Blog

CTF walkthroughs, DFIR labs, and security research

Nitroba - Email Harassment

Scenario SOURCE: Digital Corpora (Note: Because packet capture files contain timestamps for each packet, this scenario needs to have a date and time when it takes place. This scenario takes...

DFIRLABS: 2-Layer Security

At the beginning of the challenge, you can quickly realize that we are dealing with a Linux filesystem. Looking through the folders to see if we have any suspicious files...

DFIRLABS: Trinity of Secrets

(Image generated by ChatGPT) Unzipping the file shows another raw file, so lets search for a profile in volatility $ vol.py -f DFIRLABS.raw imageinfo Volatility Foundation Volatility Framework 2.6.1 INFO...

DFIRLABS: Gotham Hustle

(Image generated by ChatGPT)