DevLune · Static analysis · Android

Excavate the package, layer by layer.

Read-only static analysis of Android packages — manifest, resources, DEX and reconstructed source, native libraries and JNI, certificates and attack surface, with hidden endpoints decoded as evidence. The package is read as data, never installed or run.

Download v2.0.0

Windows 10/11 · 64-bit · 6.3 MB · released 1 September 2026 · updates itself

The package is opened as bytes and never installed, run, or sent anywhere. The one write path repackages your own file, signed as yourself.

Three editions, one codebase

All-in-oneDevLune Inspector

Both engines and every Learn track. Start here.

Windows onlyPE Inspector

PE/COFF analysis and the PE Learn track. Slim.

Android onlyAPK Inspector

APK analysis and the Android Learn track. Slim.

You're here

What it excavates

Manifest
Package, components, permissions, exported surface
Resources
resources.arsc, layouts, drawables, raw assets
DEX & source
Dalvik bytecode, smali, reconstructed classes
Native & JNI
Per-ABI .so libraries and JNI bindings
Certificates
Signing chain, v1 to v3 scheme, signer identity
Hidden endpoints
Obfuscated URLs recovered as evidence
Attack surface
Permissions and security findings
Repackage & sign
Generate-only, a new file signed as yourself

What's new

v2: the full Android workstation and an expanded Learn track

v2.0.0 · 1 September 2026 · 6.3 MB
  • Full workstation: manifest, resources, DEX/smali and source, native and JNI, certificates, strata overview
  • Expanded Learn Android track (16 lessons) with a Practice Lab that loads a real specimen
  • Repackage and Sign stays generate-only, never forging the original signer
  • Signed auto-updates; read-only, never installed or run

All versions

  1. v2.0.0Latest1 September 2026 · 6.3 MB

    v2: the full Android workstation and an expanded Learn track

    • Full workstation: manifest, resources, DEX/smali and source, native and JNI, certificates, strata overview
    • Expanded Learn Android track (16 lessons) with a Practice Lab that loads a real specimen
    • Repackage and Sign stays generate-only, never forging the original signer
    • Signed auto-updates; read-only, never installed or run
    Download v2.0.0
  2. v0.1.01 September 2026 · 4.7 MB

    First release

    • Read-only static analysis of Android APKs, manifest, DEX/Smali, resources, native libraries, JNI, and signing certificates
    • Recovers endpoints hidden in native libraries (position-dependent XOR, base64) that a plain string scan never sees, with the transform and parameters that decode them
    • Excavation-strata overview: the package by depth, every artifact catalogued with a byte offset and provenance
    • Repackage & re-sign into a new file with a generated key (never forges the original signer); YARA-style rules; diffing
    • Signed auto-updates, light/dark themes, command palette, and a full accessibility pass
    Download v0.1.0

Every build is cryptographically signed; the app verifies each update before installing. Windows SmartScreen may still warn on a new release; choose More info, then Run anyway.

Crafted in the dark. Shipped to the world.

Tell us what you are building. You get a private project space with a proposal and a line-by-line quote within a day.