LGDroid

LGDroid is a blue team lab that falls under the Endpoint Forensics category and will cover the following subjects: DB Browser for SQLite, Epoch Converter, ssim-calculator, Defense Evasion, Credential Access.

Learning Objectives

Analyze Android disk images using SQLite, Python, and log analysis to reconstruct user activity and extract key forensic artifacts.

Categories: Endpoint Forensics.

MITRE ATT&CK Tactics: Defense Evasion, Credential Access.

Tools: DB Browser for SQLite, Epoch Converter, ssim-calculator.

Difficulty: medium.