Manifest, resources, and package details
Read AndroidManifest.xml, package metadata, resources.arsc, and archive entries from one workspace.
Open an Android package in your browser to inspect its manifest, DEX code, resources, native libraries, signing certificates, and file fingerprints without automatically uploading the APK.
Read AndroidManifest.xml, package metadata, resources.arsc, and archive entries from one workspace.
Browse DEX classes and code across multiple DEX files, then inspect bundled ELF files and their security properties.
Review signing certificate information and calculate MD5, SHA-1, and SHA-256 file fingerprints.
The APK workspace brings AndroidManifest.xml, DEX classes, resources, ELF files, certificate data, and fingerprints together so you can move between package metadata and implementation details.
Attach additional files when an investigation needs more context; DEX attachments are also available to the decompiler.
With a connected AI client, UFOX can expose its analysis API documentation and run isolated JavaScript analysis in the browser through the QuickJS-based plugin engine. The client can inspect the files available to the current browser session without moving the analysis runtime to a server.