PIP Install - Week 2 - Magnet Weekly CTF g4rud4 2020-10-20 Forensics / Android tl;dr Finding Picture-In-Picture application capability. Most recently viewed web activity in Picture-In-Picture application on the device. Read More Magnet Weekly CTF ALEAP Picture-In-Picture
Mapping the Digits - Week 1 - Magnet Weekly CTF g4rud4 2020-10-12 Forensics / Android tl;dr Finding the last modified timestamp of the file that maps names to IP’s accessed. Read More Autopsy Magnet Weekly CTF Android Forensics
LOGarithm - InCTF Internationals 2020 stuxn3t 2020-08-04 Forensics / Memory tl;dr Extract keylogger script from the memory dump. Extract the master key from the packet capture. Reverse the script to get the flag. Read More InCTFi Windows Memory Analysis
Investigation Continues - InCTF Internationals 2020 stuxn3t 2020-08-04 Forensics / Memory tl;dr Extract Invalid Login timestamp from the windows registry. Extract the timestamp of when a JPEG was opened. Extract Google Chrome’s last run time which was pinned to taskbar from windows registry. Read More InCTFi Volatility Windows Memory Analysis Windows Registry
Investigation - InCTF Internationals 2020 stuxn3t 2020-08-04 Forensics / Memory tl;dr Extract process last run time from the windows registry. Extract process run count from the windows registry. Read More InCTFi Volatility Windows Memory Analysis Windows Registry
Lookout Foxy - InCTF Internationals 2020 g4rud4 2020-08-03 Forensics / Disk tl;dr Decrypt the encrypted GPG file found in Outlook Express with the private key stored on the device. Decrypt the firefox saved passwords and log in to the website that the terrorist used. Read More InCTFi Autopsy
USB 2 - 2020 Defenit CTF stuxn3t 2020-06-07 Forensics / Registry tl;dr Digging into windows registry to find process run counts. Extracting and parsing AmCache to find the hash of process images Read More Windows Registry Analysis Defenit
Strange PCAP - HackTM CTF Quals 2020 g4rud4 2020-02-10 Forensics / Network tl;dr Disk Dump extraction. USB leftover Capture data extraction. Zip file cracking. Read More HackTM Wireshark
Find My Pass - HackTM CTF Quals 2020 stuxn3t 2020-02-09 Forensics / Memory tl;dr Memory dump analysis using Volatility. Extracting Keepass Master Password from the memory. Extracting flag from ZIP archive attached in the Keepass database. Read More Windows Memory Analysis HackTM
RR - HackTM CTF Quals 2020 stuxn3t 2020-02-09 Forensics / Disk tl;dr RAID recovery JPEG image extraction from lost disk Read More HackTM RAID Recovery