Blog
Writeups
Step-by-step breakdowns of forensic CTF challenges and real investigations.
Bhackari CTF 2026
Writeups Bhackari CTF 2026 Easy
Gianbruno's Clicker
Bhackari CTF forensics on Gianbruno's seized PC: one flag hides in a base64-encoded filename inside the .minecraft folder, the second is painted into the autoclicker GUI bitmap embedded in the PE.
#forensics#ntfs#prefetch
Writeups Bhackari CTF 2026 Medium
Gianbruno's Injection Client
Bhackari CTF: the Titan Launcher on Gianbruno's disk is a red herring. The real Minecraft injection client is xproc64.exe hiding in System32. Part 1 reads the flag from its PE version info; Part 2 reverses the Rust binary to recover the XOR/AES-protected payload it injects.
#forensics#reversing#rust