La gazette de Windows

intro forensics windows logs FCSC 2023 solved on

Description

It seems that there is user running a suspicious Powershell scripts on his machine. Fortunately, loggins is turned on on that machine and we were able to retrieve the Powershell event log. Find out what has been sent to the attacker.

Files

Author

ribt

Flag

Share my success on Fediverse, Twitter, Linkedin, Facebook, or via email.

Submit your solution

You can submit your writeup for this challenge. Read the FAQ to learn how to proceed.

You need to be logged in to submit a writeup.

Writeups

I've been looking for a long time and I still can't find the flag!

You can vote for the solutions you prefer by using the on their respective pages.

DateAuthor Language Tags Vote
2024-02-18
pioueo
🇫🇷
2024-02-19
404fafnir
🇫🇷