Signcraft
MediumMalware Reverse Engineering
Overview
Our forensics team received information that there are hidden signs in this save file, in all direction within a range of 100 chunks. Will you be able to retrieve the flag?
The game is NOT required
Lab Details
Prerequisites & Requirements
- Python Scripting: Intermediate proficiency, particularly with nested data structures and library integration.
- Data Structures: Basic understanding of hierarchical binary formats (NBT) and 3D coordinate systems.
- Research Skills: Ability to navigate and implement poorly documented APIs or third-party libraries.
What will you learn?
- Digital Forensics: Identify and parse proprietary game save structures to locate hidden artifacts.
- NBT Analysis: Use NBT viewers to reverse-engineer data schemas and object hierarchies.
- Automated Data Mining: Develop scripts to programmatically iterate through massive 3D datasets (chunks/blocks) to extract specific entity metadata.
Tools
- Amulet-Core: A Python library for interacting with Minecraft’s world data.
- WebNBT: A web-based explorer for Named Binary Tag (NBT) files.
Job Positions
Digital Forensics Analyst
Tags
Static AnalysisMalware AnalysisTriageSteganographyStrings