Magnet Virtual Summit Capture The Flag 2022 - Android. Featuring an intro to ALEAPP

preview_player
Показать описание
Magnet Virtual Summit Capture The Flag 2022 - Android


Difficulty Level: Intermediate
Prerequisites:
basic understanding of digital forensics
basic understanding of linux command line
basic understanding of Autopsy

In this video we will look at solving some Capture the Flag questions from the Magnet Forensics 2022 Capture the Flag contest, Android portion.  In this video, I will use only the CAINE Linux forensics distro and other free tools. Yes, I know that there are better ways of doing this and my wife tells me that I’m an idiot too. But I was overseas and didnt have access to my dongles for my paid tools so had to work with what I got. The two main tools I will be using for this is Autopsy and ALEAPP.

To download the images and work through them yourselves, see the blog from Magnet Forensics:

Note, I’m really showing you the method of how I got the answers and not particularly the answer itself as that really doesn’t help you in the future.  As a matter of fact I’m not even sure if some of the answers are correct as I wasn’t able to participate in the CTF as it started at midnight in the timezone I was in and I had to wake up to teach a class in the morning.

*******
There will be another CTF starting soon: June 15, 2022 so make sure you sign up and play
********

Video timeline
00:00 intro
03:47 Question 1: If you are looking for an image, it was probably deleted.
04:58 Question 2: ooo so popular!
06:06 Question 3: BurgLARProof
07:11 Question 4: Your charIoT awaits
08:40 Question 5: ID Please
09:20 Question 6: Never-ending
10:41 Question 7: Last 4
11:39 Question 8: Expired Milk
12:31 Question 9: Water Water Everywhere
14:02 Question 10: Keep on Moving
14:34 Question 11: Snap your fingers
15:08 Question 12: Starting over
15:34 Question 13: Hash it out
16:11 Question 14: So Tasking
16:58 Question 15: Surviving a snake bite
17:42 Question 16: Bee Sweater
19:19 Question 17: A recent trick
20:48 Question 18: All trail blazer
21:23 Question 19: Seeing through the trees

Linux distro:

Virtualization software:

ALEAP git hub:

SANS 585 poster:

#CTF #Linux #DFIR
Рекомендации по теме
Комментарии
Автор

Hi! Can we have the Capture The Flag's file?

francescocostanzo