identify_packer
Scan an APK to fingerprint its compiler, packer, obfuscator, and anti-debug/anti-VM techniques using APKiD YARA rules—a first look before reverse-engineering.
Instructions
Fingerprint the compiler, packer, obfuscator, and anti-debug/anti-VM techniques an APK uses, via APKiD's YARA rules - a good first look before deciding how to approach an APK. Only reads the file. Returns APKiD's own JSON report (for each scanned file, its matches grouped by category - compiler, obfuscator, packer, anti_vm and so on); if APKiD's output isn't valid JSON it returns { raw } instead. Requires apkid on PATH (pip install apkid).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| apkPath | Yes | Absolute path to the .apk (or .dex) file to scan. Must exist. | |
| workspace | No | Workspace name (not id). Created if it doesn't exist, and this call is recorded as a job in its history. Defaults to "default". | |
| timeoutSeconds | No | Per-file YARA scan timeout in seconds. Default 30. |