forensicshard

Advanced Packaged Threat

scarlet

Task: Analyze PCAP to investigate suspicious SSH key on server after using custom PPA. Solution: Extract malicious deb package, deobfuscate bash dropper, reverse Rust C2 client, decrypt ChaCha20 traffic to recover exfiltrated flag.

$ ls tags/ techniques/
binary_analysispcap_analysishttp_object_extractiondeb_forensicsbash_deobfuscationc2_decryption

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]