C Apache-2.0

garlic

The world's fastest apk (android)/java open source decompiler

N

neocanable

Dernière activité 29 sept. 2026
neocanable/garlic

839

étoiles

112

forks

17

issues ouvertes

androidandroid-decompileandroid-decompilerandroid-reverseapkapk-decompilerc99decompilerdexdex-decompilerjava-decompilerreverse-engineering

Ce README est souvent en anglais.

Banner image

Garlic decompiler

License

Telegram

English | Chinese

The world's fastest apk (android)/java open source decompiler/elf analyzer

Android/Java decompiler written in C

Tool for produces java source code from class/jar/dex/apk file

Features

  • decompile apk file
  • decompile dex file
  • decompile class file
  • decompile jar file
  • decompile war file
  • analysis aarch64 elf
    • control flow
    • IR
    • imports
    • exports
    • strings
    • function call graph

Build

1. Build on linux/macOS

​ requirements: cmake >= 3.26

git clone https://github.com/neocanable/garlic.git
cd garlic
cmake -B build
cmake --build build
./build/garlic
2. Build on Windows

please check the windows build document

Also see Garlic on Windows for performance tips and known issues.

3. Build with Zig (cross-platform)

​ requirements: zig >= 0.16.0

Build for your host platform directly:

git clone https://github.com/neocanable/garlic.git
cd garlic
zig build --release=fast
./zig-out/bin/garlic

Cross-compile to any target with -Dtarget:

# Linux x86_64 (musl)
zig build --release=fast -Dtarget=x86_64-linux-musl

# Linux x86_64 (glibc)
zig build --release=fast -Dtarget=x86_64-linux-gnu

# Linux aarch64
zig build --release=fast -Dtarget=aarch64-linux-musl

# Linux i686 (32-bit)
zig build --release=fast -Dtarget=x86-linux-musl

# Windows x86_64
zig build --release=fast -Dtarget=x86_64-windows

# Windows 32-bit
zig build --release=fast -Dtarget=x86-windows

# macOS x86_64 (Intel)
zig build --release=fast -Dtarget=x86_64-macos

# macOS aarch64 (Apple Silicon)
zig build --release=fast -Dtarget=aarch64-macos

Zig bundles its own cross-linkers and libc, so no cross-toolchain needs to be installed — everything works out of the box. The output goes to zig-out/bin/.

4. Cross-compile with the Android NDK

​ Environment: Android NDK (>= r21, verified on r28)

​ The NDK is located (in priority order) via -DANDROID_NDK=/path/to/ndk, the ANDROID_NDK_HOME / ANDROID_NDK_ROOT environment variables, or ANDROID_HOME/ANDROID_SDK_ROOT (<sdk>/ndk/<version>). The default macOS / Android Studio install path is auto-detected as a fallback.

./build.sh android-arm64-v8a

​ Or invoke CMake directly:

cmake -B build/build-android-arm64-v8a \
      -DCMAKE_TOOLCHAIN_FILE=toolchains/toolchain-android-arm64-v8a.cmake \
      -DPLATFORM_NAME=android-arm64-v8a
cmake --build build/build-android-arm64-v8a

​ The output is build/garlic-android-arm64-v8a (arm64-v8a, minSdkVersion 23).

​ Note: no prebuilt librosemarylib (ELF analyzer) is shipped for Android yet, so that platform is built with the ELF-analysis (-n) feature disabled. All other decompilation features work unchanged.

Usage

  • decompile apk

    garlic /path/to/android.apk
    
    garlic /path/to/android.apk -o /path/to/save # -o option is source code output path
    
    garlic /path/to/android.apk -t 5             # -t option is thread count, default is 4
  • decompile .dex file

    garlic /path/to/classes.dex
    
    garlic /path/to/classes.dex -o /path/to/save # -o option is source code output path
    
    garlic /path/to/classes.dex -t 5             # -t option is thread count, default is 4
  • decompile .class file

    decompile .class file, default output is stdout

    garlic /path/to/jvm.class
  • decompile jar file

    garlic /path/to/file.jar
    
    garlic /path/to/file.jar -o /path/to/save # -o option is source code output path
    
    garlic /path/to/file.jar -t 5             # -t option is thread count, default is 4

    default output is same level directory as the file

  • javap

    like javap, more faster, disabled LineNumber and StackMapTable attributes

    garlic /path/to/jvm.class -p
  • dexdump

    garlic /path/to/dalvik.dex -p           
    
  • search string

    garlic ~/demo/demo.apk -f "windowInfo" # search "windowInfo" in demo.apk
    
    garlic ~/demo/demo.jar -f "[W|w]indow" # search regex [W|w]indow in demo.jar
    
    garlic ~/demo/demo.dex -f "info" # search contains string "info" in demo.dex
    

Debug

in src/jvm.c, change main function to:

int main(int argc, char **argv)
{
    jar_file_analyse(path_of_jar, out_of_jar, 1);
    return 0;
}

if thread count less than 2, it will disable multiple thread.

Speed

decompile newest(2025-06-16) wechat.apk which size is 200M+ and 19w+ classes need 12 seconds

garlic ~/wechat/wechat.apk
[Garlic] APK file analysis
File     : ~/wechat/wechat.apk
Save to  : ~/wechat/wechat_apk
Thread   : 4
Progress : 192538 (192538)
[Done]

decompile tiktok

Garlic + Rosemary pipeline

Video

Customization

Email: neocanable#gmail.com (replace # to @)

wechat: neocanable

author


Licensed under the Apache 2.0 License

Projets similaires

Dex to Java decompiler

Javaandroiddecompilerdex
Sskylot
50,7 k étoiles5,8 k

A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)

Javaandroidapkbaksmali
KKonloch
15,7 k étoiles1,3 k

the fastest and most powerful android decompiler(native tool working without Java VM) for the APK, DEX, ODEX, OAT, JAR, AAR, and CLASS file. which supports malicious behavior detection, privacy leaking detection, vulnerability detection, path solving, packer identification, variable tracking, deobfuscation, python&java scripts, device memory extraction, data decryption, and encryption, etc.

Pythondecompilermalware-analysismobile-security
Ccharles2gan
4,8 k étoiles575