Android Network Intelligence & Host Discovery Toolkit
Built for practical DNS, HTTP, TLS, certificate, subdomain and host investigation.
GlobalHostIntelligence (GHI) is an Android network-intelligence toolkit with an embedded Go engine. The application is designed to provide useful host and network investigation capabilities directly on Android without requiring a separate server or Termux installation.
GHI combines discovery, live validation and focused network-analysis tools in one Android application.
Project status: Active development. Features and interfaces may continue to evolve between releases.
- Parallel passive discovery using multiple public/free sources.
- Candidate hostname normalization and de-duplication.
- Concurrent HTTP/HTTPS validation.
- Live-host identification and source/error reporting.
- Hostname details that can be expanded directly from results.
- Configurable discovery limits, validation workers, source parallelism and timeouts.
The Response Checker provides an HTTP Custom-style testing workflow with support for:
- GET
- HEAD
- POST
- PUT
- PATCH
- OPTIONS
- Custom headers
- Request bodies
- Redirect handling
- TLS handling
- Timeout control
- DNS/resolver diagnostics
- Status and response details
- Response preview and copy controls
- Domain → IP resolution.
- IP → observed domain lookup.
- Multiple inputs can be processed concurrently.
- Results are normalized for investigation workflows.
Generate protocol-valid HTTP/1.1 request variants from a target, including:
- Standard HTTP/HTTPS requests.
- Raw and absolute-form requests.
- Keep-alive variants.
- WebSocket handshake variants.
- Custom headers and body content.
- cURL export.
- Fetch export.
- Per-payload and Copy All controls.
Inspect available TLS connection information including:
- TLS version.
- Cipher.
- ALPN.
- Certificate metadata.
- SHA-256 certificate fingerprint.
- Leaf certificate PEM.
- Peer certificate chain information.
Inspect common DNS records where available:
A · AAAA · CNAME · MX · NS · TXT · SRV · PTR
Search public Certificate Transparency data for domain and certificate information.
GHI can combine host, DNS, TLS, security-header, redirect, timing, technology, web-surface and certificate information into a broader investigation workflow.
Inspect the target's public web surface without recursive crawling, including:
- Landing page metadata.
robots.txt.sitemap.xml.security.txt.- Android association metadata.
- iOS association metadata.
- Web manifest metadata.
The GHI Agent routes plain-language requests to real local engines or supported public web search functionality. It is designed to expose actual tool results rather than fabricate remote-LLM activity.
Export discovered live hosts as:
- TXT
- CSV
- JSON
| Target | Support |
|---|---|
| Android | Android 8.0+ (minSdk 26) |
| ARM 32-bit | armeabi-v7a |
| ARM 64-bit | arm64-v8a |
| Application ID | io.ciphertun.ghi |
| Current version | 4.1.0 |
| Compile SDK | 37 |
| Target SDK | 37 |
| Java | 17 |
The release pipeline packages the embedded native Go engine for the Android ARM ABIs used by the project.
Official builds are published through the repository's Releases page when a release is created:
GitHub Actions also produces release APK artifacts from the project's release workflow.
The repository currently has no GitHub Release published. The first formal release can be created after the release APK workflow completes successfully.
Screenshots should show the actual current application UI rather than mocked or unrelated images.
Recommended public screenshots:
- Discovery screen.
- Live discovery results with hostname details expanded.
- Response Checker.
- Payload Generator.
- TLS/DNS analysis.
- Settings.
- Main navigation/menu.
Place verified screenshots under docs/screenshots/ and add them to this section using relative Markdown image paths.
GHI uses a two-stage Android build pipeline:
- The mobile core is built as an AAR.
- The release workflow downloads the matching AAR from the successful Actions run.
- The AAR is injected into the Android project.
- Android is built with Gradle.
- The signed release APK is verified and uploaded as an Actions artifact.
The release configuration currently disables R8/minification and resource shrinking to keep the release build predictable.
The project is primarily Kotlin/Jetpack Compose on Android with an embedded Go-based engine.
Current Android build configuration includes:
- Android Gradle Plugin / Gradle-based Android build.
- Kotlin + Jetpack Compose.
- Hilt dependency injection.
- AndroidX lifecycle/navigation components.
- Google Mobile Ads SDK.
- User Messaging Platform for ad consent.
The application contains consent-aware advertising and rate-limited ad experiences.
The repository's production AdMob configuration is intentionally kept in the application source and release verification workflow. Do not replace, remove or publish private advertising/account credentials.
GHI is a network-intelligence and diagnostic tool. Only investigate systems, domains and networks that you own or have explicit permission to test.
Some discovery and Certificate Transparency features use public internet data. Availability, accuracy and freshness of third-party data sources can change independently of GHI.
Please do not report sensitive vulnerabilities in a public issue.
See SECURITY.md for the responsible disclosure process.
Contributions, bug reports, documentation improvements and feature proposals are welcome.
Read CONTRIBUTING.md before opening a pull request.
GlobalHostIntelligence is released under the MIT License.
See LICENSE for the full license text.
- Repository: https://github.com/CipherTun/GlobalHostIntelligence
- Releases: https://github.com/CipherTun/GlobalHostIntelligence/releases
- Issues: https://github.com/CipherTun/GlobalHostIntelligence/issues
- Security: https://github.com/CipherTun/GlobalHostIntelligence/security
Included example: docs/screenshots/08-discovery-with-ad.png — Discovery screen with an advertisement placement.