Build a Suspicious-App Casefile
Combine supplied symptoms, app metadata, permissions and network observations into a defensive response record.
Mission
Combine supplied symptoms, app metadata, permissions and network observations into a defensive response record.
Required work
- Preserve and hash the supplied evidence
- Build a chronological incident timeline
- Prioritize containment actions by impact
- Write recovery and account-protection steps
Evidence to produce
A casefile with scope, timeline, containment, evidence, limitations and recovery steps.
Quality checks
The result must identify its source data, separate observation from assumption, preserve supplied originals, and explain any limitation or uncertain conclusion.