Mission

Combine supplied symptoms, app metadata, permissions and network observations into a defensive response record.

Required work

  1. Preserve and hash the supplied evidence
  2. Build a chronological incident timeline
  3. Prioritize containment actions by impact
  4. Write recovery and account-protection steps

Evidence to produce

A casefile with scope, timeline, containment, evidence, limitations and recovery steps.

Quality checks

The result must identify its source data, separate observation from assumption, preserve supplied originals, and explain any limitation or uncertain conclusion.

24 · Android Security and Privacy Labs

Continue learning

Back to Smartphone Academy