Every Step You Take - Application and Network Usage in Android
Every Step You Take - Application and Network Usage in Android
Jessica Hyde
Director of Forensics – Magnet Forensics
Adjunct Professor – George Mason University
June 8, 2018
Jessica
Director Forensics, Magnet Forensics
Adjunct Professor, George Mason University
Previous:
• Basis Technology
• Ernst and Young
• American Systems
• United States Marine Corps
● Web Browsers
● Chat App
● Email
○ OS Artifacts
● Why don’t we apply this
concept to our Android
applications?
● Why would it be useful?
SANS DFIR Summit - 2018
Using Application Analysis
Looks
○ Multi-user
○ Second Device
● \data\com.android.vending\databases\library.db
● \data\system\usagestats\0\
● ..\daily, \monthly. \weekly,
\yearly
● .xml file named as epoch
timestamp
SANS DFIR Summit - 2018
Android Usage History
● https://developer.android.com/reference/and
roid/app/usage/UsageEvents.Event
Looks
○ User Interaction
○ Move to Foreground
○ Move to Background
○ Configuration Change
Looks
Looks
● \data\data\com.google.androi
d.gms\shared_prefs\Batterysta
ts.xml
● Think of this as SRUM for
Android
SANS DFIR Summit - 2018
Battery Status
● \data\data\com.google.android.gms\shared_
prefs\Batterystats.xml
Looks
● \data\data\com.google.android.gms\files
\BatterystatsDumpsysTask.gz
Looks
Looks
Looks
● \system_ce\0\recent_images
Looks
● \system_ce\0\recent_images
Looks
Looks
● \system_ce\0\recent_tasks
Looks
● \system_ce\0\recent_tasks
Looks
Looks
Looks
Looks
Looks
Looks
● \system_ce\0\shortcut_service\ snapshots
Looks
Looks
Looks
Looks
● com.cleanmaster.security
○ On lots of devices
Looks
media\0\Android\data\com.cleanmaster.se
curity\files\logs\
Looks
media\0\Android\data\com.cleanmaster.security
\files\logs\AppLockLog
Looks
Looks
Looks
Looks
Looks
● Takeout
○ Download “My Activity” from
Looks
https://takeout.google.com/u/1/setting
s/takeout with credentials
Looks
Looks
Looks
Looks
Looks
uid stats 10103 com.twitter.android UID Stats Twitter Cell 1526040000 5/11/18 12:00 PM
recent tasks 244 10103 com.twitter.android first active time 1526045035484 5/11/18 1:23 PM
recent tasks 244 10103 com.twitter.android last time moved 1526045563392 5/11/18 1:32 PM
recent tasks 244 10103 com.twitter.android last active time 1526045600000 5/11/18 1:33 PM
uid netstats 10103 com.twitter.android UID Stats Twitter Cell 1526040000 5/11/18 2:00 PM
• “Big Brother was definitely watching as George Burch killed Nicole VanderHyden”
• https://www.greenbaypressgazette.com/story/news/2018/03/04/big-brother-phone-
george-burch-nicole-vanderheyden-murder-trial-gps-fitbit-snapshot-google/390236002/
Steps
Steps
Floors
Climbed
Heart Rate
Sleep
Sleep
Jessica Hyde
Twitter: @B1N2H3X
Email: [email protected]