अपडेट पर वापस जाएँ
New releaseSep 11, 2026

ALEAPP v2026.3.3

Android लॉग्स इवेंट्स और Protobuf पार्सर

साझा करें

ALEAPP

Android Logs Events And Protobuf Parser

अगर आप योगदान देना चाहते हैं तो मुझसे यहाँ संपर्क करें: https://abrignoni.github.io

ब्लॉग पोस्ट यहाँ: https://leapps.org/blog

आवश्यकताएँ

Python 3.10 या उससे ऊपर

निर्भरताएँ

आपके python environment के लिए निर्भरताएँ requirements.txt में सूचीबद्ध हैं। इन्हें नीचे दिए गए कमांड का उपयोग करके इंस्टॉल करें। सुनिश्चित करें कि py वाला हिस्सा आपके environment के लिए सही है, जैसे py, python, या python3, आदि।

py -m pip install -r requirements.txt या pip3 install -r requirements.txt

Linux पर चलाने के लिए, आपको tkinter को अलग से इंस्टॉल करना होगा, इस तरह:

sudo apt-get install python3-tk

Executable में कंपाइल करें

इसे executable में कंपाइल करने के लिए ताकि आप इसे बिना python इंस्टॉल किए किसी सिस्टम पर चला सकें।

Windows OS

aleapp.exe बनाने के लिए, चलाएँ:

pyinstaller scripts\pyinstaller\aleapp.spec

aleappGUI.exe बनाने के लिए, चलाएँ:

pyinstaller scripts\pyinstaller\aleappGUI.spec

macOS

aleapp बनाने के लिए, चलाएँ:

pyinstaller scripts/pyinstaller/aleapp_macOS.spec

aleappGUI.app बनाने के लिए, चलाएँ:

pyinstaller scripts/pyinstaller/aleappGUI_macOS.spec

Linux

aleapp बनाने के लिए, चलाएँ:

pyinstaller scripts/pyinstaller/aleapp_Linux.spec

aleappGUI बनाने के लिए, चलाएँ:

pyinstaller scripts/pyinstaller/aleappGUI_Linux.spec

उपयोग

CLI

$ python aleapp.py -t <zip | tar | fs | gz | raw> -i <path_to_extraction> -o <path_for_report_output>

raw एक disk image (.img, .dd, .bin, या split set का कोई भी क्रमांकित .001 सेगमेंट), या एक EnCase/EWF .E01 acquisition और उसके साथ के सेगमेंट को, यथास्थान पढ़ता है: न mounting और न ही administrator अधिकार। इसके NTFS, FAT32, exFAT, ext2/3/4, F2FS, HFS+, APFS, QNX6, QNX4, ETFS, EFS, SquashFS, JFFS2, UBI/UBIFS, YAFFS और QNX IFS volumes को सीधे खोजा जाता है, और image से केवल वही फ़ाइलें पढ़ी जाती हैं जिनकी किसी artifact को आवश्यकता होती है। GUI उन extensions के लिए स्वयं raw चुनता है। देखें admin/docs/raw_image_input.md।

tar एक xz-compressed tar (.tar.xz) भी पढ़ता है, और GUI उस extension के लिए tar चुनता है। एक compressed tar, जिसमें .tar.gz भी शामिल है, किसी भी फ़ाइल को पढ़ने से पहले report folder में एक बार decompress किया जाता है, इसलिए उस run को वहाँ uncompressed tar के लिए खाली जगह चाहिए। यह copy run समाप्त होने पर हटा दी जाती है, और run log बताता है कि उस step में कितना समय लगा।

GUI

$ python aleappGUI.py

सहायता

$ python aleapp.py --help

Artifact plugins में योगदान

प्रत्येक plugin एक Python source file है जिसे scripts/artifacts folder में जोड़ा जाना चाहिए, जिसे हर बार ALEAPP चलने पर गतिशील रूप से लोड किया जाएगा।

Plugin source file में module की शुरुआत में ही __artifacts_v2__ नाम का एक dictionary होना चाहिए, जो उन artifacts को परिभाषित करता है जिन्हें plugin process करता है। __artifacts_v2__ dictionary में keys artifact(s) के IDs होने चाहिए जो ALEAPP के भीतर अद्वितीय होने चाहिए। Values में निम्नलिखित keys वाली dictionaries होनी चाहिए:

  • name: artifact का नाम एक string के रूप में।
  • description: artifact का विवरण एक string के रूप में।
  • author: plugin के लेखक एक string के रूप में।
  • version: artifact का संस्करण एक string के रूप में।
  • date: artifact के अंतिम अपडेट की तारीख एक string के रूप में।
  • requirements: artifact को process करने के लिए कोई भी आवश्यकताएँ एक string के रूप में।
  • category: artifact की श्रेणी एक string के रूप में।
  • notes: कोई भी अतिरिक्त नोट्स एक string के रूप में।
  • paths: strings का एक tuple जिसमें glob search patterns होते हैं जो उस data के path से मेल खाते हैं जिसकी plugin को artifact के लिए अपेक्षा होती है।
  • function: उस function का नाम जो artifact की processing के लिए entry point है, एक string के रूप में।

उदाहरण के लिए:

__artifacts_v2__ = {
    "cool_artifact_1": {
        "name": "Cool Artifact 1",
        "description": "Extracts cool data from database files",
        "author": "@username",
        "version": "0.1",
        "date": "2022-10-25",
        "requirements": "none",
        "category": "Really cool artifacts",
        "notes": "",
        "paths": ('*/com.android.cooldata/databases/database*.db',),
        "function": "get_cool_data1"
    },
    "cool_artifact_2": {
        "name": "Cool Artifact 2",
        "description": "Extracts cool data from XML files",
        "author": "@username",
        "version": "0.1",
        "date": "2022-10-25",
        "requirements": "none",
        "category": "Really cool artifacts",
        "notes": "",
        "paths": ('*/com.android.cooldata/files/cool.xml',),
        "function": "get_cool_data2"
    }
}

__artifacts__ dictionary में entry points के रूप में संदर्भित functions को निम्नलिखित arguments लेने चाहिए:

  • उन मिली फ़ाइलों का एक iterable जिन्हें process किया जाना है (strings के रूप में)
  • ALEAPP के output folder का path (एक string के रूप में)
  • वह seeker (FileSeekerBase प्रकार का) जिसने फ़ाइलें ढूँढीं
  • एक Boolean मान जो बताता है कि plugin से text wrap करने की अपेक्षा है या नहीं

उदाहरण के लिए:

def get_cool_data1(files_found, report_folder, seeker, wrap_text):
    pass  # do processing here

Plugins से आम तौर पर ALEAPP के HTML output format, TSV में output देने, और वैकल्पिक रूप से timeline में records submit करने की अपेक्षा की जाती है। यह output उत्पन्न करने के लिए functions artifact_report और ilapfuncs modules में पाए जा सकते हैं। उच्च स्तर पर, एक उदाहरण कुछ इस तरह दिख सकता है:

__artifacts_v2__ = {
    "cool_artifact_1": {
        "name": "Cool Artifact 1",
        "description": "Extracts cool data from database files",
        "author": "@username",  # Replace with the actual author's username or name
        "version": "0.1",  # Version number
        "date": "2022-10-25",  # Date of the latest version
        "requirements": "none",
        "category": "Really cool artifacts",
        "notes": "",
        "paths": ('*/com.android.cooldata/databases/database*.db',),
        "function": "get_cool_data1"
    }
}

import datetime
from scripts.artifact_report import ArtifactHtmlReport
import scripts.ilapfuncs

def get_cool_data1(files_found, report_folder, seeker, wrap_text):
    # let's pretend we actually got this data from somewhere:
    rows = [
     (datetime.datetime.now(), "Cool data col 1, value 1", "Cool data col 1, value 2", "Cool data col 1, value 3"),
     (datetime.datetime.now(), "Cool data col 2, value 1", "Cool data col 2, value 2", "Cool data col 2, value 3"),
    ]

    headers = ["Timestamp", "Data 1", "Data 2", "Data 3"]

    # HTML output:
    report = ArtifactHtmlReport("Cool stuff")
    report_name = "Cool DFIR Data"
    report.start_artifact_report(report_folder, report_name)
    report.add_script()
    report.write_artifact_data_table(headers, rows, files_found[0])  # assuming only the first file was processed
    report.end_artifact_report()

    # TSV output:
    scripts.ilapfuncs.tsv(report_folder, headers, rows, report_name, files_found[0])  # assuming first file only

    # Timeline:
    scripts.ilapfuncs.timeline(report_folder, report_name, rows, headers)

आपके PR के लिए Test data और sample_data

एक artifact को जोड़ने या बदलने वाले PR की समीक्षा और merge सबसे आसान तब होती है जब वह दो चीज़ों के साथ आता है: एक वास्तविक extraction से काटा गया छोटा test fixture, और sample_data values जो रिकॉर्ड करती हैं कि module ने क्या उत्पन्न किया। Scripts दोनों उत्पन्न करते हैं। यहाँ पूरा प्रवाह है।

किसी भी चीज़ से पहले एक नियम: आप यहाँ जो भी commit करते हैं वह सार्वजनिक हो जाता है। केवल वही data उपयोग करें जिसे साझा करने की आपको अनुमति है, जैसे कोई test device जिसे आपने स्वयं भरा हो, कोई सार्वजनिक research image, या कोई फ़ाइल जिसे आपने हाथ से sanitize किया हो। कभी भी casework नहीं।

श्रेणियाँ