Stheno (Σθεννώ) is a powerful tool designed for analyzing and manipulating intents in Android applications. Named after the sister of Medusa, Stheno is indeed a sub project of Medusa that brings formidable capabilities akin to Burp Suite but tailored specifically for intents. This tool is essential for Android penetration testers, developers, and security enthusiasts who seek to understand and secure their applications against intent-based vulnerabilities.
- Intent Interception: Capture and inspect intents sent and received by Android applications.
- Intent Modification (TODO): Modify intercepted intents to test how applications handle unexpected or malformed data.
- Intent Replay (TODO): Resend captured intents to test the stability and security of applications.
- Logging and Reporting (TODO): Detailed logging of all activities and comprehensive reporting to aid in vulnerability assessment.
Stheno can be used either as a standalone tool or in conjunction with Medusa.
-
Install the Requirements:
pip install -r requirements.txt
-
Build the Project: Navigate to the
Intent-monitorfolder and run:./gradlew build
-
Run the Application:
Option A: Using Gradle (Recommended)
./gradlew run
Option B: Using the JAR file
# Build the fat JAR with all dependencies ./gradlew fatJar # Run the JAR (requires JavaFX to be installed) java --module-path /usr/share/openjfx/lib --add-modules javafx.controls,javafx.fxml,javafx.web -jar build/libs/Intent-monitor-fat.jar
Option C: Using custom runtime (includes JavaFX)
# Create custom runtime with JavaFX included ./gradlew jlink # Run the custom runtime ./build/image/bin/Stheno
If you are using Stheno with Medusa, only step 2 is necessary:
-
Build the Project: Navigate to the
Intent-monitorfolder and run:./gradlew build
-
Run the Application: Use any of the methods described in step 3 above.
- Run the python script defining the target app that you want to monitor (e.g.
python3 stheno.py -t com.foo.bar) - Run the monitor and go to menu->start to start monitoring the intents
If you encounter "JavaFX runtime components are missing" error:
-
Install JavaFX:
sudo apt update sudo apt install openjfx libopenjfx-java
-
Use the custom runtime (recommended):
./gradlew jlink ./build/image/bin/Stheno
If you encounter module resolution errors:
-
Use Gradle run (simplest):
./gradlew run
-
Or use the custom runtime:
./gradlew jlink ./build/image/bin/Stheno
If the build fails:
-
Clean and rebuild:
./gradlew clean ./gradlew build
-
Check Java version:
java -version
Ensure you're using Java 17 or higher.
We welcome contributions from the community! To contribute:
- Fork the repository.
- Create a new branch for your feature or bugfix.
- Implement your changes and test thoroughly.
- Submit a pull request with a detailed description of your changes.

