Deobfuscation of a NetWalker sample.
Deobfuscation | Triage
This sample has several decoder functions, adds a number of types using C# and imports a set of functions from kernel32.dll many of you will recognise.
In order to analyse the sample, I perform the following tasks:
A beginner level CTF focussing on forensics, delivered to the British Armed Forces as part of an Army wide event.
Hunt | Learn
I designed and created these evidences to train DFIR specialists in the British Army.
Available to download, including:
The questions are designed to guide a beginner through their investigation. Can you identify the indicators of compromise and attribute the attacker's actions on the compromised machine?