forensicsmedium

Cat Image

hackerlab

Task: a 4GB Windows memory dump where the suspect was drawing cats in MS Paint. Solution: dump mspaint.exe process memory, reconstruct the unsaved canvas from raw BGRA pixel data to reveal the flag drawn on a cat image.

$ ls tags/ techniques/
process_memory_dumpmspaint_canvas_recoveryraw_bgra_pixel_reconstructionregistry_recent_files_analysisdecoy_flag_identification

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub to get started.

$ssh [email protected]