. Read the risks and warnings before installing.

Documentation lives on the official website, bugbane.org. In particular, see the security architecture and the risks and warnings.

Bugbane is currently in beta. The store listings below are the beta channel; a stable release will follow.

Bugbane is an open-source Android application designed to help potential spyware and stalkerware victims self-triage their own device and, when appropriate, export evidence for later analysis by trusted organizations. Read more and see the demo in our blog post (Italian version).

image image image

Unlike existing tools such as MVT, Bugbane does not require a separate computer, command-line usage, or debugging skills. It uses ADB Wireless Debugging to issue commands directly to the same device on which it is installed, through a guided, user-friendly interface.

Exports are intended to be AndroidQF-compliant, making them portable and analyzable off-device using existing tools, and can be easily shared via Signal or other communication tools. Each export is automatically encrypted with a random password using age. Since exported data can contain sensitive personal information, the initial scan is performed on-device using a re-implementation of MVT that reuses the same IOCs as the original.

This project is still evolving. Current releases are betas: expect rough edges and please report what you find.

License

Portions of the code in Shizuku are distributed under the Apache 2.0 License, whereas Bugbane is released under the GNU General Public License, version 3 only (GPL-3.0-only).

Project Structure

Bugbane is divided in 4 main coponents:

  • the Bugbane UI components and activities (org.osservatorionessuno.bugbane.*)
  • cabd, a Kotlin implementation of a minimal ADB client (org.osservatorionessuno.cadb.*)
  • QF, a Kotlin implementation of AndroidQF acquisition modules (org.osservatorionessuno.qf.*). Its main entrypoint is the AcquisitionRunner class.
  • LibMVT, a Java implementation of MVT IOC analysis engine (org.osservatorionessuno.libmvt.*). Its main entrypoint is the ForeniscRunner class.

Translations

Translation hosting generously provided by Weblate through their open-source sponsoring program.

Translation status

Funding

This project was funded through the NGI Mobifree Fund, a fund established by NLnet with financial support from the European Commission's Next Generation Internet programme under the aegis of DG Communications Networks, Content and Technology.

About

On-device Android forensics tookit

Topics

Resources

Stars

64 stars

Watchers

4 watching

Forks

Releases

Sponsor this project

Packages

Contributors

Languages