Threat-Model a Small Service
Map assets, actors, entry points and controls for a fictional local service.
Map assets, actors, entry points and controls for a fictional local service.
Prepare 20m · Build 110m · Verify 30m · Document 20m
Work only inside the folder created by Smartphone-Academy.py prepare threat-model. Use the supplied samples or systems you personally administer.
Prepare the Termux workspace
Open Termux in the Academy root and prepare this lab with the local companion. It creates safe samples, notes and evidence files under your Termux account.
python Smartphone-Academy.py prepare threat-modelNo root. Use the supplied files and keep the workspace under $HOME.Practical mission
- Define the service scope and valuable assets
- Draw processes, data stores and trust boundaries
- Describe six realistic misuse cases without exploit instructions
- Prioritize mitigations by likelihood, impact and effort
A one-page data-flow diagram and prioritized risk register.
Quality gate
Analyst reflection
Which result from “Prioritize mitigations by likelihood, impact and effort” would need more evidence before it could support an operational decision?
After checking the evidence, run python Smartphone-Academy.py complete threat-model. Progress is stored locally in the Termux home directory.