lab 05 · capstone
lab 5 · blind assessment · capstone
A blind, end-to-end compromise assessment on a device you did not configure — scored against the rubric.
objective
The capstone removes prior knowledge and forces the methodology to do the work. You run the entire loop unaided and produce a report a peer could act on.
materials
- Labs 1–4 completed
- A blind-swapped device
- The full toolchain
- The report template + rubric from the teacher's manual
procedure
- Devices are reset and reconfigured, then swapped. You receive a device you did not set up. You are told only that it "feels off."
- Run the full loop from memory: preserve → triage → acquire → analyze → report. Decide your preservation posture before you touch it.
- Triage with
apts.sh; acquire live artifacts withacquire_artifacts.sh; if integrity signals warrant, image the boot chain withapts_tui.py. - Correlate across all evidence. Build the timeline. Form a hypothesis and try to disprove it before you commit.
- Write the full report and choose a remediation on the severity ladder — from "suspicious, preserve" to "reflash + rotate credentials."
deliverable
Deliverable: a complete assessment report — authorization & preservation decision, findings with evidence citations, a fused timeline, a calibrated confidence level, a remediation recommendation matched to severity, and an explicit statement of what your triage could not see.
graded on
The report is graded, not the tool run — see the rubric in the teacher's manual. Confidence calibration and honesty about the limits of userspace triage weigh as heavily as the findings themselves.