forensicseasy

Чувак, где мой флаг? (Dude, Where's My Flag?)

hackerlab

Task: Analyze a suspicious file from an infected computer. Solution: Detected Unicode RLO spoofing in filename (.exe disguised as .jpg), extracted WinRAR SFX archive, and decrypted XOR-encoded flag from embedded malware.

$ ls tags/ techniques/
xor_decryptionunicode_filename_detectionsfx_extractionbinary_analysis

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub to get started.

$ssh [email protected]