bi0s
  •  Home
  •  Categories
  •  Archives
  •  Tags
  •  Home
  •  Categories
  •  Archives
  •  Tags

The Big Score - InCTF Internationals 2021

d3liri0us
2021-08-20
Forensics / Memory

tl;dr

  • Create a Linux profile for Ubuntu 18.04 (5.4.0-42-generic) in Volatility
  • Use linux_bash plugin to get link to the repo and linux_find_file plugin to recover the filepath
  • Decode the keyboard stream data to retrieve the flag
Read More
InCTFi Memory Linux

Ermittlung - InCTF Internationals 2021

g4rud4
2021-08-16
Forensics / Memory

tl;dr

  • Finding Chat application
  • Extract unread message count from NTUSER.dat.
  • Extract the last executed timestamp of the chat application.
  • Extract the Version of the chat application.
Read More
InCTFi Volatility Windows Memory Analysis

KarDi Bee X - Securinets Quals 2021

g4rud4
2021-03-22
Forensics / Memory

tl;dr

  • File recovery from the memory dump
  • Environment variables analysis.
  • RAR and Zip password cracking.
  • Cracking Windows user password hash.
  • Extracting Keepass Master Password from keystrokes of logged data.
Read More
Volatility Windows Memory Analysis Securinets Quals

LOGarithm - InCTF Internationals 2020

stuxn3t
2020-08-04
Forensics / Memory

tl;dr

  • Extract keylogger script from the memory dump.
  • Extract the master key from the packet capture.
  • Reverse the script to get the flag.
Read More
InCTFi Windows Memory Analysis

Investigation Continues - InCTF Internationals 2020

stuxn3t
2020-08-04
Forensics / Memory

tl;dr

  • Extract Invalid Login timestamp from the windows registry.
  • Extract the timestamp of when a JPEG was opened.
  • Extract Google Chrome’s last run time which was pinned to taskbar from windows registry.
Read More
InCTFi Volatility Windows Memory Analysis Windows Registry

Investigation - InCTF Internationals 2020

stuxn3t
2020-08-04
Forensics / Memory

tl;dr

  • Extract process last run time from the windows registry.
  • Extract process run count from the windows registry.
Read More
InCTFi Volatility Windows Memory Analysis Windows Registry

Find My Pass - HackTM CTF Quals 2020

stuxn3t
2020-02-09
Forensics / Memory

tl;dr

  • Memory dump analysis using Volatility.
  • Extracting Keepass Master Password from the memory.
  • Extracting flag from ZIP archive attached in the Keepass database.
Read More
Windows Memory Analysis HackTM

Notch It Up - InCTF Internationals 2019

stuxn3t
2019-09-24
Forensics / Memory

tl;dr

  • Chrome history analysis
  • File recovery from the memory dump
  • Raw analysis of email content
  • Environment variables analysis
  • RAR password cracking
  • Corrupted file analysis
Read More
InCTFi Volatility Windows Memory Analysis

Just Do It - InCTF Internationals 2019

stuxn3t
2019-09-24
Forensics / Memory

tl;dr

  • Master File Table Analysis
  • Deleted file data recovery
Read More
InCTFi Volatility Windows Memory Analysis

SecurinetsQuals2019-Contact_Me

stuxn3t
2019-08-24
Forensics / Memory

tl;dr

  1. Analysis of memory dump using Volatility framework.
  2. Using mac_contacts plugin to get relevant data.
  3. Base64 decode to get flag.

Solved by: stuxn3t

Read More
MacOS Memory Analysis

1 / 2

 Next 

Official blog of team bi0s

  Projects
  •   bi0s-wargame
    (Unraveling)
  •   bi0s-wiki
    (Free Encyclopedia)
  •   InCTF
    (Nationals CTF)
  •   InCTFj
    (Juniors CTF)

Made With Love and Coffee



Blog content follows the Attribution-NonCommercial-ShareAlike 4.0 International (CC BY-NC-SA 4.0) License

Use Material X as theme, total visits times.