Construct an Incident Timeline
Merge synthetic file, authentication and network events into a defensible sequence.
Merge synthetic file, authentication and network events into a defensible sequence.
Prepare 20m · Build 110m · Verify 30m · Document 20m
Work only inside the folder created by Smartphone-Academy.py prepare incident-timeline. Use the supplied samples or systems you personally administer.
Prepare the Termux workspace
Open Termux in the Academy root and prepare this lab with the local companion. It creates safe samples, notes and evidence files under your Termux account.
python Smartphone-Academy.py prepare incident-timelineNo root. Use the supplied files and keep the workspace under $HOME.Practical mission
- Normalize all source timestamps before sorting
- Keep original source and record identifiers in every row
- Mark inferred ordering when timestamps collide
- Write a concise narrative that does not exceed the evidence
A timestamped timeline with source citations, uncertainty and key pivots.
Quality gate
Analyst reflection
Which result from “Write a concise narrative that does not exceed the evidence” would need more evidence before it could support an operational decision?
After checking the evidence, run python Smartphone-Academy.py complete incident-timeline. Progress is stored locally in the Termux home directory.