forensicshard
Advanced Packaged Threat
scarlet
Task: Analyze PCAP to investigate suspicious SSH key on server after using custom PPA. Solution: Extract malicious deb package, deobfuscate bash dropper, reverse Rust C2 client, decrypt ChaCha20 traffic to recover exfiltrated flag.
$ ls tags/ techniques/
binary_analysispcap_analysishttp_object_extractiondeb_forensicsbash_deobfuscationc2_decryption
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]