OBJECTIVE

Capture two network snapshots and distinguish expected changes from findings that need investigation.

TIME PLAN

Prepare 20m · Build 110m · Verify 30m · Document 20m

Working boundary

Work only inside the folder created by Smartphone-Academy.py prepare network-change-diff. Use the supplied samples, your own phone, or systems you are explicitly authorized to administer.

Prepare the Termux workspace

Open Termux in the Academy root and prepare this lab with the local companion. It creates safe samples, notes and evidence files under your Termux account.

Android + Termuxpython Smartphone-Academy.py prepare network-change-diffNo root. Keep the workspace under $HOME and avoid personal identifiers in evidence.

Practical mission

  1. Capture a baseline of interfaces, routes, DNS and listening sockets
  2. Create a second snapshot after one controlled network change
  3. Normalize volatile fields before comparing the snapshots
  4. Classify differences and document the evidence needed for follow-up
EVIDENCE TO PRODUCE

A normalized diff report with expected, suspicious and unresolved changes.

Quality gate

The scope, date and tested device or workspace are clearly identified.
Every conclusion points to a command result, setting, source or measured observation.
Another learner can repeat the procedure without guessing hidden steps.
Limitations, uncertainty and any skipped checks are recorded honestly.

Analyst reflection

Which result from “Classify differences and document the evidence needed for follow-up” needs stronger evidence before it can support a real decision?

Complete in Termux

After checking the evidence, run python Smartphone-Academy.py complete network-change-diff. Progress is stored locally in the Termux home directory.

Extended Smartphone Practice

Continue learning

Back to Smartphone Academy