forensicsmedium
Cat Image
hackerlab
Task: a 4GB Windows memory dump where the suspect was drawing cats in MS Paint. Solution: dump mspaint.exe process memory, reconstruct the unsaved canvas from raw BGRA pixel data to reveal the flag drawn on a cat image.
$ ls tags/ techniques/
process_memory_dumpmspaint_canvas_recoveryraw_bgra_pixel_reconstructionregistry_recent_files_analysisdecoy_flag_identification
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub to get started.
$ssh [email protected]