Tags: volatility forensics 

Rating:

Writeup: Classic Forensic:triangular_flag_on_post:

Category : Forensic:minidisc:
Points : 425
Author : krn bhargav (Ryn0)
Team : Red-Knights:warning:

Description

We need to do some classic forensic stuff on this mem dump, can you help us and check what is important there?

Dumpfile-259 MB (sorry for not uploading.)

description

solution

We have a MS Windows 64bit crash dump,for this we have to use the tool Volatility3. Thanks to the authors for making our life easy.

fileinfo

During this ctf,I try everything to analyse this MEMORY.dmp but donot find anything ,finally i use this command.

vol.py -f MEMORY.dmp windows.lsadump

in this command we used the lsadump plugin to extract lsa secrets. and found flag volatility3

Flag : AFFCTF{f0rensic_w3ll_d0n3}
Original writeup (https://github.com/Red-Knights-CTF/writeups/tree/master/2020/affinity_ctf_lite/Classic_Forensics).