2HWAمنتخب القهوة

Tick Tock

Forensicsbeginner-friendly

An employee's workstation was flagged after unusual outbound network activity was detected by the organization's monitoring systems. Initial Investigation revealed that a malicious executable had been executed on the host. Investigators managed to acquire a copy of the system's registry, before the machine was reimaged as part of the remediation process. Your task is to examine the provided registry hives and determine how the attacker maintained their presence on the system.

Author(s)
Date

July 24, 2026

Writeup Pending

Challenge files and resources are available for download above. An official writeup has not been published yet.

Other challenges from EYCC CTF 2026