Android
ADB: Android Debug Bridge
ADB command reference for Android pentesting: device management, file transfer, shell access, app analysis, and traffic interception setup.
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
ADB command reference for Android pentesting: device management, file transfer, shell access, app analysis, and traffic interception setup.
adb devices
# First connect via USB, then switch to TCP
adb tcpip 5555
adb connect <DEVICE-IP>:5555
adb disconnect
adb -e shell # emulator only
adb -d shell # physical device only
adb -s <SERIAL> shell # specific device by serial
adb shell # interactive shell
adb shell <command> # single command
adb shell su # root shell (rooted device)
adb shell pm list packages # all
adb shell pm list packages -3 # third-party only
adb shell pm list packages | grep <name>
adb shell pm path <package.name>
adb pull /data/app/<package.name>-<hash>/base.apk ./target.apk
adb install target.apk
adb install -r target.apk # reinstall (keep data)
adb uninstall <package.name>
adb shell am start -n <package>/<activity>
adb shell am force-stop <package.name>
adb pull /sdcard/file.txt ./ # device → host
adb push ./file.txt /sdcard/ # host → device
| Path | Contents |
|---|---|
/sdcard/ | External storage |
/data/data/<pkg>/ | App private data (root required) |
/data/local/tmp/ | World-writable temp dir |
adb logcat # all logs
adb logcat -s <TAG> # filter by tag
adb logcat | grep -i <package> # filter by package name
adb logcat -d > logcat.txt # dump and exit
adb logcat -c # clear log buffer
adb forward tcp:<HOST-PORT> tcp:<DEVICE-PORT>
adb forward tcp:8080 tcp:8080
adb reverse tcp:<DEVICE-PORT> tcp:<HOST-PORT>
adb reverse tcp:8080 tcp:8080
# Export DER from Burp → convert to PEM
openssl x509 -inform der -in burp.der -out burp.pem
# Get the hash filename Android expects
openssl x509 -inform PEM -subject_hash_old -in burp.pem | head -1
# Example output: 9a5ba575
mv burp.pem 9a5ba575.0
# Push to system trusted store (root required)
adb push 9a5ba575.0 /sdcard/
adb shell
su
mount -o rw,remount /system
cp /sdcard/9a5ba575.0 /system/etc/security/cacerts/
chmod 644 /system/etc/security/cacerts/9a5ba575.0
adb shell settings put global http_proxy <BURP-IP>:8080
# Remove proxy
adb shell settings delete global http_proxy
# List app data directory (root required)
adb shell ls /data/data/<package.name>/
# Pull entire app data
adb pull /data/data/<package.name>/ ./app-data/
# Shared preferences (often stores tokens/flags)
adb shell cat /data/data/<package.name>/shared_prefs/<name>.xml
# SQLite databases
adb pull /data/data/<package.name>/databases/<db>.db .
sqlite3 <db>.db .tables
sqlite3 <db>.db "SELECT * FROM <table>;"
# Start activity
adb shell am start -a android.intent.action.VIEW -d "http://target.com"
# Start exported activity directly
adb shell am start -n <package>/<activity>
# Send broadcast
adb shell am broadcast -a <ACTION> --es key value
# Start service
adb shell am startservice -n <package>/<service>
adb shell dumpsys activity # running activities
adb shell dumpsys activity packages | grep <pkg> # package info
adb shell dumpsys package <package.name> # permissions, activities, services
adb shell dumpsys meminfo <package.name> # memory usage
# Screenshot
adb shell screencap /sdcard/screen.png && adb pull /sdcard/screen.png
# Screen record
adb shell screenrecord /sdcard/record.mp4
# Current foreground activity
adb shell dumpsys window | grep mCurrentFocus
# List exported activities
adb shell dumpsys package <package.name> | grep -A 2 "Activity"
# Check if device is rooted
adb shell which su
# Get Android version
adb shell getprop ro.build.version.release
# Get device architecture
adb shell getprop ro.product.cpu.abi