kali@kali: ~/hackerverse-dfir — Terminal
[ EC-Council Hackerverse CTF — DFIR Writeup ]
cat README.md
Event : EC-Council Hackerverse CTF — Digital Forensics & Incident Response (DFIR)
Participant: Asahel Kipkemei
Level : Journeyman
Issued : 3rd Oct 2026 | CPE Credits: 1 | Certificate No.: 1998
Platform : EC-Council lab (Kali Linux + Windows Forensic VM)
Sections : 1) Cryptic Canvas 2) Network Forensics (Synixon) 3) Autopsy / Chrome / LSASS 4) Ransomware
display certificate.png
kali@kali: ~/Stego Artifacts
[1] Level 1 — Cryptic Canvas
# Challenge 1 — The Hidden Voice (Audio.wav)
file Audio.wav; exiftool Audio.wav; strings Audio.wav | head -30
Audio.wav: RIFF (little-endian) data, WAVE audio, Microsoft PCM, 8 bit, mono 11050 Hz
# Uploaded the WAV to an online Morse audio decoder (adaptive). Output used only two symbols:
# ----- = 0 and .---- = 1 → the Morse was a carrier for a binary stream.
echo "0110011001101100011000010110011101111011...01111101" | perl -lpe '$_=pack("B*",$_)'
Flag: flag{binary_audio_secrets} (6-5-7 letters, matches flag{xxxxxx_xxxxx_xxxxxxx})
# Challenge 2 — JFIF magic bytes (Cat.jpg)
Answer: FF D8 FF E0 # FF D8 = SOI, FF E0 = APP0 → "JFIF"
binwalk -e Cat.jpg
Extractor Exception: ... use '--run-as=root'
steghide extract -sf Cat.jpg
steghide: the file format of the file "Cat.jpg" is not supported.
file Cat.jpg; exiftool Cat.jpg
Cat.jpg: data
Error : File format error # header corrupted → repair a COPY
cp Cat.jpg Cat_fixed.jpg && chmod u+w Cat_fixed.jpg
printf '\xff\xd8\xff\xe0' | dd of=Cat_fixed.jpg bs=1 seek=0 conv=notrunc
printf '\x4a\x46\x49\x46\x00' | dd of=Cat_fixed.jpg bs=1 seek=6 conv=notrunc
file Cat_fixed.jpg
steghide extract -sf Cat_fixed.jpg
Enter passphrase: (now prompts → valid JPEG with embedded data)
wrote extracted data to "flag.txt".
cat flag.txt | base64 -d
flag.txt : Q1RGe3N0ZWcwXzFzX2NvMGx9
Flag : CTF{steg0_1s_co0l}
# Challenges 4 & 5 — Encoded_Dump.txt (decoys + real secret)
cat Encoded_Dump.txt
Hint 1 (b64 → reversed) : ".eno tsuj si eurt ,syoced era owT" → two strings are decoys
Hint 2 (b64) : Process: Base58 → ROT13 → BASE64 → XOR (Hex Key: 342120)
Challenge 4 answer: Base58 → ROT13 → Base64 → XOR (Hex Key: 342120)
python3 -c "import base58,base64,codecs;b=base58.b58decode('2A6fz3V1RQkk4RgpctzF5bPYFCaCXsLLb7Jxot4');r=codecs.decode(b.decode(),'rot13');d=base64.b64decode(r);k=bytes.fromhex('342120');print(bytes(c^k[i%3] for i,c in enumerate(d)).decode())"
pz1up1c2KJWHr1A5IJWVsHE2HJIq → cm1hc1p2XWJUe1N5VWJIfUR2UWVd → rmasZv]bT{SyUbH}DvQe] →
Challenge 5 flag: FLAG{ViCtOrYaChIeVeD}
# CyberChef equivalent: From Base58 → ROT13 → From Base64 → XOR (Hex 342120)
kali@kali: ~/Pcap Artifacts
[2] Network Forensics — Synixon ChatOps breach
# synixon_breach_capture.pcapng, exported as plain-text dissections. Attacker: 10.10.1.2 → Victim: 10.10.1.111
tshark -r synixon_breach_capture.pcapng -Y http.request -T fields -e frame.number -e ip.src -e http.request.method -e http.host -e http.request.uri
tshark -r synixon_breach_capture.pcapng -Y websocket -T fields -e frame.number -e ip.src -e text
tshark -r synixon_breach_capture.pcapng -q -z follow,tcp,ascii,N # reverse-shell stream
| # | Question | Answer | Evidence (frame) |
| 1 | Attacker signup email | [fill in from POST body] | POST / (236, 303) — form body not in export |
| 2 | Supervisor email reset via WebSocket | [fill in from WS text] | WebSocket frames 422–476, 570–573 (port 5000) |
| 3 | LFI debug page | debug-view.php | 1164 /syni_dev/debug-view.php, 1168 ?file=history.php |
| 4 | Log file read via LFI | legacy_dev_keys.log | 1186 ?file=../../../../../../../opt/syni_dev/legacy_dev_keys.log (1176 read /etc/passwd) |
| 5 | New admin account email | [fill in from POST / WS] | Check POSTs 1312, 1631, 1901+ and WS 1259–1286 |
| 6 | New web service port | 17645 | 1321 onward, 10.10.1.2 → 10.10.1.111:17645 |
| 7 | Hidden admin login page | admin_login_ERHG23W2.php | 1597 GET, 1631 POST, 1635 dashboard |
| 8 | Legacy feedback service port | 5000 | 1826 GET /legacy-feedback on :5000 |
| 9 | Reverse-shell callback | 10.10.1.2:8998 | 2249–2251 (victim connects out to attacker :8998) |
| 10 | Root flag | flag{A1EL2L8P} | 2299 / 2307 — cat /home/flag.txt |
Shell session replayed: whoami (typo "whomai" → /usr/bin/whoami → root) → find / -name flag.txt (first typo'd as /usr/bind/find) → /home/flag.txt → cat.
Note: rows 1, 2 and 5 live in HTTP/WebSocket bodies that the text export collapsed; pull them with the tshark commands above.
kali@kali: ~/chrome_cracker
[3] Autopsy — Chrome + LSASS (chaincrypto.com)
# Guidance taken from the chat.deepseek.com session. Tools on the Windows Forensic VM: Autopsy 4.21.0, FTK Imager, x32dbg/x64dbg, Wireshark, Sysinternals.
unzip chrome_cracker.zip # right-click → Extract All on the VM Desktop
lsass.DMP | Chrome profile (User Data / Default)
# Autopsy: New Case → Add Data Source → Logical Files → select the extracted chrome_cracker folder → ingest.
| # | Question | Method / answer |
| 1 | Tool used to extract MasterKey from lsass.DMP | Suggested by DeepSeek: pypykatz (DPAPI masterkey parsing from minidump) — mimikatz is the alternative. Confirm against your submitted answer. |
| 2 | File holding Base64 encrypted_key | Local State (JSON in Chrome User Data) |
| 3 | Attacker's Windows username | Autopsy file tree → C:\Users\<username>\AppData\Local\Google\Chrome\User Data\ — the folder name. [record value] |
| 4 | First 10 chars of MasterKey | pypykatz lsa minidump lsass.DMP (dpapi section) → masterkey hex, first 10 chars. [record value] |
| 5 | First 10 chars of Final Secret Key | Base64-decode encrypted_key (strip "DPAPI" prefix), decrypt with the MasterKey → AES key. [record value] |
| 6 | Username / password for chaincrypto.com | Open Login Data (SQLite, logins table) → decrypt password blob with AES-GCM using the Final Secret Key. [record value] |
Challenges 3 and 4 (username → MasterKey) are the pivot: the username locates the profile, and the MasterKey unlocks challenges 5 and 6.
Values for rows 3–6 were not part of the chat, so they are left for you to fill in from your lab output.
kali@kali: ~/ransomware
[4] Ransomware challenge
NOT SOLVED. I was unable to solve the final question on the ransomware challenge. No flag or answer was recovered for it, and none is claimed in this writeup.
kali@kali: ~/hackerverse-dfir — summary
cat tools_used.txt
Kali: file, exiftool, strings, xxd, dd, printf, binwalk, steghide, perl, python3 (base58), tshark, Wireshark
Online/other: Morse audio decoder, CyberChef
Windows VM: Autopsy 4.21.0, pypykatz (suggested), SQLite viewer
Lessons: broken magic bytes defeat stego tools — repair a copy first; "unsupported format" is itself a clue; always follow TCP streams for reverse shells.
exit