bi0s
  •  Home
  •  Categories
  •  Archives
  •  Tags
  •  Home
  •  Categories
  •  Archives
  •  Tags

PIP Install - Week 2 - Magnet Weekly CTF

g4rud4
2020-10-20
Forensics / Android

tl;dr

  • Finding Picture-In-Picture application capability.
  • Most recently viewed web activity in Picture-In-Picture application on the device.
Read More
Magnet Weekly CTF ALEAP Picture-In-Picture

Mapping the Digits - Week 1 - Magnet Weekly CTF

g4rud4
2020-10-12
Forensics / Android

tl;dr

  • Finding the last modified timestamp of the file that maps names to IP’s accessed.
Read More
Autopsy Magnet Weekly CTF Android Forensics

LOGarithm - InCTF Internationals 2020

stuxn3t
2020-08-04
Forensics / Memory

tl;dr

  • Extract keylogger script from the memory dump.
  • Extract the master key from the packet capture.
  • Reverse the script to get the flag.
Read More
InCTFi Windows Memory Analysis

Investigation Continues - InCTF Internationals 2020

stuxn3t
2020-08-04
Forensics / Memory

tl;dr

  • Extract Invalid Login timestamp from the windows registry.
  • Extract the timestamp of when a JPEG was opened.
  • Extract Google Chrome’s last run time which was pinned to taskbar from windows registry.
Read More
InCTFi Volatility Windows Memory Analysis Windows Registry

Investigation - InCTF Internationals 2020

stuxn3t
2020-08-04
Forensics / Memory

tl;dr

  • Extract process last run time from the windows registry.
  • Extract process run count from the windows registry.
Read More
InCTFi Volatility Windows Memory Analysis Windows Registry

Lookout Foxy - InCTF Internationals 2020

g4rud4
2020-08-03
Forensics / Disk

tl;dr

  • Decrypt the encrypted GPG file found in Outlook Express with the private key stored on the device.
  • Decrypt the firefox saved passwords and log in to the website that the terrorist used.
Read More
InCTFi Autopsy

USB 2 - 2020 Defenit CTF

stuxn3t
2020-06-07
Forensics / Registry

tl;dr

  • Digging into windows registry to find process run counts.
  • Extracting and parsing AmCache to find the hash of process images
Read More
Windows Registry Analysis Defenit

Strange PCAP - HackTM CTF Quals 2020

g4rud4
2020-02-10
Forensics / Network

tl;dr

  • Disk Dump extraction.
  • USB leftover Capture data extraction.
  • Zip file cracking.
Read More
HackTM Wireshark

Find My Pass - HackTM CTF Quals 2020

stuxn3t
2020-02-09
Forensics / Memory

tl;dr

  • Memory dump analysis using Volatility.
  • Extracting Keepass Master Password from the memory.
  • Extracting flag from ZIP archive attached in the Keepass database.
Read More
Windows Memory Analysis HackTM

RR - HackTM CTF Quals 2020

stuxn3t
2020-02-09
Forensics / Disk

tl;dr

  • RAID recovery
  • JPEG image extraction from lost disk
Read More
HackTM RAID Recovery

 Previous 

2 / 3

 Next 

Official blog of team bi0s

  Projects
  •   bi0s-wargame
    (Unraveling)
  •   bi0s-wiki
    (Free Encyclopedia)
  •   InCTF
    (Nationals CTF)
  •   InCTFj
    (Juniors CTF)

Made With Love and Coffee



Blog content follows the Attribution-NonCommercial-ShareAlike 4.0 International (CC BY-NC-SA 4.0) License

Use Material X as theme, total visits times.