Operator On The Wire
Join
← Back to Knowledge Base
BLUE TEAM / DFI / ARTEFACT / ANDROID

media

User-accessible shared storage — holds user files, downloads, media, and app external data (no sandbox, accessible by many apps).

/data/media


ArtifactWhat it containsTypical Use Case
0/Download/Downloaded files (APKs, docs, payloads)Did user download malware or payloads?
0/DCIM/Camera photos/videosTimeline via EXIF, user activity
0/Pictures/Screenshots/imagesEvidence of activity, phishing screens
0/Movies/Video filesUser activity, possible exfil
0/Music/Audio filesRarely DFIR-critical
0/Documents/User documentsData exfiltration targets
0/Android/data/<pkg>/App external storageMalware configs, logs, dropped files
0/Android/media/<pkg>/Scoped storage mediaApp-specific media artifacts
0/Android/obb/App expansion filesLarge app assets (less DFIR value)
0/WhatsApp/WhatsApp media/backupsChat artifacts, media exfil
0/Telegram/Telegram media/cacheMessaging artifacts
0/DCIM/.thumbnails/Cached image previewsRecover deleted images
0/ (root)Misc user filesGeneral staging / loose artifacts