All Writeups
Comprehensive collection of CTF challenges, solutions, and insights.
DEADROP Network 6 - OPERATION NIGHTJAR
A single PCAP containing a complete attack kill chain, reconnaissance, exploitation, C2 establishment, lateral movement, data staging, and exfiltration. Each stage requires a different analysis technique. Read the whole story from first SYN to final exfil packet.
DEADROP Network 3 - TLS Session
A TLS-encrypted PCAP paired with a session key log file. Load both into Wireshark to decrypt the traffic and recover the flag from the plaintext HTTP response.
DEADROP Network 2 - DEADROP C2
A PCAP containing DNS exfiltration traffic where the flag is split across hex-encoded subdomain labels in a series of TXT queries. Extract and reassemble the labels in sequence to reconstruct and decode the flag.
DEADROP Network 1 - Breach Traffic
A PCAP containing FTP traffic with credentials and file transfers sent in plaintext. Follow the TCP stream in Wireshark to extract the flag directly.
WHAMazon! Network 2 - The AI gets mixed up when you rev it
Decrypting TLS traffic in Wireshark using a provided pre-master secret log, then following the TLS stream to find a base64-encoded flag in captured shell session output.