A script to install and set up an Android pentest environment
Tools the script installs
adbjadxapktoolapkleaks- Firebase Scanner
drozerfrida- Burp Suite
nuclei
Languages the script installs
python3+pip3gojava(JDK)
Installation
git clone https://github.com/xenion0/Android_install.gitcd Android_installchmod +x setup.sh./setup.shRequirements
1. Install Burp Suite
The script takes Burp’s CA certificate in DER format and installs it into the emulator’s system trust store.
Export it from Burp: Proxy → Proxy Settings → Proxy listeners → Import / export CA certificate → Export → Certificate in DER format. (On an older Burp this is Proxy → Options → Import/Export CA Certificate. You can also skip the menus entirely — with Burp running, browse to http://burpsuite from the device and download the CA there.)
Why the system store and not the user store: since Android 7 (API 24), apps no longer trust user-installed CAs, so a certificate added via Settings → Security will not let you intercept app traffic. It has to land in /system/etc/security/cacerts, which is why this needs an emulator (or a rooted device) with a writable system partition.
The DER file is the input to the script.
2. Install Genymotion

Usage

After the script finishes
1. Burp
The certificate should now be installed as a system-trusted CA, which you can confirm on the emulated device under Settings → Security & Location → Encryption & Credentials → Trusted Credentials.

Next, point the device’s traffic at Burp. On the emulated device open WiFi → long-press the network name → Modify Network → Advanced Options, and change the proxy from None to Manual.

2. Drozer
Drozer lets you search for security vulnerabilities in apps and devices by taking the role of an app and interacting with the Dalvik VM, other apps’ IPC endpoints and the underlying OS.
The Drozer Agent is installed into the Genymotion emulator by the script.
Running Drozer without opening the agent
With drozer 2.x:
adb forward tcp:31415 tcp:31415adb shell am startservice -n com.mwr.dz/.services.ServerService -c com.mwr.dz.START_EMBEDDEDdrozerNote that am startservice is restricted on Android 8+ by background-service limits. drozer 3.x — the current Python 3 rewrite, which needs Python 3.8+ and JDK 11+ — changes this workflow: install the agent, adb forward tcp:31415 tcp:31415, then drozer console connect.
3. Frida
This is a dynamic code instrumentation toolkit which lets you dynamically inject snippets of code into running processes of the app in order to change its behavior.
when Script finish will find frida server in /data/local/tmp

run frida
adb shell "/data/local/tmp/frida-server &"frida-ls-devicesfrida-ps -UOnce the proxy is working, the next thing that usually breaks it is certificate pinning — the app validates the server certificate against one baked into the app, and the connection fails no matter how cleanly the system CA is installed. That is where runtime instrumentation earns its place: Frida (or objection) can hook the pinning check and disable it. Installing the CA buys you the ability to intercept; bypassing pinning is what most real apps will additionally require.
Future work
Future script to recon and do some daily routine static analysis tasks for android recon and recon_profile