$ cat writeup.md…
$ cat writeup.md…
hackthebox
Task: memory dump (powershell.dmp) + pcap of a Covenant Grunt C2 session; determine whether the APT penetrated the network and recover the flag. Solution: fingerprint Covenant via its default HTTP profile, deobfuscate the base64+DEFLATE .NET stager to extract SetupAESKey, recover the negotiated AES session key from the process dump via an HMAC-SHA256 oracle full-dump scan, decrypt the AES-256-CBC C2 traffic, and reconstruct the flag from keylogger output by stripping lshiftkey noise tokens.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar