Android ADB Backup
| Kayvon2008  (Talk | contribs)  (→Header) | Kayvon2008  (Talk | contribs)  | ||
| Line 5: | Line 5: | ||
| |extensions={{ext|ab}} | |extensions={{ext|ab}} | ||
| }} | }} | ||
| − | Android backups (.ab) are backups made by Android Debug Bridge (ADB). They are the preferred way of backing up an unrooted stock android device. (Manufacturers and/or carriers may provide their own backup tools). They can be encrypted (with AES) or unencrypted. They can be created via ADB backup and restored via ADB restore. Android backups themselves are [[Tape Archive|.TAR]] files with a different header and no footer. Unfortunately, there are no graphical tools yet (other than [https://www.mobiledit.com/forensic-express/details MobilEDIT Forensics], which  | + | Android backups (.ab) are backups made by Android Debug Bridge (ADB). They are the preferred way of backing up an unrooted stock android device. (Manufacturers and/or carriers may provide their own backup tools). They can be encrypted (with AES) or unencrypted. They can be created via ADB backup and restored via ADB restore. Android backups themselves are [[Tape Archive|.TAR]] files with a different header and no footer. Unfortunately, there are no graphical tools yet (other than mobile forensic tools like Cellebrite Physical Analyzer, Oxygen Detective, Magnet AXIOM, and [https://www.mobiledit.com/forensic-express/details MobilEDIT Forensics], which are all payed) that can extract them, and they require the command line. It is compressed via the DEFLATE method.   | 
| ===Header=== | ===Header=== | ||
| <pre style="white-space: pre-wrap;   | <pre style="white-space: pre-wrap;   | ||
Revision as of 23:28, 12 January 2022
Android backups (.ab) are backups made by Android Debug Bridge (ADB). They are the preferred way of backing up an unrooted stock android device. (Manufacturers and/or carriers may provide their own backup tools). They can be encrypted (with AES) or unencrypted. They can be created via ADB backup and restored via ADB restore. Android backups themselves are .TAR files with a different header and no footer. Unfortunately, there are no graphical tools yet (other than mobile forensic tools like Cellebrite Physical Analyzer, Oxygen Detective, Magnet AXIOM, and MobilEDIT Forensics, which are all payed) that can extract them, and they require the command line. It is compressed via the DEFLATE method.
| Contents | 
Header
ANDROID BACKUP 1 1 none
Extraction
It is extremely hard to extract them, and for the best available tool you need the command line (and knowledge how to use it) and Java installed. Droid Explorer claims to be able to extract ADB backups, but there is no prompt of extraction and is a pain to install. Other command line tricks may also convert it to an easily extractable TAR.
Structucture
 /app  Contains all app data 
 /app/(package id)  Contains app data 
 /app/(package id)/a  Contains app APK (app file) (if requested) 
 /app/(package id)/f  Contains app files 
 /app/(package id)/db  Contains app SQLite databases (open them here) 
 /app/(package id)/ef  Contains app shared data (storage/emulated/0/Android/data/(package id) ) 
 /app/(package id)/sp  Contains app shared prefrences (app settings), usually xml files 
 /app/(package id)/r  Contains app resources like webview data (like cookies) and texture cache
 /shared  Contains shared files (/storage/emulated/0/) 
Flags
 -all   Backups all compatible apps 
 -f   Chooses the path and name for the file 
(package id)   Backs up the stated package(s) if compatible. 
-system   backups system apps if -all or a system package Id is stated. 
-nosystem   does not back up system data. 
-apk   Backs up the .apk of the app(s) 
-noapk   does not back up apk files 
-obb   Backs up .obb (app extention) files 
-noobb   Does not back up .obb files 
-shared   Backs up all shared storage (/storage/emulated/0/), including SD cards and USB OTGs, so it is recommended to eject and disconnect any external storage unless you want to back up that. 
-noshared   does not back up shared storage. 
-includekeyvalue  or -keyvalue Backs up apps that support Key Value backups. Key value backups were added in Android 2.2 “Froyo”, and this flag was added in Android 8.0 “Oreo” (Even since Developer Preview 1) 
-nokeyvalue Does not back up key value apps.
Discontinuation
Android backups are being discontinued and fully replaced by Google Drive backups. Google drive backups cannot be downloaded, and there is a 25 MB per-app limit. You need a network sniffer to log upload traffic to capture these. The warning was there since the SDK of Android 10 “Queen Cake”, however, backups themselves weren’t changed. In Android 12 “Snow Cone”, apps with Snow Cone’s API level with backup flag set to true and a Snow Cone device will back up to (dumb) Google Drive instead.
Example
cats.ab: Extracted on a Galaxy Tab A with Android Nougat, Contains Android easter egg (com.android.egg) cats and render data.

