Skip to content

Security: Msr7799/Android-Deep-Analysis-Lab

Security

SECURITY.md

Security policy / سياسة الأمان

Supported version

Security fixes currently target the latest 0.1.x release and the default branch.

Reporting a vulnerability

Use GitHub's Report a vulnerability private reporting feature when it is enabled for the repository. If private reporting is unavailable, contact the maintainer privately before publishing technical details. Do not open a public issue containing an exploit, API key, device identifier, APK, PCAP, or raw evidence.

استخدم ميزة Report a vulnerability الخاصة في GitHub عند تفعيلها. لا تنشر تفاصيل الاستغلال أو المفاتيح أو معرّفات الأجهزة أو الأدلة الخام في Issue عامة.

Include only a minimal redacted reproduction, the affected version, impact, and a safe proposed fix. You should receive acknowledgement when the maintainer reviews the private report; disclosure timing will be coordinated after a fix is available.

Project boundary

This project is intended only for authorized defensive assessment. Dynamic and network features collect restricted metadata and do not implement credential capture, TLS bypass, root acquisition, persistence, or exploitation. Reports and forensic exports can still contain sensitive device or application information and must be handled accordingly.

If a Gemini or MobSF key is ever exposed, revoke it with its provider immediately. Removing it from the latest file does not remove it from Git history.

There aren't any published security advisories