Open in app

Sign In

Write

Sign In

Nisarg Suthar
Nisarg Suthar

40 Followers

Home

Lists

About

Nov 2, 2022

CyberDefenders Write-up: GrabThePhisher

Disclaimer: All the answers apart from the obvious will be redacted to encourage defenders to try the challenge themselves. The Prompt: An attacker compromised a server and impersonated https://pancakeswap.finance/, a decentralized exchange native to BNB Chain, to host a phishing kit at https://apankewk.soup.xyz/mainpage.php. …

Dfir

3 min read

CyberDefenders Write-up: GrabThePhisher
CyberDefenders Write-up: GrabThePhisher
Dfir

3 min read


Mar 30, 2022

picoCTF 2022 Write-up: TorrentAnalyze

This includes my standalone write-up for the forensics challenge ‘TorrentAnalyze’ from picoCTF 2022 as it was something I never looked into and was an interesting challenge for network forensics! Prompt

Dfir

5 min read

picoCTF 2022 Write-up: TorrentAnalyze
picoCTF 2022 Write-up: TorrentAnalyze
Dfir

5 min read


Mar 13, 2022

Belkasoft Write-up: CTF 4

This will be my write-up for the 4th Belkasoft CTF! This CTF follows a plot based progression to make it fun, so I’ll also include the plot details unlike my other write-ups :) Prompt — Have you heard the news? I have. — The CID has interrogated the father. Other than…

Ctf

8 min read

Belkasoft Write-up: CTF 4
Belkasoft Write-up: CTF 4
Ctf

8 min read


Mar 12, 2022

UMDCTF 2022 Write-ups

This includes my write-up for UMDCTF which had many interesting and new forensics challenges along with other categories! Forensics 1. Renzik’s Case We’re given an image file usb.img which after loading in FTK shows the deleted files from the unallocated space. Simple one to begin with, nothing too complex.

Capture The Flag

8 min read

UMDCTF 2022 Write-ups
UMDCTF 2022 Write-ups
Capture The Flag

8 min read


Jan 24, 2022

CyberDefenders Write-up: Injector

Disclaimer: All the answers apart from the obvious will be redacted to encourage defenders to try the challenge themselves. The Prompt: A company’s web server has been breached through their website. Our team arrived just in time to take a forensic image of the running system and its memory for further analysis. …

Dfir

6 min read

CyberDefenders Write-up: Injector
CyberDefenders Write-up: Injector
Dfir

6 min read


Jan 22, 2022

CyberDefenders Write-up: Hunter

Disclaimer: All the answers apart from the obvious will be redacted to encourage defenders to try the challenge themselves. The Prompt: The SOC team got an alert regarding some illegal port scanning activity coming from an employee’s system. The employee was not authorized to do any port scanning or any offensive hacking activity…

Dfir

9 min read

CyberDefenders Write-up: Hunter
CyberDefenders Write-up: Hunter
Dfir

9 min read


Nov 15, 2021

CyberDefenders Write-up: DumpMe

Disclaimer: All the answers apart from the obvious will be redacted to encourage defenders to try the challenge themselves. The Prompt: One of the SOC analysts took a memory dump from a machine infected with a meterpreter malware. …

Dfir

4 min read

CyberDefenders Write-up: DumpMe
CyberDefenders Write-up: DumpMe
Dfir

4 min read


Nov 14, 2021

CyberDefenders Write-up: BankingTroubles

Disclaimer: All the answers apart from the obvious will be redacted to encourage defenders to try the challenge themselves. The Prompt: Company X has contacted you to perform forensics work on a recent incident that occurred. One of their employees had received an e-mail from a co-worker that pointed to a PDF file…

Malware

7 min read

CyberDefenders Write-up: BankingTroubles
CyberDefenders Write-up: BankingTroubles
Malware

7 min read


Oct 2, 2021

DeconstruCTF 2021 Write-ups

This will be my write-up for some random challenges from DeconstruCTF 2021! Forensics 1. The Missing Journalist

Capture The Flag

4 min read

DeconstruCTF 2021 Write-ups
DeconstruCTF 2021 Write-ups
Capture The Flag

4 min read


Sep 30, 2021

CyberDefenders Write-up: CTF01

This is going to be my write-up for the first blue team CTF from CyberDefenders, involving investigating a Linux image. The Prompt: We’re provided with a .E01 file, which is an EnCase image format. I used FTK Imager as it was faster for me than Autopsy. …

Dfir

8 min read

CyberDefenders Write-up: CTF01
CyberDefenders Write-up: CTF01
Dfir

8 min read

Nisarg Suthar

Nisarg Suthar

40 Followers

DFIR & CySec Aficionado.

Following
  • Syed Hasan

    Syed Hasan

  • David Schiff

    David Schiff

  • Florian Roth

    Florian Roth

  • Mike Cohen

    Mike Cohen

  • dr3ad_0X1

    dr3ad_0X1

See all (10)

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech