OBJECTIVE

Document where an APK came from, what package it claims to be and whether its hashes and signer remain consistent.

TIME PLAN

Prepare 20m · Build 110m · Verify 30m · Document 20m

Working boundary

Work only inside the folder created by Smartphone-Academy.py prepare apk-provenance-report. Use the supplied samples, your own phone, or systems you are explicitly authorized to administer.

Prepare the Termux workspace

Open Termux in the Academy root and prepare this lab with the local companion. It creates safe samples, notes and evidence files under your Termux account.

Android + Termuxpython Smartphone-Academy.py prepare apk-provenance-reportNo root. Keep the workspace under $HOME and avoid personal identifiers in evidence.

Practical mission

  1. Use only an APK you are legally allowed to inspect
  2. Record download source, date, filename, package name and version
  3. Calculate cryptographic hashes and capture available signer information
  4. Compare evidence with the expected publisher and state unresolved risks
EVIDENCE TO PRODUCE

A provenance report with source, package identity, hashes, signer evidence and decision.

Quality gate

The scope, date and tested device or workspace are clearly identified.
Every conclusion points to a command result, setting, source or measured observation.
Another learner can repeat the procedure without guessing hidden steps.
Limitations, uncertainty and any skipped checks are recorded honestly.

Analyst reflection

Which result from “Compare evidence with the expected publisher and state unresolved risks” needs stronger evidence before it can support a real decision?

Complete in Termux

After checking the evidence, run python Smartphone-Academy.py complete apk-provenance-report. Progress is stored locally in the Termux home directory.

Extended Smartphone Practice

Continue learning

Back to Smartphone Academy