Tags: wireshark traffic misc usb forensics pyshark 

Rating: 5.0

* Look for large packets with PKZIP header and trailer bytes
* Extract with pyshark
* Base-64 decode flag

Original writeup (https://rainbowpigeon.me/posts/buckeyectf-2021/#usb-exfiltration).