Operator On The Wire
Join
← Back to Knowledge Base
BLUE TEAM / DFI / ARTEFACT / ANDROID

data

Per-app private sandbox storing each app’s internal data (configs, databases, files, tokens) isolated by package.

/data/data


Artifact / PathWhat it containsTypical Use Case
/data/data/<pkg>/App private directoryStart point for any app investigation
shared_prefs/*.xmlApp preferences, flags, tokens, configsFind URLs, tokens, feature flags
databases/*.dbSQLite DBs (messages, logs, cache)Extract chats, logs, exfil data
files/App-created filesPayloads, configs, dropped files
cache/Temporary cached dataRecover deleted / transient data
code_cache/Compiled/intermediate codeRare but useful for dynamic behavior
lib/Native libraries (.so)Reverse C2 / crypto in IDA
no_backup/Data excluded from backupsMalware persistence configs
app_webview/WebView storage (cookies, localStorage)Tokens, session hijacking
app_webview/CookiesSQLite cookie DBReuse sessions (like your Proton case)
app_webview/Local Storage/Web local storageAPI responses, identifiers
databases/webview.dbWebView DBHistory, cached data
shared_prefs/*firebase*Firebase configs/tokensIdentify cloud endpoints
shared_prefs/*auth*Auth/session dataAPI replay / account access
shared_prefs/*config*App configurationMay include hidden endpoints
files/*.json / *.datCustom config filesDecode C2 / settings
files/Download/Downloaded contentSecondary malware
files/logs/App logsTimeline reconstruction
databases/*.wal / *.shmSQLite write-ahead logsRecover deleted/unsaved data