Specific Ducky

MediumDigital Forensics

Overview

A suspicious USB device triggered an automated PowerShell payload on an employee workstation, but the malware never fully executed. Analyze the captured USB traffic, recover the injected commands, and trace the hidden infrastructure the payload attempted to contact.

Flag format: flag{*****************.******.**}

Job Positions

Digital Forensics Analyst

Tags

WiresharkPacket CaptureNetwork ForensicsUsb Device HistoryOs Artifacts