AppXpose AppXpose
III. The dossier

Seven exhibits. Each one independently verifiable.

What's actually inside
the apps you opened today.

01
Exhibit 01

On-device DEX analysis

The bytecode never leaves your phone.

AppXpose unpacks the APK file directly through the Android Package Manager and reads its DEX classes in-process. Class names, method calls, and obfuscation patterns are matched against a growing database of curated tracker signatures, without ever uploading a single byte. The actual analysis happens in the same place the malware would: on your device.

"We can't leak what we never had."

02
Exhibit 02

AI-driven deep analysis

Not just what trackers are there. Why they matter.

Every scan triggers an LLM-powered analysis that goes far beyond tracker lists. You get a full paywall and monetization breakdown (is this app pay-to-win?), a developer profile (company, server locations, GDPR posture), data-sharing probability estimates (who gets your Advertising ID and why), and natural-language explanations next to every finding. The AI sees the pre-score, the permissions, the trackers, and the breach history, and writes you a report a human would understand.

"The receipts, translated."

03
Exhibit 03

Fake APK detection

Five systems. Server + on-device. If one flags it, you know.

Five systems working together. MalwareBazaar and Koodous check every APK hash against two independent malware databases in parallel. AppXpose CertNet, our crowd-sourced database of 4,700+ verified signing certificates, catches repackaged APKs by comparing certs. Community APK Hash Verification cross-references your hash against what other users report - once 7+ devices agree, any deviation is flagged. And on your device, the APK Integrity Checker inspects DEX headers, signing blocks, native libraries, and file structures for hooking frameworks, root tools, debug artifacts, and repackaging indicators. If any of the five flags something, you know.

"Five locks, one door."

04
Exhibit 04

Breach risk forecast

Developer history checked, future risk predicted.

For every app scanned by any AppXpose user, our server checks the developer's domain against the Have I Been Pwned breach database. The AI then forecasts future risk based on breach history, data practices, and developer reputation. GUARD subscribers are checked automatically every 24 hours. When a new breach is detected, every GUARD user with that app installed gets notified, even if they never scanned it themselves.

"The forecast is the warning."

05
Exhibit 05

Permission audit

Context-aware. A weather app asking for contacts scores differently than a messenger.

Every permission is mapped to a plain-language explanation, ranked by risk class (normal, dangerous, signature, special), and compared against previous results when available. The scoring is context-aware across 45 Play Store categories. A navigation app with location access scores 0. A flashlight app with the same permission scores higher. GUARD subscribers get automatic alerts when an app silently adds new permissions after an update.

"Permissions you can read."

06
Exhibit 06

GUARD: 5 always-on alerts

You stop checking. We don't.

GUARD combines community intelligence with local monitoring. Breach alerts and tracker change detection are powered by the community: when any user scans an app, the results are compared server-side and all GUARD users with the same app benefit. Permission changes, app removals, and developer certificate changes are monitored locally on your device every 24 hours.

"Five sentries. One command center."

07
Exhibit 07

Community verdict

Anonymous votes, profanity-filtered, no algorithm games.

Other AppXpose users have already scanned the apps you have installed. Their scores, comments, and warnings are pinned next to the technical results. There are no follower counts, no engagement loops, just signal from people who came to the same question you did.

"Wisdom of the cautious."

08
Exhibit 08

App Index

Your phone, documented.

Every scan you run is saved to a local database: risk scores, tracker lists, permission audits, all timestamped. The App Index lets you browse, search, and compare your installed apps in one place. Filter by risk level, sort by last scan date, spot which apps got worse over time. It turns scattered scans into a structured record of what is running on your device.

"Infrastructure, not a feature."

IV. The lab

Five detection systems live and learning. Two ML models in training.

We are also
teaching the scanner.

Five detection systems are live in production and actively learning from every scan. MalwareBazaar and Koodous check APK hashes against two independent malware databases, CertNet and Community Hash Verification catch repackaged APKs through crowd-sourced baselines, and the on-device APK Integrity Checker inspects file structures for hooking, root tools, debug artifacts, and packer signatures. Two additional ML models are in training on that growing corpus.

D01
MalwareBazaar Hash Lookup
LIVE v7.4.1
Every scanned APK's SHA256 hash is checked against abuse.ch's open malware database. If the hash matches a known malicious sample, the risk score jumps to CRITICAL immediately.
D02
AppXpose CertNet
LIVE v7.4.1
Crowd-sourced database of signing certificates. Compares each app's cert against 4,700+ verified certs (F-Droid) and real user scans (trust-on-first-use). Confidence threshold: 7+ devices must report the same cert before it becomes the verified baseline. A cert mismatch means the APK was likely repackaged or faked.
D03
Community APK Hash Verification
LIVE v7.4.1
Crowd-sourced APK hash database. Every scan contributes the app's SHA256 hash. Once 7+ distinct devices report the same hash for a package version, it becomes the verified baseline. If your APK hash differs from the community consensus, the app was likely tampered with or repackaged.
D04
Koodous Threat Intelligence
LIVE v7.4.1
Every APK hash is checked against Koodous, a community-driven Android threat intelligence platform with millions of analyzed samples. Runs in parallel with MalwareBazaar so two independent malware databases are queried simultaneously. A Koodous detection adds +13 to the risk score.
D05
On-Device APK Integrity Checker
LIVE v7.4.1
Runs entirely on the device, parallel to the tracker scan. Inspects DEX headers (magic bytes, endian tags, link fields), signing blocks, native libraries, and file structures. Detects hooking frameworks (Cydia Substrate, Whale/LSPosed, ADBI), root tools (su, busybox, resetprop), debug artifacts (gdbserver, lldb-server, ida.key), repackaging indicators (patched DEX files), and known packer signatures (Jiagu, DexProtector, Bangcle). Severity-classified from LOW to CRITICAL.
Still in training
M01
Tracker Permission Linker
IN TRAINING
Learns which Android permissions co-occur with which tracker SDKs, so we can flag suspicious combinations even when the SDK is obfuscated.
M02
Behavioural Pattern Recognizer
IN TRAINING
Surfaces non-obvious links across apps. Same dev, same servers, same SDK fingerprint, same data buyer. Maps the relationships our DEX scanner alone cannot see.
Live corpus stats
Connecting...