RAGBAZRAGBAZ/forensics
school
syllabus teacher's manual student instructions methodology live acquisition
labs
lab 1 · baseline & authorized acquisitionlab 2 · persistence huntlab 3 · live artifact acquisitionlab 4 · boot-chain imaging & verificationlab 5 · blind assessment · capstone
tools
apts.sh apts_tui.py acquire_artifacts.sh
studio
↩ school overview ↩ ragbaz.cc
lab 05 · capstone

lab 5 · blind assessment · capstone

A blind, end-to-end compromise assessment on a device you did not configure — scored against the rubric.

150 mincapstonefull loopreport

objective

The capstone removes prior knowledge and forces the methodology to do the work. You run the entire loop unaided and produce a report a peer could act on.

materials

  • Labs 1–4 completed
  • A blind-swapped device
  • The full toolchain
  • The report template + rubric from the teacher's manual

procedure

  1. Devices are reset and reconfigured, then swapped. You receive a device you did not set up. You are told only that it "feels off."
  2. Run the full loop from memory: preserve → triage → acquire → analyze → report. Decide your preservation posture before you touch it.
  3. Triage with apts.sh; acquire live artifacts with acquire_artifacts.sh; if integrity signals warrant, image the boot chain with apts_tui.py.
  4. Correlate across all evidence. Build the timeline. Form a hypothesis and try to disprove it before you commit.
  5. Write the full report and choose a remediation on the severity ladder — from "suspicious, preserve" to "reflash + rotate credentials."

deliverable

Deliverable: a complete assessment report — authorization & preservation decision, findings with evidence citations, a fused timeline, a calibrated confidence level, a remediation recommendation matched to severity, and an explicit statement of what your triage could not see.

graded on

The report is graded, not the tool run — see the rubric in the teacher's manual. Confidence calibration and honesty about the limits of userspace triage weigh as heavily as the findings themselves.