bi0s
  •  Home
  •  Categories
  •  Archives
  •  Tags
  •  Home
  •  Categories
  •  Archives
  •  Tags

LOGarithm - InCTF Internationals 2020

stuxn3t
2020-08-04
Forensics / Memory

tl;dr

  • Extract keylogger script from the memory dump.
  • Extract the master key from the packet capture.
  • Reverse the script to get the flag.
Read More
InCTFi Windows Memory Analysis

Investigation Continues - InCTF Internationals 2020

stuxn3t
2020-08-04
Forensics / Memory

tl;dr

  • Extract Invalid Login timestamp from the windows registry.
  • Extract the timestamp of when a JPEG was opened.
  • Extract Google Chrome’s last run time which was pinned to taskbar from windows registry.
Read More
InCTFi Volatility Windows Memory Analysis Windows Registry

Investigation - InCTF Internationals 2020

stuxn3t
2020-08-04
Forensics / Memory

tl;dr

  • Extract process last run time from the windows registry.
  • Extract process run count from the windows registry.
Read More
InCTFi Volatility Windows Memory Analysis Windows Registry

USB 2 - 2020 Defenit CTF

stuxn3t
2020-06-07
Forensics / Registry

tl;dr

  • Digging into windows registry to find process run counts.
  • Extracting and parsing AmCache to find the hash of process images
Read More
Windows Registry Analysis Defenit

Find My Pass - HackTM CTF Quals 2020

stuxn3t
2020-02-09
Forensics / Memory

tl;dr

  • Memory dump analysis using Volatility.
  • Extracting Keepass Master Password from the memory.
  • Extracting flag from ZIP archive attached in the Keepass database.
Read More
Windows Memory Analysis HackTM

RR - HackTM CTF Quals 2020

stuxn3t
2020-02-09
Forensics / Disk

tl;dr

  • RAID recovery
  • JPEG image extraction from lost disk
Read More
HackTM RAID Recovery

EV3 Player - HITCON Quals 2019

stuxn3t
2019-10-14
Forensics / Network

tl;dr

  • EV3 Robot pklg analysis
  • .RSF file recovery
Read More
EV3 Robot Wireshark HITCON

Notch It Up - InCTF Internationals 2019

stuxn3t
2019-09-24
Forensics / Memory

tl;dr

  • Chrome history analysis
  • File recovery from the memory dump
  • Raw analysis of email content
  • Environment variables analysis
  • RAR password cracking
  • Corrupted file analysis
Read More
InCTFi Volatility Windows Memory Analysis

Just Do It - InCTF Internationals 2019

stuxn3t
2019-09-24
Forensics / Memory

tl;dr

  • Master File Table Analysis
  • Deleted file data recovery
Read More
InCTFi Volatility Windows Memory Analysis

SecurinetsQuals2019-Contact_Me

stuxn3t
2019-08-24
Forensics / Memory

tl;dr

  1. Analysis of memory dump using Volatility framework.
  2. Using mac_contacts plugin to get relevant data.
  3. Base64 decode to get flag.

Solved by: stuxn3t

Read More
MacOS Memory Analysis

1 / 2

 Next 

Official blog of team bi0s

  Projects
  •   bi0s-wargame
    (Unraveling)
  •   bi0s-wiki
    (Free Encyclopedia)
  •   InCTF
    (Nationals CTF)
  •   InCTFj
    (Juniors CTF)

Made With Love and Coffee



Blog content follows the Attribution-NonCommercial-ShareAlike 4.0 International (CC BY-NC-SA 4.0) License

Use Material X as theme, total visits times.