$ cat writeup.md…
$ cat writeup.md…
D^3CTF 2026
Task: Windows kernel Gomoku driver (drv_game.sys) with a hidden second-stage PE protected by hypervisor EPT dual-view obfuscation and a convincing HTTP decoy. Solution: runtime memory-diff to reveal hook-view constants, reconstruct the MSR-spoofed salt, invert a base-37 fold, simulate the Gomoku engine to recover the exact winning move sequence, and pass the 39-byte SHA256 double-check to make the driver write the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar