Match Indicators Carefully
Compare a supplied indicator list with local synthetic events while controlling false matches.
Compare a supplied indicator list with local synthetic events while controlling false matches.
Prepare 20m · Build 110m · Verify 30m · Document 20m
Work only inside the folder created by Smartphone-Academy.py prepare ioc-matching. Use the supplied samples or systems you personally administer.
Prepare the Termux workspace
Open Termux in the Academy root and prepare this lab with the local companion. It creates safe samples, notes and evidence files under your Termux account.
python Smartphone-Academy.py prepare ioc-matchingNo root. Use the supplied files and keep the workspace under $HOME.Practical mission
- Validate and normalize domains, addresses and hashes
- Use exact matching where substring matching is unsafe
- Attach surrounding event context to every hit
- Explain why an indicator match is a lead rather than a verdict
A match report with normalization rules, context and confidence.
Quality gate
Analyst reflection
Which result from “Explain why an indicator match is a lead rather than a verdict” would need more evidence before it could support an operational decision?
After checking the evidence, run python Smartphone-Academy.py complete ioc-matching. Progress is stored locally in the Termux home directory.