11/12 free views
Framework
Framework
Endpoint Security

EdXposed

by ElderDrivers

5.6Kstars
641forks
179watchers
Updated 10 months ago
About

EdXposed is an Android ART hooking framework that enables modules to modify system and app behavior dynamically without altering APKs, supporting Android 8.0 to 11.

Elder driver Xposed Framework.

Primary Use Case

EdXposed is primarily used by Android enthusiasts and developers who want to customize or extend system and app functionalities without modifying APK files. It is ideal for users running rooted devices with Magisk and Riru, enabling them to run Xposed modules compatible with Android Pie through 11 for endpoint protection and security automation.

Key Features
  • Provides ART hooking framework compatible with Android 8.0 to 11
  • Delivers consistent APIs compatible with original Xposed Framework
  • Leverages YAHFA or SandHook hooking frameworks
  • Supports multiple modules modifying the same system or app parts simultaneously
  • Changes are applied in-memory, allowing easy deactivation and reboot to restore original system
  • Available in Stable, Alpha, and Canary builds for different user needs
  • Compatible with Magisk and Riru modules for installation
  • Supports development and use of Xposed modules without APK modifications

Installation

  • Install Magisk v21+
  • Install Riru v23+ from Magisk repo
  • Download and install EdXposed in Magisk Manager or recovery
  • Install EdXposed Manager app
  • Reboot the device
  • Use and enjoy the framework

Usage

>_ Install Magisk v21+

Prerequisite for rooting and managing modules like Riru and EdXposed

>_ Install Riru v23+ from Magisk repo

Required module that EdXposed depends on for hooking into the Android runtime

>_ Install EdXposed via Magisk Manager or recovery

Installs the EdXposed framework on the device

>_ Install EdXposed Manager

App to manage EdXposed modules and framework settings

>_ Reboot device

Applies changes and activates EdXposed framework

Security Frameworks
Defense Evasion
Persistence
Execution
Privilege Escalation
Discovery
Usage Insights
  • Leverages in-memory hooking to enable stealthy runtime modifications, useful for red team evasion and persistence simulations.
  • Can be integrated with custom Xposed modules to automate endpoint security checks and anomaly detection on Android devices.
  • Ideal for purple teams to develop and test detection rules against advanced hooking and code injection techniques on mobile endpoints.
  • Supports rapid toggling of hooks without APK modification, enabling safer experimentation and rollback during incident response drills.
  • Can be combined with Magisk and Riru frameworks to extend root-level security automation and endpoint protection capabilities.

Docs Take 2 Hours. AI Takes 10 Seconds.

Ask anything about EdXposed. Installation? Config? Troubleshooting? Get answers trained on real docs and GitHub issues—not generic ChatGPT fluff.

3 free chats per tool • Instant responses • No credit card

Security Profile
Red Team70%
Blue Team40%
Purple Team60%
Details
LicenseGNU General Public License v3.0
LanguageJava
Open Issues782
Topics
riru
yahfa
xposed-framework
xposed
android
android-framework
xposedbridge
magisk-module
magisk
riru-module