v0.5.0-beta β’ Updated 9 August 2026 Β· Exampledefcon edition
π Example Page
Sample layout matching the live Android analyzer (v0.5.0-beta Β· 9 August 2026): 40 Sigma rules from /rules/ (amnesty, android including android/CVE, ios/darksword, spyware), timeline + Sigma matches, privacy parser (location providers, last availability, OpenStreetMap links), packages installed by user, parser cards, and full JSON export. See bugreport-status for the rule catalog. All values are fictional.
β
Analysis complete
β
π Pwned Results Detection
Rules
Matches
π Analysis Results
Analyzed on
π± Device Information
Manufacturer
-
Model
-
Android Version
-
Build ID
-
Kernel Version
-
π Battery Status
Level
-
Health
-
Temperature
-
Voltage
-
Current
-
Battery level over time
Recent history samples
Kernel hardware samples
π
Fileββ
SHA-256β
π System Statistics
Apps & packages
Processes
-
Unique Packages
-
Apps in battery stats
-
Package detail records
-
Install history entries
-
Network & connectivity
Network interfaces
-
Network statistics rows
-
Socket entries
-
Bluetooth devices
-
USB devices (log)
-
Power history events
-
Security & detection
Sigma rules loaded
-
Sigma matches
-
Crashes & stability
ANR files
-
Crash tombstones
-
ποΈ Timeline
Parser-based Plaso/Timesketch-style rows when available, plus Sigma matches. Colors by parser or category; click an event for JSON.
π² Packages installed by user
0
Same non-system rules as below (flags/paths), plus installation metadata: installer, install times, install logs, or per-user install fields. Packages with none of these are omitted here.
π
π± Package Details
0
π
APK downgrades (battery daily)
0
Version decreases and vers=0 uninstalls from dumpsys batterystats daily Update lines. Forensic tools sometimes leave these trails.
π
π¦ Deleted Packages
0
Packages that were installed or uninstalled. Packages not found in the "Package Details" section have been deleted.
π
π App Battery Usage
0
π
Package Name
UID
CPU Time
Network (RX/TX)
Wakelock Time
Job Time
FG service
π Network Sockets
0
π
Protocol
Local Address
Local Port
Remote Address
Remote Port
State
UID
π Network Interfaces
0
π
π Network Statistics
0
π
πΆ Bluetooth
0
π
π USB
0
π
π VPN parser
π Authentication parser
0
Keystore unlock and PowerManager wakeUp events from SYSTEM LOG.
βοΈ Running Processes
0
π
PID
Name
User
CPU%
Memory
ANR / Crash
ANR traces and native tombstones from the bugreport β expandable incidents with process, signal, and stacks.
π
No crash content matches the filter.
β‘ Power History
0
π§ Memory parser
π Device policy parser
π§ ADB parser
π‘οΈ Privacy parser
π¦ Parser outputs (complete)
One block per parser: status, duration, and full JSON (same data the timeline and cards are built from).