Workflow: Data Storage & Exfiltration Analysis
Maps to MASTG-TEST-0001 / 0002 / 0003. Confirm what leaves the sandbox and what's readable without root.
1. Full dump (parallel)
dump_databases("com.target.app")
dump_shared_prefs("com.target.app")
dump_internal_storage("com.target.app")
dump_external_storage("com.target.app")
get_logcat("com.target.app")2. Sensitive-data grep
Search all dumped artifacts for: token, bearer, password, api_key, secret, jwt, -----BEGIN, SSN regex, PAN regex (\b(?:\d[ -]*?){13,16}\b), email regex.
3. Real-time write monitoring
frida_run_script(pid, """
Java.perform(function() {
var Editor = Java.use('android.app.SharedPreferencesImpl$EditorImpl');
Editor.putString.implementation = function(key, value) {
console.log('[PREFS] ' + key + ' = ' + value);
return this.putString(key, value);
};
});
""")4. External storage exposure
External paths (/sdcard/Android/data/...) are world-readable on pre-scoped-storage targets and readable by any app with READ_EXTERNAL_STORAGE on Android ≤ 10. Flag any credential/token/financial doc found there.
5. Backup & debuggable flags
From the manifest (via get_app_info): flag android:allowBackup=true and android:debuggable=true.
adb backup -apk -noshared com.target.app # if allowBackup=true6. SQLCipher-encrypted DBs
If dump_databases returns unreadable blobs, hook the open call:
frida_hook_method(pid, "net.sqlcipher.database.SQLiteDatabase", "openOrCreateDatabase")
frida_memory_search(pid, "PRAGMA key")Typical findings table
| Location | Sensitive data → Severity |
|---|---|
| SharedPreferences plaintext | auth_token / refresh_token → HIGH |
| Unencrypted SQLite | balances, transactions → HIGH |
| /files/*.json | PII (email, phone, SSN4) → MEDIUM |
| /sdcard/Android/data | statements, exports → MEDIUM |
| logcat | token/password echo → HIGH |