$ cat writeup.md…
$ cat writeup.md…
hackthebox
Task: memory dump (powershell.dmp) + pcap of a Covenant Grunt C2 session; determine whether the APT penetrated the network and recover the flag. Solution: fingerprint Covenant via its default HTTP profile, deobfuscate the base64+DEFLATE .NET stager to extract SetupAESKey, recover the negotiated AES session key from the process dump via an HMAC-SHA256 oracle full-dump scan, decrypt the AES-256-CBC C2 traffic, and reconstruct the flag from keylogger output by stripping lshiftkey noise tokens.
Permission denied (requires tier.pro)
Sign in with GitHub or Discord to continue. No email required.
$sign in$ grep --similar