Repository navigation
Expand file tree
/
Copy pathphase3_apps_v2.py
More file actions
120 lines (91 loc) · 3.87 KB
/
Copy pathphase3_apps_v2.py
File metadata and controls
120 lines (91 loc) · 3.87 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
#!/usr/bin/env python3
"""
Phase 3 - Installed Apps
Extract all installed applications
"""
import sys
from pathlib import Path
sys.path.insert(0, str(Path(__file__).parent))
from config import BASE, get_aleapp_tsv_dir, PhaseOutput
from datetime import datetime
import csv
def extract_installed_apps():
"""Extract installed apps list."""
output = PhaseOutput(3, "installed_apps")
tsv_dir = get_aleapp_tsv_dir()
if not tsv_dir:
output.set_summary("status", "ERROR: ALEAPP TSV directory not found")
return output
# Try different known filenames
apps_file = None
for candidate in ["Installed Apps.tsv", "Installed Apps Vending 0.tsv", "Installed Apps Vending.tsv"]:
p = tsv_dir / candidate
if p.exists():
apps_file = p
break
if not apps_file:
output.set_summary("status", "ERROR: Installed Apps.tsv not found")
return output
output.add_source(apps_file, "ALEAPP Installed Apps TSV")
# Parse apps
user_apps = []
system_apps = []
red_flags = []
try:
with open(apps_file, 'r', errors='ignore') as f:
reader = csv.DictReader(f, delimiter='\t')
for row in reader:
package = row.get('Package Name', 'Unknown')
version = row.get('Version', '')
installer = row.get('Installer Package', '')
# Categorize
is_system = installer in ['', 'com.android.vending', '(system/unknown)', 'null'] and package.startswith('com.android.')
is_user = installer in ['com.android.vending', 'com.google.android.packageinstaller'] or 'com.samsung' not in package
# Check for suspicious apps
suspicious_keywords = ['vpn', 'spy', 'track', 'capture', 'hide', 'lock', 'vault', 'encrypto', 'signal', 'tor', 'orbot']
is_suspicious = any(kw in package.lower() for kw in suspicious_keywords)
app_info = {
"package": package,
"version": version,
"installer": installer,
}
if is_user and not is_system:
user_apps.append(app_info)
else:
system_apps.append(app_info)
if is_suspicious:
red_flags.append(package)
output.add_finding(
category="suspicious_app",
key=package,
value={"installer": installer},
context=f"Suspicious keyword match"
)
output.set_summary("total_apps", len(user_apps) + len(system_apps))
output.set_summary("user_apps", len(user_apps))
output.set_summary("system_apps", len(system_apps))
output.set_summary("red_flag_apps", len(red_flags))
output.set_summary("status", "SUCCESS")
except Exception as e:
output.set_summary("status", f"ERROR: {str(e)}")
# Add timeline
output.add_timeline_event(
timestamp=datetime.now().strftime("%Y-%m-%d"),
event_type="apps_extracted",
description=f"{output.data['summary'].get('total_apps', 0)} apps found",
source="Phase 3"
)
return output
def main():
print("=" * 60)
print("Phase 3: Installed Apps")
print("=" * 60)
output = extract_installed_apps()
paths = output.write()
for path, type_ in paths.items():
print(f"[OUTPUT] {path}")
print(f"\nStatus: {output.data['summary'].get('status', 'Unknown')}")
print(f"Total Apps: {output.data['summary'].get('total_apps', 0)}")
print(f"Red Flags: {output.data['summary'].get('red_flag_apps', 0)}")
if __name__ == "__main__":
main()