Skip to content

类别:anti_debug 反调试 ​

anti_debug

anti_debug 类别检测 反调试技术——样本用来判断自己是否正被调试器附加,若是则改变行为。

🎯 常见反调试手段 ​

  • ptrace 检测:自己 ptrace 自己,若失败说明已被调试器附加。
  • 调试器检测:检查 Debug.isDebuggerConnected()。
  • 进程扫描:查 gdb、lldb、android_server 进程。
  • 时间检测:某段代码执行耗时异常→被单步了。
  • /proc/self/status:读 TracerPid 字段,非 0 表示被 trace。

📋 规则分布 ​

anti_debug tag 的规则:

规则检测
checks_debugger_presentDebug.isDebuggerConnected() 调用

APKiD 的 anti_debug 规则较少——很多反调试技术发生在原生层(so 库),属于 anti_root/protector 的覆盖范围。DEX 层主要抓 Java API 的调试检测。

与其它反分析的关系

反调试常与 反 Root、反 Hook 共存——一个完整的对抗样本会同时检测调试器、Root、Frida。APKiD 会分别报告。

📊 finding 示例 ​

json
{
  "tag": "anti_debug::checks_debugger_present",
  "category": "anti_debug",
  "description": "Detects anti-debugging techniques",
  "source": "app.apk!classes.dex",
  "identifier": "checks_debugger_present",
  "confidence": "high"
}

📍 相关 ​

基于 GPL & Commercial 双重许可发布