Consensual Forensics with Android Intrusion Logging


A few months back Android introduced their new intrusion logging capabilities as part of their advanced protection mode. Security Lab has a great blog on everything about them. It really breaks them down into three different categories from the samples I've seen:
  • Security Events - A lot of types, including ADB commands, packages installed/uninstalled, process starts and more
  • DNS Events - Hostnames, IP addresses
  • Connection Events - IP addresses, package names, ports
It really allows you to then run IOCs on the logs to see if anything suspicious may be connecting to your mobile device or other connections or packages running that shouldn't be. I don't think there are many tools that support parsing these logs at this time but ALEAPP does now after a quick run through Python. The files are just JSON after all.

Figure 1: LAVA output from Android Intrusion Logging parsers

As for the acquisition side of the house, you can zip them and export them yourself or you can use MVT or now ALEX from Christian Peter. I had proposed the suggestion to him the other day and he had a workflow done in under 3 hours. I always like his included helpful graphics that walk you through the touches.


Figure 2: ALEX infographic for kicking off intrusion logs

As always, grab the latest ALEAPP codebase for the parser support now, and it will be baked into the next compiled release coming soon.