Заметка Android Cheatsheet (Partition, Path, Table, Description)

Темы, которые НЕ подходят по объему под префикс "Статья"

Sunnych

Mod. Forensics
Gold Team
01.06.2018
277
1 454
BIT
41
Эта тема продолжение темы Android, Ищем интересности в которой в сообщениях пользователей то же очень много полезной информации

DEVICE INFORMATION
Partition​
Path​
Table​
Description​
System/build.propN/ADevice information (version, patches, etc.)
Userdata/data/com.android.providers.calendar/databases/calendar.db*Calendar Items and Timezone information
Userdata/data/com.android.providers.settings/databases/settings.db*Lock settings information
Userdata/data/com.android.providers.settings/databases/settings.db-WAL*Lock settings information
Userdata/data/com.android.providers.settings/databases/locksettings.db*Lock settings information
Userdata/data/com.android.providers.settings/databases/locksettings.db-WAL*Lock settings information
Userdata/data/com.google.android.gms/shared_prefs/Checkin.xmlN/AActivity on device related to installed SIM (ICCID and Google Account included)
Userdata/data/com.google.android.gsf/databases/gservices.db*Fitness settings, network settings, other settings
Userdata/misc/N/ABluetooth, VPN, Wi-Fi and more
Userdata/Property/persist.sys.timezoneN/ATimezone (Up to Android 8)
Userdata/Property/persistent_propertiesN/ATimezone (From Android 9)
Userdata/system/*.keyN/AFiles needed for password cracking
Userdata/system/device_policies.xmlN/APasscode requirements and policies. Syncing info may exist
Userdata/system/locksettings.db*Lock settings information
Userdata/system/locksettings.db-WAL*Lock settings information
Userdata/system/netpolicy.xmlN/ATimezone
Userdata/system/SimCard.datN/ASim card and phone number information
Userdata/system/users/0/settings_global.xmlN/AGlobal settings
Userdata/system/users/0/settings_secure.xmlN/ASecure settings
Userdata/system/users/0/settings_system.xmlN/ASystem settings

PASSWORDS AND ACCOUNT INFORMATION
Partition​
Path​
Table​
Description​
Userdata/data/com.android.email/databases/EmailProvider.dbAccount, Email AddressCache, Mailbox*Email accounts, 3rd party app data, and messages associated with Email notifications, Email accounts, 3rd party app data, and messages associated with Email notifications
Userdata/data/com.android.providers.contacts/databases/contacts2.dbaccountsLogin info
Userdata/data/com.android.providers.settings/*N/AUsername and passwords
Userdata/data/com.android.vending/shared_prefs/lastaccount.xmlN/ALast account used on Google PlayStore (Android 9 and above)
Userdata/data/com.google.android.gms/shared_prefs/BackupAccount.xmlN/ABackup account email address
Userdata/data/com.google.android.googlequicksearchbox/databases/app_icons.db*Google Account Information
Userdata/data/com.google.android.googlequicksearchbox/databases/launcher.db*Google Account Information
Userdata/data/com.google.android.googlequicksearchbox/databases/opa_history*Google Account Information
Userdata/data/com.google.android.gsf/databases/gservices.db*Fitness settings, network settings, other settings
Userdata/system_ce/0/accounts_ce.db*Additional accounts (could also be system_de or accounts_de)
Userdata/system_de/0/accounts_de.db*Additional accounts (could also be system_de or accounts_de)
Userdata/misc/wifi/softap.confN/AHotspot Passwords
Userdata/misc/wifi/wpa_supplicant.confN/AWi-Fi Network Password
Userdata/system/accounts*.db*User account information
Userdata/system/sync/accounts.xmlN/AUser account information
Userdata/system/users/0/0.xmlN/AUser information

SYSTEM SETTINGS
Partition​
Path​
Table​
Description​
Userdata/data/com.google.android.gms/shared_prefs/*N/APreference files
Userdata/data/com.google.android.gsf/databases/gservices.db*Fitness settings, network settings, other settings
Userdata/system/recent_images/*.pngN/AApplication snapshots
Userdata/system_ce/recent_images/*.pngApplication snapshots
Userdata/system/users/0/settings_global.xmlN/AGlobal settings
Userdata/system/users/0/settings_secure.xmlN/ASecure Settings
Userdata/system/users/0/settings_system.xmlN/ASystem Settings

USER SETTINGS
Partition​
Path​
Table​
Description​
Userdata/data/com.android.providers.calendar/databases/calendar.db*Calendar Items and Timezone information
Userdata/data/com.android.providers.userdictionary/databases/user_dict.db*Dictionary Files (Keylogging)
Userdata/data/com.google.android.gms/databases/NetworkUsage.db*Application, User and Location traces
Userdata/data/com.google.android.gms/databases/ns.db*Application, User and Location traces
Userdata/data/com.google.android.gms/databases/reminders.db*Application, User and Location traces
Userdata/data/com.google.android.gsf/databases/googlesettings.db*Google preferences – location, maps, wallet, etc --1=true
Userdata/data/com.google.android.gsf/databases/gservices.db*Fitness settings, network settings, other settings
Userdata/data/com.sec.android.inputmethod/Swiftkey/user/dynamic.lmN/ADictionary Files (Keylogging) SwiftKey folder name may vary

COMMUNICATIONS - SMS, CALLS, EMAILS
Partition​
Path​
Table​
Description​
Cache**Gmail attachments, Downloads and Browser data
Userdata/data/com.android.providers.contacts/databases/calllog.dbcallsCall logs (From Android 7)
Userdata/data/com.android.providers.contacts/databases/contacts2.dbcallsCall logs (Up to Android 6)
Userdata/data/com.android.providers.telephony/databases/mmssms.dbsms and partSMS/MMS
Userdata/data/com.google.android.apps.messaging/databases/bugle_db*RCS/Android Messages (refer to notebook for query)
Userdata/data/com.google.android.dialer/databases/dialer.db*Call logs
Userdata/data/com.google.android.gm/databases/<mail-name>.dbconversations and messagesGmail snippets
Userdata/data/com.google.android.gm/databases/bigTopDataDB.<user-id>Email information
Userdata/data/com.google.android.gm/databases/EmailProvider.dbEmail information
Userdata/data/com.google.android.gms/databases/icing_mmssms.db*SMS/MMS
Userdata/data/com.google.android.gms/databases/ipa_mmssms.db*SMS/MMS
Userdata/data/com.sec.android.provider.logsprovider/databases/logs.dblogsCall logs

MULTIMEDIA
Partition​
Path​
Table​
Description​
Userdata/data/com.android.providers.media/databases/external*.db*Traces to SD card used in the device. This is stored on the phone.
Userdata/data/com.android.providers.media/databases/external*.db-WAL*Traces to SD card used in the device. This is stored on the phone.
Userdata/data/com.google.android.apps.photos/databases/gphotos0.dblocal_mediaCamera Photos information
Userdata/data/com.samsung.cmh/databases/cmh.dbfilesCamera Photo - Samsung Devices
Userdata/data/com.samsung.storyservice/databases/dme.dbinfoCamera Photo - Samsung Devices
Userdata/data/com.samsung.visionprovider/databases/visionprovider.dbfilesCamera Photo - Samsung Devices
Userdata/media/N/AActs like SD card

BROWSER ACTIVITY
Partition​
Path​
Table​
Description​
Cache*N/AGmail attachments, Downloads and Browser data
Userdata/data/com.android.browser/app_databases/**Internet History
Userdata/data/com.android.browser/app_geolocation/GeolocationPermissions.db*Internet History
Userdata/data/com.android.browser/databases/Browser.db
Userdata/data/com.android.browser/databases/browser2.db*Internet History
Userdata/data/com.android.browser/databases/webview.db*Internet History
Userdata/data/com.android.browser/databases/webviewCache.db*Internet History
Userdata/data/com.android.email/webviewCache.db*Internet History

NETWORK CONNECTIONS
Partition​
Path​
Table​
Description​
Userdata/data/com.android.connectivity.metrics/databases/events.dbcompleted_events_requestsUSB, Bluetooth, NFC and other connects - Acquisition connection tracked here
Userdata/data/com.google.android.gms/databases/herrevad*Wireless network and MAC addresses
Userdata/data/com.google.android.locations/files/cache.cell*Cellular and WiFi
Userdata/data/com.google.android.locations/files/cache.wifi*Cellular and WiFi
Userdata/misc/wifi/WifiConfigStore.xmlN/AWireless network

SYNCING ARTIFACTS
Partition​
Path​
Table​
Description​
Userdata/data/com.google.android.apps.docs.editors.docs/databases/**Google Docs
Userdata/data/com.google.android.apps.docs.editors.sheets/databases/**Google Docs
Userdata/data/com.google.android.apps.docs.editors.slides/databases/**Google Docs
Userdata/data/com.google.android.apps.docs/databases/**Google Docs
Userdata/data/com.google.android.apps.genie.geniewidget/databases/newsweather.db*Sync activity
Userdata/data/com.google.android.gms/databases/peoplelog.db*Sync activity - contacts
Userdata/data/com.google.android.gms/shared_prefs/com.google.android.gms.auth.authzen.cryptauth.SyncManager.proximity_features.xmlN/ASync Activity
Userdata/system/sync/accounts.xmlSynced Accounts

LOCATION ARTIFACTS
Partition​
Path​
Table​
Description​
Userdata/data/com.google.android.apps.maps/databases/da_destination_historydestination historyMaps
Userdata/data/com.google.android.apps.maps/databases/gmm_storage.db*Search history Maps
Userdata/data/com.google.android.apps.maps/databases/search_history.dbhistory and suggestionsMaps
Userdata/data/com.google.android.apps.maps/databases/gmm_sync.db*Syncing
Userdata/data/com.sec.android.daemonapp/db/weatherClock*Location artifacts
Userdata/Media/0/DCIM/Camera*EXIF data with location info

APPLICATION USAGE
Partition​
Path​
Table​
Description​
Userdata/app/*N/AAPK files for installed applications
Userdata/dalvik-cacheN/A.dex/.oat/.art files for installed applications
Userdata/data/"Application Folder"N/AApplication Data Files*
Userdata/data/com.android.vending/databases/data_usage.dbapp_data_usageApplication traces
Userdata/data/com.android.vending/databases/frosting.dbfrostingApplication traces
Userdata/data/com.android.vending/databases/install_queue.dbinstall_requestsApplication traces
Userdata/data/com.android.vending/databases/library.dbownershipApplication traces
Userdata/data/com.android.vending/databases/localappstate.dbappstateApplication traces
Userdata/data/com.android.vending/databases/notification_cachenotificationsApplication traces
Userdata/data/com.android.vending/databases/package_verification.dbverification_cacheApplication traces
Userdata/data/com.android.vending/databases/suggestions.dbsuggestionsApplication traces
Userdata/data/com.android.vending/databases/verify_apps.db*Application traces
Userdata/data/com.google.android.gms/databases/config.dbmainApplication traces
Userdata/data/com.google.android.gms/databases/gass.dbapp_infoApplication traces
Userdata/data/com.google.android.gms/databases/gcm_registrar.dbpackagesApplication traces
Userdata/data/com.google.android.gms/databases/google_app_measurement.db*Application traces
Userdata/data/com.google.android.gms/shared_prefs/batterystats.xmlN/ABattery Usage Stats - Contains Application Usage information
Userdata/data/com.google.android.googlequicksearchbox/*N/AGoogle App searches, installed applications and more
Userdata/data/com.samsung.android.providers.context.databases.ContextLog_0.db*Application traces (Samsung devices)
Userdata/data/com.sec.android.app.launcher/databases/launcher.dbN/AApplication artifacts (even after deleted)
Userdata/data/data/com.google.android.gms/files/batterystatsdumpsystask.gzN/ABattery Usage Stats - Contains Application Usage information
Userdata/system/appops.xmlN/AApplication permissions
Userdata/system/batterystats.binN/ABattery Usage Stats - Contains Application Usage information
Userdata/system/batterystats-checkin.binN/ABattery Usage Stats - Contains Application Usage information
Userdata/system/batterystats-daily.xmlN/ABattery Usage Stats - Contains Application Usage information
Userdata/system/dmappmgr.dbN/AApplication Usage
Userdata/system/job/jobs.xmlN/AApplication Usage
Userdata/system/notification_log.dbN/AApplication notifications
Userdata/system/packages.listN/AApplication permissions and metadata
Userdata/system/packages.xmlN/AApplication permissions
Userdata/system/usagestats/0/*N/AApplication Usage Stats
Userdata/system/users/0/app_idle_stats.xmlN/AApplication Usage
Userdata/system_ce/0/recent_images/*.pngN/AApplication snapshots
Userdata/system_ce/0/recent_tasks/*.xmlN/ARecent Tasks

NATIVE APPLICATIONS
Partition​
Path​
Table​
Description​
Userdata/data/com.android.providers.calendar/databases/calendar.db*Calendar Items
Userdata/data/com.android.providers.contacts/databases/contacts2.dbcontacts and raw contactsContacts
Userdata/data/com.android.providers.contacts/databases/contacts2.dbcallsCall Logs
Userdata/data/com.android.providers.contacts/databases/calllog.dbcallsCall Logs
Userdata/data/com.android.providers.downloads/databases/downloads.db*Downloads
Userdata/data/com.google.android.gms/databases/icing_contacts.db*Contacts
Userdata/data/com.google.android.gms/databases/icing_mmssms.dbMMS/SMS
Userdata/data/com.google.android.gms/databases/ipa_mmssms.db*MMS/SMS
Userdata/data/com.google.android.gms/databases/android_paywalletAndroid Pay
Userdata/data/com.google.android.gms/databases/pluscontacts.db*Google+ Contacts

Файл вложения "poster.pdf" это for585.com/poster SANS The Most Relevant Evidence per Gigabyte
и не только ;-)

Дополнительный ресурс с материалами и примерами Android Forensics References -> USERDATA Partition (Last update: September 6th 2022)
 

Вложения

  • poster.pdf
    3 МБ · Просмотры: 2 420
  • 330.pdf
    1,2 МБ · Просмотры: 242
Последнее редактирование:

ROP

Red Team
27.08.2019
327
664
BIT
163
Эта заметка очень сильно экономит время при форензике.
Спасибо, @Sunnych (y)
 
  • Нравится
Реакции: nks1ck

apache2

Green Team
26.02.2021
42
22
BIT
302
Ты лучший бро! с тобой так и хочется учить форензику :)

а для Windows есть такое?
а то я хз где эти control001\set.......
 
  • Нравится
Реакции: ROP

Sunnych

Mod. Forensics
Gold Team
01.06.2018
277
1 454
BIT
41
Эта заметка очень сильно экономит время при форензике.
Спасибо, @Sunnych (y)
Спасибо, но мало кто замечает, я некоторые статьи дополняю или обновляю - как например тут появилась ссылка на Android Forensics References с множеством практических примеров, выбирай и качай то что тебя именно интересует и читать и читать. Так же сегодня обновил и добавил в
 
  • Нравится
Реакции: ROP
Мы в соцсетях:

Обучение наступательной кибербезопасности в игровой форме. Начать игру!