Competitor app intelligence
Horus Eye helps affiliate, competitive-intelligence, fraud, and compliance teams take apart a rival's
Android app — tracing disguises, hidden backends, payment rails, SDK footprints, and operator playbooks
into a single shareable case file.
How it works
Every case runs through the same investigation pipeline — static signals first,
optional live capture second, then correlation and briefing before the case file is filed.
-
1
Ingest & unpack
APK, XAPK, or AAB is normalized to a scan bundle — splits merged, AAB converted, hashes recorded.
-
2
DEX & manifest pass
Bytecode and AndroidManifest are parsed for permissions, components, embedded URLs, WebView/H5 patterns, and third-party SDK fingerprints.
-
3
Backend & config probes
Candidate servers are grouped and ranked; bootstrap/config APIs are probed with geo personas; Firebase Remote Config is fetched where keys are found.
-
4
Storefront cross-check
Play Store listings are pulled across locales — title homoglyphs, developer identity, screenshot sets, and disguise/rejection heuristics.
-
5
Field ops capture
When enabled
App installs on a local emulator; mitm proxy records live traffic, WebView loads, and per-country screenshots.
-
6
Correlation layer
Authored DEX methods/classes, shared bootstrap hosts, and config keys are matched against prior cases to surface developer groups, operator clusters, and copycat links.
-
7
Agents & briefing
Reversed code is exported; specialist agents draft focused memos; an analyst briefing synthesizes risk, architecture, and next steps.
-
8
Case file
Threat score, verdict, HTML/JSON/PDF report, and artifacts are stored — rescan diffs highlight what changed between versions.
Live today — static analysis
Active
- Upload a competitor APK, XAPK, or AAB you are authorized to inspect
- DEX and manifest pass — permissions, components, strings, and embedded URLs
- Third-party SDK, attribution, and hidden backend mapping
- Payment rails, Play Store impersonation, and storefront cross-checks
- Operator-cluster linking and threat scoring
- Analyst briefing and downloadable case report
Coming soon — dynamic field ops
Roadmap
The next layer runs the app inside an isolated Android emulator on your machine or infrastructure —
the same controlled environment your team already uses for QA — and captures what static analysis cannot see alone.
- Runtime network traffic and WebView / H5 shell behavior
- Locale, timezone, and GPS-gated backend switching
- Multi-country field probes in one investigation
- Device screenshots and session artifacts attached to the case file
Responsible use
Horus Eye is a defensive research tool.
Use it only on applications you are legally permitted to analyze — your own builds, explicit client
authorization, or a documented lawful research scope.
We do not provide malware, credential theft, DRM circumvention, or unauthorized access to third-party
systems. Static inspection reads artifacts you submit; future dynamic runs operate inside emulators you
control. Outputs are intelligence for your team, not instructions to break the law.
You are responsible for compliance with applicable laws, platform terms, and your organization’s policy.
When scope is unclear, consult legal counsel before opening a case.