Adds detection for disabled security packages in Android

This commit is contained in:
tek 2022-09-26 12:09:05 +02:00
parent e1d1b6c5de
commit d706cc7668

View File

@ -66,6 +66,13 @@ ROOT_PACKAGES = [
"com.kingouser.com",
"com.topjohnwu.magisk",
]
SECURITY_PACKAGES = [
"com.policydm",
"com.samsung.android.app.omcagent",
"com.samsung.android.securitylogagent",
"com.sec.android.soagent",
"com.wssyncmldm",
]
class Packages(AndroidExtraction):
@ -122,6 +129,12 @@ class Packages(AndroidExtraction):
self.detected.append(result)
continue
if result["package_name"] in SECURITY_PACKAGES and result["disabled"]:
self.log.warning("Found a security package disabled: \"%s\"",
result["package_name"])
self.detected.append(result)
continue
if not self.indicators:
continue