13Cubed Windows memory forensics
Files
Scenario
Analysis Environment

Challenge Questions
Question 1: What is the hostname of this device?
Question 2: What is the username of the primary user on this device?
Question 3: What is the IP address assigned to this device?
Question 4: What was the full URL, including the file name, that the malicious program was downloaded from?
Question 5: According to this execution artifact that would not be found on servers, the first execution occurred within 10 seconds of what time?
Question 6:
According to the malicious program's log file, how many files were encrypted?
Question 7:
What is the NTFS creation time for backup.exe?
Question 8:
What is the full path and name of the public key created by the malicious file?
Question 9:
What is the first line of key material from the TA's private key?
Question 10:
What is the last web search performed by the user?

Bonus Question:
What folder does the "Backup Software" landing page tell users to exclude?

Last updated