Specific Ducky
MediumDigital Forensics
Overview
A suspicious USB device triggered an automated PowerShell payload on an employee workstation, but the malware never fully executed. Analyze the captured USB traffic, recover the injected commands, and trace the hidden infrastructure the payload attempted to contact.
Flag format: flag{*****************.******.**}
Job Positions
Digital Forensics Analyst
Tags
WiresharkPacket CaptureNetwork ForensicsUsb Device HistoryOs Artifacts