Triage File Changes
Classify changes reported by the integrity-monitor lab in a simulated incident.
Classify changes reported by the integrity-monitor lab in a simulated incident.
Prepare 20m · Build 110m · Verify 30m · Document 20m
Work only inside the folder created by Smartphone-Academy.py prepare change-triage. Use the supplied samples or systems you personally administer.
Prepare the Termux workspace
Open Termux in the Academy root and prepare this lab with the local companion. It creates safe samples, notes and evidence files under your Termux account.
python Smartphone-Academy.py prepare change-triageNo root. Use the supplied files and keep the workspace under $HOME.Practical mission
- Compare the incident snapshot with the trusted baseline
- Attribute expected changes to documented maintenance
- Prioritize unexplained executable and configuration changes
- Preserve uncertain items for further review instead of deleting them
A change register with expected, suspicious and unresolved categories.
Quality gate
Analyst reflection
Which result from “Preserve uncertain items for further review instead of deleting them” would need more evidence before it could support an operational decision?
After checking the evidence, run python Smartphone-Academy.py complete change-triage. Progress is stored locally in the Termux home directory.