Points: 666

Tags: misc forensics rdp pkcs12 

Poll rating:

One of our boxes was pwned. During the post-mortem, we found something called mimikatz which we didn't install so we wiped and reinstalled the box. However, we forgot to backup our flag file. Luckily, we have a network capture of the attacker exfiltrating the file. CAN YOU PLEASE RECOVER OUR FLAG FILE?

Writeups

ActionRatingAuthor team
Read writeup
not rated
NUS GreyHats
You need to authenticate and join a team to post writeups