
ALEAPP v2026.3.3
Android लॉग्स इवेंट्स और Protobuf पार्सर

Android Logs Events And Protobuf Parser
अगर आप योगदान देना चाहते हैं तो मुझसे यहाँ संपर्क करें: https://abrignoni.github.io
ब्लॉग पोस्ट यहाँ: https://leapps.org/blog
आवश्यकताएँ
Python 3.10 या उससे ऊपर
निर्भरताएँ
आपके python environment के लिए निर्भरताएँ requirements.txt में सूचीबद्ध हैं। इन्हें नीचे दिए गए कमांड का उपयोग करके इंस्टॉल करें। सुनिश्चित करें
कि py वाला हिस्सा आपके environment के लिए सही है, जैसे py, python, या python3, आदि।
py -m pip install -r requirements.txt
या
pip3 install -r requirements.txt
Linux पर चलाने के लिए, आपको tkinter को अलग से इंस्टॉल करना होगा, इस तरह:
sudo apt-get install python3-tk
Executable में कंपाइल करें
इसे executable में कंपाइल करने के लिए ताकि आप इसे बिना python इंस्टॉल किए किसी सिस्टम पर चला सकें।
Windows OS
aleapp.exe बनाने के लिए, चलाएँ:
pyinstaller scripts\pyinstaller\aleapp.spec
aleappGUI.exe बनाने के लिए, चलाएँ:
pyinstaller scripts\pyinstaller\aleappGUI.spec
macOS
aleapp बनाने के लिए, चलाएँ:
pyinstaller scripts/pyinstaller/aleapp_macOS.spec
aleappGUI.app बनाने के लिए, चलाएँ:
pyinstaller scripts/pyinstaller/aleappGUI_macOS.spec
Linux
aleapp बनाने के लिए, चलाएँ:
pyinstaller scripts/pyinstaller/aleapp_Linux.spec
aleappGUI बनाने के लिए, चलाएँ:
pyinstaller scripts/pyinstaller/aleappGUI_Linux.spec
उपयोग
CLI
$ python aleapp.py -t <zip | tar | fs | gz | raw> -i <path_to_extraction> -o <path_for_report_output>
raw एक disk image (.img, .dd, .bin, या split set का कोई भी क्रमांकित .001 सेगमेंट),
या एक EnCase/EWF .E01 acquisition और उसके साथ के सेगमेंट को, यथास्थान पढ़ता है: न mounting और न ही administrator अधिकार। इसके NTFS, FAT32, exFAT, ext2/3/4,
F2FS, HFS+, APFS, QNX6, QNX4, ETFS, EFS, SquashFS, JFFS2, UBI/UBIFS, YAFFS और QNX IFS
volumes को सीधे खोजा जाता है, और
image से केवल वही फ़ाइलें पढ़ी जाती हैं जिनकी किसी artifact को आवश्यकता होती है। GUI उन extensions के लिए
स्वयं raw चुनता है। देखें admin/docs/raw_image_input.md।
tar एक xz-compressed tar (.tar.xz) भी पढ़ता है, और GUI उस
extension के लिए tar चुनता है। एक compressed tar, जिसमें .tar.gz भी शामिल है, किसी भी फ़ाइल को पढ़ने से पहले
report folder में एक बार decompress किया जाता है, इसलिए उस run को वहाँ uncompressed tar के लिए खाली जगह चाहिए। यह
copy run समाप्त होने पर हटा दी जाती है, और run log बताता है कि उस step में कितना समय लगा।
GUI
$ python aleappGUI.py
सहायता
$ python aleapp.py --help
Artifact plugins में योगदान
प्रत्येक plugin एक Python source file है जिसे scripts/artifacts folder में जोड़ा जाना चाहिए, जिसे हर बार ALEAPP चलने पर गतिशील रूप से लोड किया जाएगा।
Plugin source file में module की शुरुआत में ही __artifacts_v2__ नाम का एक dictionary होना चाहिए, जो उन artifacts को परिभाषित करता है जिन्हें plugin process करता है। __artifacts_v2__ dictionary में keys artifact(s) के IDs होने चाहिए जो ALEAPP के भीतर अद्वितीय होने चाहिए। Values में निम्नलिखित keys वाली dictionaries होनी चाहिए:
name: artifact का नाम एक string के रूप में।description: artifact का विवरण एक string के रूप में।author: plugin के लेखक एक string के रूप में।version: artifact का संस्करण एक string के रूप में।date: artifact के अंतिम अपडेट की तारीख एक string के रूप में।requirements: artifact को process करने के लिए कोई भी आवश्यकताएँ एक string के रूप में।category: artifact की श्रेणी एक string के रूप में।notes: कोई भी अतिरिक्त नोट्स एक string के रूप में।paths: strings का एक tuple जिसमें glob search patterns होते हैं जो उस data के path से मेल खाते हैं जिसकी plugin को artifact के लिए अपेक्षा होती है।function: उस function का नाम जो artifact की processing के लिए entry point है, एक string के रूप में।
उदाहरण के लिए:
__artifacts_v2__ = {
"cool_artifact_1": {
"name": "Cool Artifact 1",
"description": "Extracts cool data from database files",
"author": "@username",
"version": "0.1",
"date": "2022-10-25",
"requirements": "none",
"category": "Really cool artifacts",
"notes": "",
"paths": ('*/com.android.cooldata/databases/database*.db',),
"function": "get_cool_data1"
},
"cool_artifact_2": {
"name": "Cool Artifact 2",
"description": "Extracts cool data from XML files",
"author": "@username",
"version": "0.1",
"date": "2022-10-25",
"requirements": "none",
"category": "Really cool artifacts",
"notes": "",
"paths": ('*/com.android.cooldata/files/cool.xml',),
"function": "get_cool_data2"
}
}
__artifacts__ dictionary में entry points के रूप में संदर्भित functions को निम्नलिखित arguments लेने चाहिए:
- उन मिली फ़ाइलों का एक iterable जिन्हें process किया जाना है (strings के रूप में)
- ALEAPP के output folder का path (एक string के रूप में)
- वह seeker (FileSeekerBase प्रकार का) जिसने फ़ाइलें ढूँढीं
- एक Boolean मान जो बताता है कि plugin से text wrap करने की अपेक्षा है या नहीं
उदाहरण के लिए:
def get_cool_data1(files_found, report_folder, seeker, wrap_text):
pass # do processing here
Plugins से आम तौर पर ALEAPP के HTML output format, TSV में output देने, और वैकल्पिक रूप से
timeline में records submit करने की अपेक्षा की जाती है। यह output उत्पन्न करने के लिए functions artifact_report और ilapfuncs modules में पाए जा सकते हैं।
उच्च स्तर पर, एक उदाहरण कुछ इस तरह दिख सकता है:
__artifacts_v2__ = {
"cool_artifact_1": {
"name": "Cool Artifact 1",
"description": "Extracts cool data from database files",
"author": "@username", # Replace with the actual author's username or name
"version": "0.1", # Version number
"date": "2022-10-25", # Date of the latest version
"requirements": "none",
"category": "Really cool artifacts",
"notes": "",
"paths": ('*/com.android.cooldata/databases/database*.db',),
"function": "get_cool_data1"
}
}
import datetime
from scripts.artifact_report import ArtifactHtmlReport
import scripts.ilapfuncs
def get_cool_data1(files_found, report_folder, seeker, wrap_text):
# let's pretend we actually got this data from somewhere:
rows = [
(datetime.datetime.now(), "Cool data col 1, value 1", "Cool data col 1, value 2", "Cool data col 1, value 3"),
(datetime.datetime.now(), "Cool data col 2, value 1", "Cool data col 2, value 2", "Cool data col 2, value 3"),
]
headers = ["Timestamp", "Data 1", "Data 2", "Data 3"]
# HTML output:
report = ArtifactHtmlReport("Cool stuff")
report_name = "Cool DFIR Data"
report.start_artifact_report(report_folder, report_name)
report.add_script()
report.write_artifact_data_table(headers, rows, files_found[0]) # assuming only the first file was processed
report.end_artifact_report()
# TSV output:
scripts.ilapfuncs.tsv(report_folder, headers, rows, report_name, files_found[0]) # assuming first file only
# Timeline:
scripts.ilapfuncs.timeline(report_folder, report_name, rows, headers)
आपके PR के लिए Test data और sample_data
एक artifact को जोड़ने या बदलने वाले PR की समीक्षा और merge सबसे आसान तब होती है जब वह
दो चीज़ों के साथ आता है: एक वास्तविक extraction से काटा गया छोटा test fixture, और sample_data values जो
रिकॉर्ड करती हैं कि module ने क्या उत्पन्न किया। Scripts दोनों उत्पन्न करते हैं। यहाँ पूरा प्रवाह है।
किसी भी चीज़ से पहले एक नियम: आप यहाँ जो भी commit करते हैं वह सार्वजनिक हो जाता है। केवल वही data उपयोग करें जिसे साझा करने की आपको अनुमति है, जैसे कोई test device जिसे आपने स्वयं भरा हो, कोई सार्वजनिक research image, या कोई फ़ाइल जिसे आपने हाथ से sanitize किया हो। कभी भी casework नहीं।