bi0s
  •  Home
  •  Categories
  •  Archives
  •  Tags
  •  Home
  •  Categories
  •  Archives
  •  Tags

Investigation - InCTF Internationals 2020

stuxn3t
2020-08-04
Forensics / Memory

tl;dr

  • Extract process last run time from the windows registry.
  • Extract process run count from the windows registry.
Read More
InCTFi Volatility Windows Memory Analysis Windows Registry

Lookout Foxy - InCTF Internationals 2020

g4rud4
2020-08-03
Forensics / Disk

tl;dr

  • Decrypt the encrypted GPG file found in Outlook Express with the private key stored on the device.
  • Decrypt the firefox saved passwords and log in to the website that the terrorist used.
Read More
InCTFi Autopsy

USB 2 - 2020 Defenit CTF

stuxn3t
2020-06-07
Forensics / Registry

tl;dr

  • Digging into windows registry to find process run counts.
  • Extracting and parsing AmCache to find the hash of process images
Read More
Windows Registry Analysis Defenit

Strange PCAP - HackTM CTF Quals 2020

g4rud4
2020-02-10
Forensics / Network

tl;dr

  • Disk Dump extraction.
  • USB leftover Capture data extraction.
  • Zip file cracking.
Read More
HackTM Wireshark

Find My Pass - HackTM CTF Quals 2020

stuxn3t
2020-02-09
Forensics / Memory

tl;dr

  • Memory dump analysis using Volatility.
  • Extracting Keepass Master Password from the memory.
  • Extracting flag from ZIP archive attached in the Keepass database.
Read More
Windows Memory Analysis HackTM

RR - HackTM CTF Quals 2020

stuxn3t
2020-02-09
Forensics / Disk

tl;dr

  • RAID recovery
  • JPEG image extraction from lost disk
Read More
HackTM RAID Recovery

EV3 Player - HITCON Quals 2019

stuxn3t
2019-10-14
Forensics / Network

tl;dr

  • EV3 Robot pklg analysis
  • .RSF file recovery
Read More
EV3 Robot Wireshark HITCON

"...---..." - InCTF Internationals 2019

f4lc0n
2019-10-10
Forensics / Network

Write-Up for the “…—…” challenge from InCTF Internationals 2019

tl;dr

  1. Alert signals encoded in morse transfered to the Mi-Band
  2. Traverse through the packets and find the appropriate BLE handles of the encoded message
  3. Decode the morse encoded message
Read More
InCTFi Wireshark BLE Morse Code

Fresh From The Oven - InCTF Internationals 2019

g4rud4
2019-10-03
Forensics / Network

tl;dr

  • Decoding the strings found in TCP stream 0.
  • Analysing and extracting data sent via different ports of TCP.
  • Using character-wise caesar from the extracted data.
  • Zip cracking
Read More
InCTFi Wireshark Stego

Notch It Up - InCTF Internationals 2019

stuxn3t
2019-09-24
Forensics / Memory

tl;dr

  • Chrome history analysis
  • File recovery from the memory dump
  • Raw analysis of email content
  • Environment variables analysis
  • RAR password cracking
  • Corrupted file analysis
Read More
InCTFi Volatility Windows Memory Analysis

 Previous 

3 / 4

 Next 

Official blog of team bi0s

  Projects
  •   bi0s-wargame
    (Unraveling)
  •   bi0s-wiki
    (Free Encyclopedia)
  •   InCTF
    (Nationals CTF)
  •   InCTFj
    (Juniors CTF)

Made With Love and Coffee



Blog content follows the Attribution-NonCommercial-ShareAlike 4.0 International (CC BY-NC-SA 4.0) License

Use Material X as theme, total visits times.