BreizhCTF 2022 - La livraison de pizza

La livraison de pizza

Enoncé

Un nouvel employé travaille tranquillement à son bureau, quand quelqu’un se présente devant pour ‘Livraison de galettes saucisses’. Il est nouveau, mais il se dit qu’en Bretagne, après tout, cela doit arriver.

Il est donc venu dans votre bureau vous demandez si vous aviez commandé, mais votre réponse est non. Il revient tout paniqué en vous disant que son anvitirus a enregistré un traffic USB inhabituel.

Cyberdefenders - Brave

Brave

Info

  • Category : Digital Forensics
  • SHA1SUM : fa02a505471aeb89172f89cb27dd4e2eea14bb9e
  • Published : June 20, 2021
  • Author : DFIRScience
  • Size : 1.2 GB
  • Tags : Volatility Memory Brave Winows

Unzip the challenge (pass: cyberdefenders.org)

Scenario

A memory image was taken from a seized Windows machine. Analyze the image and answer the provided questions.

Tools

  • Volatility 3
  • CertUtil
  • HxD

Questions

1 - What time was the RAM image acquired according to the suspect system ? (YYYY-MM-DD HH:MM:SS)

sudo vol -f 20210430-Win10Home-20H2-64bit-memdump.mem windows.info
Volatility 3 Framework 2.0.0
Progress:  100.00               PDB scanning finished                        
Variable        Value

Kernel Base     0xf8043cc00000
DTB     0x1aa000
Symbols file:///usr/local/lib/python3.8/dist-packages/volatility3-2.0.0-py3.8.egg/volatility3/symbols/windows/ntkrnlmp.pdb/769C521E4833ECF72E21F02BF33691A5-1.json.xz
Is64Bit True
IsPAE   False
layer_name      0 WindowsIntel32e
memory_layer    1 FileLayer
KdVersionBlock  0xf8043d80f368
Major/Minor     15.19041
MachineType     34404
KeNumberProcessors      4
SystemTime      2021-04-30 17:52:19
NtSystemRoot    C:\Windows
NtProductType   NtProductWinNt
NtMajorVersion  10
NtMinorVersion  0
PE MajorOperatingSystemVersion  10
PE MinorOperatingSystemVersion  0
PE Machine      34404
PE TimeDateStamp        Tue Oct 11 07:04:26 1977

Réponse : 2021-04-30 17:52:19

Cyberdefenders - DetectLog4j

DetectLog4j

Info

  • Category : Digital Forensics
  • SHA1SUM : 6556e7d46e89bf2ea68e05cf101920e2de071a22
  • Published : Jan. 15, 2022
  • Author : CyberDefenders
  • Size : 2.8 GB
  • Tags : Windows Disk ransomware log4shell

Uncompress the challenge (pass: cyberdefenders.org)

Scenario

For the last week, log4shell vulnerability has been gaining much attention not for its ability to execute arbitrary commands on the vulnerable system but for the wide range of products that depend on the log4j library. Many of them are not known till now. We created a challenge to test your ability to detect, analyze, mitigate and patch products vulnerable to log4shell.

Cyberdefenders - DumpMe

DumpMe

Info

  • Category : Digital Forensics
  • SHA1SUM : 70f1bafca632f7518cb0a0ee126246b040247b37
  • Published : May 30, 2021
  • Author : Champlain College
  • Size : 1.2 GB
  • Tags : Volatility DFIR Windows Memory

Scenario

One of the SOC analysts took a memory dump from a machine infected with a meterpreter malware. As a Digital Forensicators, your job is to analyze the dump, extract the available indicators of compromise (IOCs) and answer the provided questions.

Tools

  • Volatility 2
  • sha1sum

Questions

1 - What is the SHA1 hash of Triage-Memory.mem (memory dump) ?

sha1sum Triage-Memory.mem 
c95e8cc8c946f95a109ea8e47a6800de10a27abd  Triage-Memory.mem

Answer : c95e8cc8c946f95a109ea8e47a6800de10a27abd

Cyberdefenders - HawkEye

HawkEye

Info

  • Category : Digital Forensics, Malware Analysis
  • SHA1SUM : bd7239a7c1e33f4d616242fe892888befc9fashed
  • Published : March 3, 2022
  • Authors : Brad Duncan and Manuel GRegal
  • Size : 1.3 MB
  • Tags : PCAP WireShark Network BRIM

Uncompress the challenge (pass: cyberdefenders.org)

Scenario

An accountant at your organization received an email regarding an invoice with a download link. Suspicious network traffic was observed shortly after opening the email. As a SOC analyst, investigate the network trace and analyze exfiltration attempts.

Cyberdefenders - l337 S4uc3

l337 S4uc3

Info

  • Category : Digital Forensics, Incident response
  • SHA1SUM : 94ac99ef544086f0be9f5f6b00ae1a0834b0027b
  • Published : Nov. 16, 2021
  • Author : Wyatt Roersma
  • Size : 117 MB
  • Tags : Wireshark PCAP Memory Network

Uncompress the challenge (pass: cyberdefenders.org)

Scenario

Everyone has heard of targeted attacks. Detecting these can be challenging, responding to these can be even more challenging. This scenario will test your network and host-based analysis skills to figure out the who, what, where, when, and how of this incident. There is sure to be something for all skill levels and the only thing you need to solve the challenge is some l337 S4uc3!