DEFCON 2019 forensics
This is a brief write up for the DEFCON 2019 forensics CTF
1 / get your volatility on (5)
$ sha1sum winmem.mem
$ c95e8cc8c946f95a109ea8e47a6800de10a27abd winmem.mem2 / pr0file (10)
$ python vol.py -f /mnt/ctf/Defcon2019/winmem.mem imageinfoVolatility Foundation Volatility Framework 2.6.1
INFO : volatility.debug : Determining profile based on KDBG search...
Suggested Profile\(s\) : Win7SP1x64, Win7SP0x64, Win2008R2SP0x64, Win2008R2SP1x64\_24000, Win2008R2SP1x64\_23418, Win2008R2SP1x64, Win7SP1x64\_24000, Win7SP1x64\_23418$ python vol.py -f /mnt/ctf/Defcon2019/winmem.mem kdbgscan3 / hey, write this down (12)
4 / wscript can haz children (14)
5 / tcpip settings (18)
6 / intel (18)
7 / i <3 windows dependencies (20)
8 mal-ware-are-you (20)
9 lm-get bobs hash (24)
11 more vads?! (25)
12 vacation bible school (25)
13 thx microsoft (25)
14 lightbulb moment (35)
15 8675309 (35)
16 whats-a-metasploit? (50)
Last updated