frida-tracing-discovery
Discover Frida hook points with frida-trace, class and method enumeration, module/export/import/symbol discovery, stack traces, Stalker, and probe narrowing.
How do I install this agent skill?
npx skills add https://github.com/rudra-ravi/frida-skills --skill frida-tracing-discoveryIs this agent skill safe to install?
- Gen Agent Trust Hubpass
The skill provides instructional content and code templates for using the Frida dynamic instrumentation toolkit to analyze applications. It references official documentation and provides standard discovery patterns for security research.
- Socketwarn
1 alert: gptSecurity
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
Frida Tracing Discovery
Use this skill when the target API, class, symbol, or call path is unknown.
Start Broad, Then Narrow
- Prove the behavior happens without Frida.
- Choose the highest-signal boundary: network, crypto, file, IPC, WebView, class loading, native library loading, or UI action.
- Trace or enumerate around that boundary.
- Add stack traces to identify app-owned callers.
- Replace broad probes with narrow hooks.
CLI Tracing
frida-trace -U -f com.example.app -j 'java.net.URL!*' --no-pause
frida-trace -U -f com.example.app -i 'open' -i 'connect' --no-pause
frida-trace -U -n target -m 'Module!*pattern*'
Treat generated handlers as temporary discovery artifacts, then move proven logic into a reviewed script.
Android Discovery
Java.perform(() => {
const groups = Java.enumerateMethods("*crypto*!*/isu");
console.log(JSON.stringify(groups, null, 2));
});
Class loader check:
Java.perform(() => {
Java.enumerateClassLoaders({
onMatch(loader) {
try {
Java.classFactory.loader = loader;
Java.use("com.example.Target");
console.log("loader", loader);
} catch (_) {}
},
onComplete() {}
});
});
Native Discovery
const mod = Process.getModuleByName("libtarget.so");
for (const e of mod.enumerateExports()) {
if (e.name.includes("SSL") || e.name.includes("crypto")) console.log(e.name, e.address);
}
Backtrace on a generic boundary:
Interceptor.attach(Module.getGlobalExportByName("open"), {
onEnter(args) {
console.log(args[0].readUtf8String());
console.log(Thread.backtrace(this.context, Backtracer.ACCURATE)
.map(DebugSymbol.fromAddress).join("\n"));
}
});
References
Read references/discovery-patterns.md for target-specific trace ladders.
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/rudra-ravi/frida-skills/frida-tracing-discovery">View frida-tracing-discovery on skillZs</a>