A static analysis tool for Android and iOS applications focusing on security issues outside the source code such as resource strings, third party libraries and configuration files.
Python 3 is required and you can find all required modules in the requirements.txt file. Only tested on Python 3.7 but should work on other 3.x releases. No plans to 2.x support at this time.
You can install this via PIP as follows:
pip install truegaze
To download and run manually, do the following:
git clone https://github.com/nightwatchcybersecurity/truegaze.git
pip -r requirements.txt
python -m truegaze.cli
How to use
To list modules:
To scan an application:
truegaze scan test.apk
truegaze scan test.ipa