• 15 апреля стартует «Курс «SQL-injection Master» ©» от команды The Codeby

    За 3 месяца вы пройдете путь от начальных навыков работы с SQL-запросами к базам данных до продвинутых техник. Научитесь находить уязвимости связанные с базами данных, и внедрять произвольный SQL-код в уязвимые приложения.

    На последнюю неделю приходится экзамен, где нужно будет показать свои навыки, взломав ряд уязвимых учебных сайтов, и добыть флаги. Успешно сдавшие экзамен получат сертификат.

    Запись на курс до 25 апреля. Получить промодоступ ...

Заметка Android Cheatsheet (Partition, Path, Table, Description)

Темы, которые НЕ подходят по объему под префикс "Статья"

Sunnych

Mod. Forensics
Gold Team
01.06.2018
276
1 446
BIT
20
Эта тема продолжение темы Android, Ищем интересности в которой в сообщениях пользователей то же очень много полезной информации

DEVICE INFORMATION
Partition​
Path​
Table​
Description​
System/build.propN/ADevice information (version, patches, etc.)
Userdata/data/com.android.providers.calendar/databases/calendar.db*Calendar Items and Timezone information
Userdata/data/com.android.providers.settings/databases/settings.db*Lock settings information
Userdata/data/com.android.providers.settings/databases/settings.db-WAL*Lock settings information
Userdata/data/com.android.providers.settings/databases/locksettings.db*Lock settings information
Userdata/data/com.android.providers.settings/databases/locksettings.db-WAL*Lock settings information
Userdata/data/com.google.android.gms/shared_prefs/Checkin.xmlN/AActivity on device related to installed SIM (ICCID and Google Account included)
Userdata/data/com.google.android.gsf/databases/gservices.db*Fitness settings, network settings, other settings
Userdata/misc/N/ABluetooth, VPN, Wi-Fi and more
Userdata/Property/persist.sys.timezoneN/ATimezone (Up to Android 8)
Userdata/Property/persistent_propertiesN/ATimezone (From Android 9)
Userdata/system/*.keyN/AFiles needed for password cracking
Userdata/system/device_policies.xmlN/APasscode requirements and policies. Syncing info may exist
Userdata/system/locksettings.db*Lock settings information
Userdata/system/locksettings.db-WAL*Lock settings information
Userdata/system/netpolicy.xmlN/ATimezone
Userdata/system/SimCard.datN/ASim card and phone number information
Userdata/system/users/0/settings_global.xmlN/AGlobal settings
Userdata/system/users/0/settings_secure.xmlN/ASecure settings
Userdata/system/users/0/settings_system.xmlN/ASystem settings

PASSWORDS AND ACCOUNT INFORMATION
Partition​
Path​
Table​
Description​
Userdata/data/com.android.email/databases/EmailProvider.dbAccount, Email AddressCache, Mailbox*Email accounts, 3rd party app data, and messages associated with Email notifications, Email accounts, 3rd party app data, and messages associated with Email notifications
Userdata/data/com.android.providers.contacts/databases/contacts2.dbaccountsLogin info
Userdata/data/com.android.providers.settings/*N/AUsername and passwords
Userdata/data/com.android.vending/shared_prefs/lastaccount.xmlN/ALast account used on Google PlayStore (Android 9 and above)
Userdata/data/com.google.android.gms/shared_prefs/BackupAccount.xmlN/ABackup account email address
Userdata/data/com.google.android.googlequicksearchbox/databases/app_icons.db*Google Account Information
Userdata/data/com.google.android.googlequicksearchbox/databases/launcher.db*Google Account Information
Userdata/data/com.google.android.googlequicksearchbox/databases/opa_history*Google Account Information
Userdata/data/com.google.android.gsf/databases/gservices.db*Fitness settings, network settings, other settings
Userdata/system_ce/0/accounts_ce.db*Additional accounts (could also be system_de or accounts_de)
Userdata/system_de/0/accounts_de.db*Additional accounts (could also be system_de or accounts_de)
Userdata/misc/wifi/softap.confN/AHotspot Passwords
Userdata/misc/wifi/wpa_supplicant.confN/AWi-Fi Network Password
Userdata/system/accounts*.db*User account information
Userdata/system/sync/accounts.xmlN/AUser account information
Userdata/system/users/0/0.xmlN/AUser information

SYSTEM SETTINGS
Partition​
Path​
Table​
Description​
Userdata/data/com.google.android.gms/shared_prefs/*N/APreference files
Userdata/data/com.google.android.gsf/databases/gservices.db*Fitness settings, network settings, other settings
Userdata/system/recent_images/*.pngN/AApplication snapshots
Userdata/system_ce/recent_images/*.pngApplication snapshots
Userdata/system/users/0/settings_global.xmlN/AGlobal settings
Userdata/system/users/0/settings_secure.xmlN/ASecure Settings
Userdata/system/users/0/settings_system.xmlN/ASystem Settings

USER SETTINGS
Partition​
Path​
Table​
Description​
Userdata/data/com.android.providers.calendar/databases/calendar.db*Calendar Items and Timezone information
Userdata/data/com.android.providers.userdictionary/databases/user_dict.db*Dictionary Files (Keylogging)
Userdata/data/com.google.android.gms/databases/NetworkUsage.db*Application, User and Location traces
Userdata/data/com.google.android.gms/databases/ns.db*Application, User and Location traces
Userdata/data/com.google.android.gms/databases/reminders.db*Application, User and Location traces
Userdata/data/com.google.android.gsf/databases/googlesettings.db*Google preferences – location, maps, wallet, etc --1=true
Userdata/data/com.google.android.gsf/databases/gservices.db*Fitness settings, network settings, other settings
Userdata/data/com.sec.android.inputmethod/Swiftkey/user/dynamic.lmN/ADictionary Files (Keylogging) SwiftKey folder name may vary

COMMUNICATIONS - SMS, CALLS, EMAILS
Partition​
Path​
Table​
Description​
Cache**Gmail attachments, Downloads and Browser data
Userdata/data/com.android.providers.contacts/databases/calllog.dbcallsCall logs (From Android 7)
Userdata/data/com.android.providers.contacts/databases/contacts2.dbcallsCall logs (Up to Android 6)
Userdata/data/com.android.providers.telephony/databases/mmssms.dbsms and partSMS/MMS
Userdata/data/com.google.android.apps.messaging/databases/bugle_db*RCS/Android Messages (refer to notebook for query)
Userdata/data/com.google.android.dialer/databases/dialer.db*Call logs
Userdata/data/com.google.android.gm/databases/<mail-name>.dbconversations and messagesGmail snippets
Userdata/data/com.google.android.gm/databases/bigTopDataDB.<user-id>Email information
Userdata/data/com.google.android.gm/databases/EmailProvider.dbEmail information
Userdata/data/com.google.android.gms/databases/icing_mmssms.db*SMS/MMS
Userdata/data/com.google.android.gms/databases/ipa_mmssms.db*SMS/MMS
Userdata/data/com.sec.android.provider.logsprovider/databases/logs.dblogsCall logs

MULTIMEDIA
Partition​
Path​
Table​
Description​
Userdata/data/com.android.providers.media/databases/external*.db*Traces to SD card used in the device. This is stored on the phone.
Userdata/data/com.android.providers.media/databases/external*.db-WAL*Traces to SD card used in the device. This is stored on the phone.
Userdata/data/com.google.android.apps.photos/databases/gphotos0.dblocal_mediaCamera Photos information
Userdata/data/com.samsung.cmh/databases/cmh.dbfilesCamera Photo - Samsung Devices
Userdata/data/com.samsung.storyservice/databases/dme.dbinfoCamera Photo - Samsung Devices
Userdata/data/com.samsung.visionprovider/databases/visionprovider.dbfilesCamera Photo - Samsung Devices
Userdata/media/N/AActs like SD card

BROWSER ACTIVITY
Partition​
Path​
Table​
Description​
Cache*N/AGmail attachments, Downloads and Browser data
Userdata/data/com.android.browser/app_databases/**Internet History
Userdata/data/com.android.browser/app_geolocation/GeolocationPermissions.db*Internet History
Userdata/data/com.android.browser/databases/Browser.db
Userdata/data/com.android.browser/databases/browser2.db*Internet History
Userdata/data/com.android.browser/databases/webview.db*Internet History
Userdata/data/com.android.browser/databases/webviewCache.db*Internet History
Userdata/data/com.android.email/webviewCache.db*Internet History

NETWORK CONNECTIONS
Partition​
Path​
Table​
Description​
Userdata/data/com.android.connectivity.metrics/databases/events.dbcompleted_events_requestsUSB, Bluetooth, NFC and other connects - Acquisition connection tracked here
Userdata/data/com.google.android.gms/databases/herrevad*Wireless network and MAC addresses
Userdata/data/com.google.android.locations/files/cache.cell*Cellular and WiFi
Userdata/data/com.google.android.locations/files/cache.wifi*Cellular and WiFi
Userdata/misc/wifi/WifiConfigStore.xmlN/AWireless network

SYNCING ARTIFACTS
Partition​
Path​
Table​
Description​
Userdata/data/com.google.android.apps.docs.editors.docs/databases/**Google Docs
Userdata/data/com.google.android.apps.docs.editors.sheets/databases/**Google Docs
Userdata/data/com.google.android.apps.docs.editors.slides/databases/**Google Docs
Userdata/data/com.google.android.apps.docs/databases/**Google Docs
Userdata/data/com.google.android.apps.genie.geniewidget/databases/newsweather.db*Sync activity
Userdata/data/com.google.android.gms/databases/peoplelog.db*Sync activity - contacts
Userdata/data/com.google.android.gms/shared_prefs/com.google.android.gms.auth.authzen.cryptauth.SyncManager.proximity_features.xmlN/ASync Activity
Userdata/system/sync/accounts.xmlSynced Accounts

LOCATION ARTIFACTS
Partition​
Path​
Table​
Description​
Userdata/data/com.google.android.apps.maps/databases/da_destination_historydestination historyMaps
Userdata/data/com.google.android.apps.maps/databases/gmm_storage.db*Search history Maps
Userdata/data/com.google.android.apps.maps/databases/search_history.dbhistory and suggestionsMaps
Userdata/data/com.google.android.apps.maps/databases/gmm_sync.db*Syncing
Userdata/data/com.sec.android.daemonapp/db/weatherClock*Location artifacts
Userdata/Media/0/DCIM/Camera*EXIF data with location info

APPLICATION USAGE
Partition​
Path​
Table​
Description​
Userdata/app/*N/AAPK files for installed applications
Userdata/dalvik-cacheN/A.dex/.oat/.art files for installed applications
Userdata/data/"Application Folder"N/AApplication Data Files*
Userdata/data/com.android.vending/databases/data_usage.dbapp_data_usageApplication traces
Userdata/data/com.android.vending/databases/frosting.dbfrostingApplication traces
Userdata/data/com.android.vending/databases/install_queue.dbinstall_requestsApplication traces
Userdata/data/com.android.vending/databases/library.dbownershipApplication traces
Userdata/data/com.android.vending/databases/localappstate.dbappstateApplication traces
Userdata/data/com.android.vending/databases/notification_cachenotificationsApplication traces
Userdata/data/com.android.vending/databases/package_verification.dbverification_cacheApplication traces
Userdata/data/com.android.vending/databases/suggestions.dbsuggestionsApplication traces
Userdata/data/com.android.vending/databases/verify_apps.db*Application traces
Userdata/data/com.google.android.gms/databases/config.dbmainApplication traces
Userdata/data/com.google.android.gms/databases/gass.dbapp_infoApplication traces
Userdata/data/com.google.android.gms/databases/gcm_registrar.dbpackagesApplication traces
Userdata/data/com.google.android.gms/databases/google_app_measurement.db*Application traces
Userdata/data/com.google.android.gms/shared_prefs/batterystats.xmlN/ABattery Usage Stats - Contains Application Usage information
Userdata/data/com.google.android.googlequicksearchbox/*N/AGoogle App searches, installed applications and more
Userdata/data/com.samsung.android.providers.context.databases.ContextLog_0.db*Application traces (Samsung devices)
Userdata/data/com.sec.android.app.launcher/databases/launcher.dbN/AApplication artifacts (even after deleted)
Userdata/data/data/com.google.android.gms/files/batterystatsdumpsystask.gzN/ABattery Usage Stats - Contains Application Usage information
Userdata/system/appops.xmlN/AApplication permissions
Userdata/system/batterystats.binN/ABattery Usage Stats - Contains Application Usage information
Userdata/system/batterystats-checkin.binN/ABattery Usage Stats - Contains Application Usage information
Userdata/system/batterystats-daily.xmlN/ABattery Usage Stats - Contains Application Usage information
Userdata/system/dmappmgr.dbN/AApplication Usage
Userdata/system/job/jobs.xmlN/AApplication Usage
Userdata/system/notification_log.dbN/AApplication notifications
Userdata/system/packages.listN/AApplication permissions and metadata
Userdata/system/packages.xmlN/AApplication permissions
Userdata/system/usagestats/0/*N/AApplication Usage Stats
Userdata/system/users/0/app_idle_stats.xmlN/AApplication Usage
Userdata/system_ce/0/recent_images/*.pngN/AApplication snapshots
Userdata/system_ce/0/recent_tasks/*.xmlN/ARecent Tasks

NATIVE APPLICATIONS
Partition​
Path​
Table​
Description​
Userdata/data/com.android.providers.calendar/databases/calendar.db*Calendar Items
Userdata/data/com.android.providers.contacts/databases/contacts2.dbcontacts and raw contactsContacts
Userdata/data/com.android.providers.contacts/databases/contacts2.dbcallsCall Logs
Userdata/data/com.android.providers.contacts/databases/calllog.dbcallsCall Logs
Userdata/data/com.android.providers.downloads/databases/downloads.db*Downloads
Userdata/data/com.google.android.gms/databases/icing_contacts.db*Contacts
Userdata/data/com.google.android.gms/databases/icing_mmssms.dbMMS/SMS
Userdata/data/com.google.android.gms/databases/ipa_mmssms.db*MMS/SMS
Userdata/data/com.google.android.gms/databases/android_paywalletAndroid Pay
Userdata/data/com.google.android.gms/databases/pluscontacts.db*Google+ Contacts

Файл вложения "poster.pdf" это for585.com/poster SANS The Most Relevant Evidence per Gigabyte
и не только ;-)

Дополнительный ресурс с материалами и примерами Android Forensics References -> USERDATA Partition (Last update: September 6th 2022)
 

Вложения

  • poster.pdf
    3 МБ · Просмотры: 1 031
  • 330.pdf
    1,2 МБ · Просмотры: 179
Последнее редактирование:

Mogen

Red Team
27.08.2019
314
610
BIT
5
Эта заметка очень сильно экономит время при форензике.
Спасибо, @Sunnych (y)
 
  • Нравится
Реакции: nks1ck

apache2

Green Team
26.02.2021
32
16
BIT
202
Ты лучший бро! с тобой так и хочется учить форензику :)

а для Windows есть такое?
а то я хз где эти control001\set.......
 
  • Нравится
Реакции: Mogen

Sunnych

Mod. Forensics
Gold Team
01.06.2018
276
1 446
BIT
20
Эта заметка очень сильно экономит время при форензике.
Спасибо, @Sunnych (y)
Спасибо, но мало кто замечает, я некоторые статьи дополняю или обновляю - как например тут появилась ссылка на Android Forensics References с множеством практических примеров, выбирай и качай то что тебя именно интересует и читать и читать. Так же сегодня обновил и добавил в
 
  • Нравится
Реакции: Mogen
Мы в соцсетях:

Обучение наступательной кибербезопасности в игровой форме. Начать игру!