OBJECTIVE

Analyze the supplied synthetic incident without altering the source evidence.

TIME PLAN

Prepare 30m · Build 150m · Verify 40m · Document 20m

Working boundary

Work only inside the folder created by Smartphone-Academy.py prepare capstone-incident. Use the supplied samples or systems you personally administer.

Prepare the Termux workspace

Open Termux in the Academy root and prepare this lab with the local companion. It creates safe samples, notes and evidence files under your Termux account.

Android + Termuxpython Smartphone-Academy.py prepare capstone-incidentNo root. Use the supplied files and keep the workspace under $HOME.

Practical mission

  1. Verify every evidence file before analysis
  2. Correlate authentication, network and file-change records
  3. Test at least two competing explanations
  4. Recommend proportionate containment while preserving evidence
EVIDENCE TO PRODUCE

An investigation package with timeline, findings, confidence and containment advice.

Quality gate

The deliverable states a clear scope and date for Capstone: Investigate the Incident.
A second learner can reproduce the commands and paths.
Original samples remain unchanged and verifiable.
Limitations are recorded beside the conclusions.

Analyst reflection

Which result from “Recommend proportionate containment while preserving evidence” would need more evidence before it could support an operational decision?

Complete in Termux

After checking the evidence, run python Smartphone-Academy.py complete capstone-incident. Progress is stored locally in the Termux home directory.

16 · Capstone Missions

Continue learning

Back to Smartphone Academy