LABORATORY FORENSICS PLANNED WORKSTATION · AGDM SOFT

AGDM Root Lab

Planned desktop forensic analysis workstation for deep offline device inspection, extraction artifact evaluation, and low-level system integrity auditing.

Status: Planned / Under Development
AGDM Root Lab is a concept and engineering project currently in the planning stage. In accordance with project milestones, implementation will proceed following the production release of AGDM Root Checker Release 1. This application is not released and is not available for download or purchase.

Purpose and Architecture

While AGDM Root Checker operates directly on Android devices as an unprivileged mobile application, certain forensic investigations require analyzing complete physical partition dumps, raw filesystem structures, or extraction artifacts that cannot be examined from within the standard Android application sandbox.

AGDM Root Lab is designed as a standalone desktop laboratory workstation (macOS, Linux, Windows) that processes device extractions and physical dumps in an isolated, controlled forensic environment without modifying evidence.

Planned Technical Capabilities

Offline Partition Image Analysis

Parser and evaluator for physical partition images, verifying filesystem integrity, mount structures, and detecting unauthorized persistent binaries across system, vendor, and product partitions.

Cryptographic Binary Baseline Diffing

Automated comparison of system executables and shared libraries against verified vendor release baselines and cryptographic hash registries to surface binary tampering or malicious replacements.

Forensic Indicator Matching (IOC)

Multi-source offline cross-referencing of file signatures, daemon names, cron jobs, network artifacts, and persistent scripts against curated public threat indicator databases (including stalkerware and commercial spyware signatures).

Attestation & Keystore Verification

Detailed technical review of hardware keystore records, bootloader state tokens, and attestation certificate chains obtained from compliant device extractions.

Honest Limitations and Forensic Boundaries

  • Physical Extraction Required: AGDM Root Lab is an offline analysis workstation tool. It does not perform wireless intrusion or remote exploitation; it requires pre-acquired extraction images or authorized physical lab connectivity.
  • Hardware Encryption Enclaves: Modern Android devices enforce hardware-backed file-based encryption (FBE). The laboratory tool cannot decrypt encrypted partitions without valid device credentials and hardware security module access.
  • No Absolute Zero-Day Guarantee: No security tool can guarantee detection of an uncharacterized, previously undocumented hardware-level or kernel-level zero-day implant. Forensic conclusions are strictly evidence-based.
  • Development Status: No desktop binary, beta program, or commercial license currently exists. Implementation is planned following the production stabilization of AGDM Root Checker Release 1.

Looking for mobile on-device security verification?

AGDM Root Checker for Android provides on-device diagnostics for root status, bootloader state, SELinux enforcement, app traffic, and Google Play Integrity verification.

Return to AGDM Root Checker →