Example: Data Storage Investigation
Goal: enumerate sensitive data the app persists locally.
Tool-call blueprint
prefs = dump_shared_prefs("com.megabank.mobile")
dbs = dump_databases("com.megabank.mobile")
internal = dump_internal_storage("com.megabank.mobile")
external = dump_external_storage("com.megabank.mobile")
logs = get_logcat("com.megabank.mobile")Findings template (populate per hit)
| Artifact | Sensitive content | Severity | MASTG |
|---|---|---|---|
auth_prefs.xml |
auth_token, refresh_token, pin_hash plaintext |
HIGH | MASTG-TEST-0001 |
app_data.db |
accounts (account#, balance), transactions, cached_credentials |
HIGH | MASTG-TEST-0001 |
/files/user_profile.json |
name, email, phone, ssn_last_4 | MEDIUM | MASTG-TEST-0002 |
/Android/data/.../exports/statements_*.pdf |
world-readable statements | MEDIUM | MASTG-TEST-0003 |
Evidence required per finding
- File path, byte size, exact plaintext snippet (redacted as needed)
package_name,device_id, capture timestamp- Copy of the file into the evidence bundle under
evidence/data_storage/
Follow-ups
- If DB is SQLCipher-encrypted: see workflows/data_exfiltration.md §6
- If
allowBackup=true: runadb backup -apk -noshared com.megabank.mobile