Analyse mémoire - Pour commencer (2/2)

intro forensics windows memory FCSC 2025 solved on

Description

The memory dump was taken while a user was working on a highly sensitive document. If the workstation was compromised, this document may have been stolen. Can you find:

  • the name of the document editing software,
  • the name of the document.

The flag is in the format FCSC{<software name>:<document name>} where:

  • <software name> is the name of the editing software’s executable, and
  • <document name> is the name of the document being edited by the user (without the file path).

For example: FCSC{calc.exe:My accounts 2025.txt}.

Files

Author

haxom

Flag

Share my success on Fediverse, Twitter, Linkedin, Facebook, or via email.

Submit your solution

You can submit your writeup for this challenge. Read the FAQ to learn how to proceed.

You need to be logged in to submit a writeup.

Writeups

I've been looking for a long time and I still can't find the flag!

You can vote for the solutions you prefer by using the on their respective pages.

DateAuthor Language Tags
2025-05-02
Cyrhades
🇫🇷