Open in app
Home
Notifications
Lists
Stories

Write
Nisarg Suthar
Nisarg Suthar

Home

About

Mar 30

picoCTF 2022 Write-up: TorrentAnalyze

This includes my standalone write-up for the forensics challenge ‘TorrentAnalyze’ from picoCTF 2022 as it was something I never looked into and was an interesting challenge for network forensics! Prompt

Dfir

5 min read

picoCTF 2022 Write-up: TorrentAnalyze
picoCTF 2022 Write-up: TorrentAnalyze

Mar 13

Belkasoft Write-up: CTF 4

This will be my write-up for the 4th Belkasoft CTF! This CTF follows a plot based progression to make it fun, so I’ll also include the plot details unlike my other write-ups :) Prompt — Have you heard the news? I have. — The CID has interrogated the father. Other than…

Ctf

8 min read

Belkasoft Write-up: CTF 4
Belkasoft Write-up: CTF 4

Mar 12

UMDCTF 2022 Write-ups

This includes my write-up for UMDCTF which had many interesting and new forensics challenges along with other categories! Forensics 1. Renzik’s Case We’re given an image file usb.img which after loading in FTK shows the deleted files from the unallocated space. Simple one to begin with, nothing too complex.

Capture The Flag

8 min read

UMDCTF 2022 Write-ups
UMDCTF 2022 Write-ups

Jan 24

CyberDefenders Write-up: Injector

Disclaimer: All the answers apart from the obvious will be redacted to encourage defenders to try the challenge themselves. The Prompt: A company’s web server has been breached through their website. Our team arrived just in time to take a forensic image of the running system and its memory for further analysis. …

Dfir

6 min read

CyberDefenders Write-up: Injector
CyberDefenders Write-up: Injector

Jan 22

CyberDefenders Write-up: Hunter

Disclaimer: All the answers apart from the obvious will be redacted to encourage defenders to try the challenge themselves. The Prompt: The SOC team got an alert regarding some illegal port scanning activity coming from an employee’s system. The employee was not authorized to do any port scanning or any offensive hacking activity…

Dfir

9 min read

CyberDefenders Write-up: Hunter
CyberDefenders Write-up: Hunter

Nov 15, 2021

CyberDefenders Write-up: DumpMe

Disclaimer: All the answers apart from the obvious will be redacted to encourage defenders to try the challenge themselves. The Prompt: One of the SOC analysts took a memory dump from a machine infected with a meterpreter malware. …

Dfir

4 min read

CyberDefenders Write-up: DumpMe
CyberDefenders Write-up: DumpMe

Nov 14, 2021

CyberDefenders Write-up: BankingTroubles

Disclaimer: All the answers apart from the obvious will be redacted to encourage defenders to try the challenge themselves. The Prompt: Company X has contacted you to perform forensics work on a recent incident that occurred. One of their employees had received an e-mail from a co-worker that pointed to a PDF file…

Malware

7 min read

CyberDefenders Write-up: BankingTroubles
CyberDefenders Write-up: BankingTroubles

Oct 2, 2021

DeconstruCTF 2021 Write-ups

This will be my write-up for some random challenges from DeconstruCTF 2021! Forensics 1. The Missing Journalist

Capture The Flag

4 min read

DeconstruCTF 2021 Write-ups
DeconstruCTF 2021 Write-ups

Sep 30, 2021

CyberDefenders Write-up: CTF01

This is going to be my write-up for the first blue team CTF from CyberDefenders, involving investigating a Linux image. The Prompt: We’re provided with a .E01 file, which is an EnCase image format. I used FTK Imager as it was faster for me than Autopsy. …

Dfir

8 min read

CyberDefenders Write-up: CTF01
CyberDefenders Write-up: CTF01

Sep 26, 2021

DUCTF 2021 Write-ups

This is going to be my write-up for some challenges from DownUnderCTF 2021. Official write-ups for all the challenges can be found here. Forensics 1. Retro! Very simple one to begin with, just extract the EXIF data for the flag

Ctf

4 min read

DUCTF 2021 Write-ups
DUCTF 2021 Write-ups
Nisarg Suthar

Nisarg Suthar

DFIR & CySec Aficionado.

Following
  • Mike Cohen

    Mike Cohen

  • Syed Hasan

    Syed Hasan

  • David Schiff

    David Schiff

  • dr3ad_0X1

    dr3ad_0X1

  • Mahmoud S. Soheem

    Mahmoud S. Soheem

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Knowable