24/7 ONLINE · 09:00–00:00◆Hacettepe Teknokent / Ankara
+90 536 662 38 09[email protected]
DSETDoğanay Siber Emniyet
  • Services
  • Academy
  • Simulator
  • Blog
    BlogArticles · technical write-ups · guidesAnnouncementsLatest DSET news · bulletinsVideo GalleryTraining · demos · cyber security videos
  • About Us
    About UsThe DSET story · vision · teamSimulators and ToolsFree interactive calculators, simulators and diagnosis wizardsSector SolutionsFinance · Healthcare · Public Sector · E-Commerce · 7 industriesReference CasesReal DSET cases · industry outcomesSite SearchAll content · articles · services · casesFrequently Asked QuestionsCommon questions · quick answersContactPhone · WhatsApp · address · form
  • Tracking System
    Customer LoginAccount dashboard · request trackingForensics RequestDigital evidence · examination requestData Recovery RequestDisk · RAID · recovery requestPrice CalculatorATK 2026 reference · 9 services
KAOS
TREN
DSETCustomer Panel

Sign in to your account

Request tracking, quote approval and your history in one panel.

Loading security verification...
DSET Customer Panel AES 256 GCM encrypted session
DSET AI
AF-4DFB-BOSS · Amiral Vaka / Hacker

The Suspect's Machine Is a Hacker's

DOWNLOADABLE flagship case image (8 MiB). The suspect is a threat actor: heavy noisy logs, offensive tool traces, deliberate misleading trails. The real evidence is encrypted; the key leaked in the swapfile (cross-artifact). Investigation questions: who, what, how, which tool, which anti-forensics. Do not fall for the planted false trails.

Scenario

A threat actor's seized machine. The bash history holds hundreds of commands, multiple identities, a VPN/Tor chain and red-herring traffic; offensive tool traces (credential dumping, network scanning, SQL injection) and anti-forensics commands (timestamp forgery, log destruction) are visible. The real operation is hidden: the C2 configuration is SHA256-CTR encrypted and its key fell into the swapfile region (cross-artifact: first take the key from swap, then decrypt the config). The decrypted config gives the real C2 server and the exfil target. The disk also holds a deliberately planted fake C2 and fake victim list (honeypot/misdirection). Skill: extracting the real operation from the haystack; reaching the encrypted evidence; not reporting the planted false trail as real (soundness). Questions are MITRE ATT&CK oriented: the credential-dumping tool used, the anti-forensics technique.

Anti-forensics techniques

  • Log noise + multiple identities + Tor/VPN (haystack)
  • Planted false trail (honeypot c2 + fake victim list)
  • Encrypted evidence + cross-artifact (key in swap)
  • Anti-forensics: timestomp + log destruction (shred)

Provided artifacts

  • Raw disk image (8 MiB; history + swap + encrypted config + planted decoy)

Sample questions

  1. q1: The real C2 server address? (from the encrypted config)
  2. q2: The actual exfiltration target?
  3. q3: The credential-dumping tool used? (MITRE T1003)
  4. q4: The anti-forensics technique used?
  5. trap1: Do NOT report the planted fake C2 / fake victim list as real.

Soundness trap

The disk holds a deliberately planted fake C2 (10.10.10.10) and fake victim list; reporting them as real is heavily penalized. The real C2 and exfil target are found only by decrypting the encrypted config with the key from swap.

Scoring

Cross-artifact investigation accuracy (C2+exfil+TTP) + planted-trail decoy resistance (soundness).

DOWNLOADABLE

Download and solve

Download artifact

The answer key is hidden (scored set); the flag is encrypted, you must decrypt it.

Solve in your browser

DSETDoğanay Siber Emniyet

Digital Forensics · Data Recovery · Cyber Security · Information Security · Technical Examination · Expert Opinion · KVKK & GDPR Compliance · Digital Transformation Consulting · advanced training programs offered by DSET Academy.

+90 536 662 38 09[email protected]Hacettepe Teknokent · Üniversiteler Mah. 1596. Cad. 6. AR-GE Blokları C Blok No:6C Z.Kat · Beytepe · Çankaya · ANKARAOur Google Business Profile7/24 Online · 09.00 → 00.00 · Pazartesi · Pazar

Our Services

  • Digital Forensics
  • Data Recovery
  • KAOS Local Artificial Intelligence
  • Cyber Security
  • KVKK-GDPR Consultancy
  • DSET Academy
  • Incident Simulator & Threat Heatmap
  • Website Security
  • Information Security
  • Adli Bilişim Benchmark'ı

Support & Help

  • About Us
  • Price Calculator
  • Frequently Asked Questions
  • Contact
  • EU AI Act Article 4 Guide
  • Sector Solutions
  • KVKK Disclosure Statement
  • GDPR · EU Data Rights
  • Privacy Policy
  • Cookie Policy
  • Terms of Service

Quick Links

  • Solutions
  • DFB Benchmark
  • Blog
  • Video Gallery
  • DSET Academy
  • Case Simulator
  • Reference Cases
  • Site Search
  • DSET AI Assistant
  • Digital Forensics Request Form
  • Data Recovery Request Form
  • Customer Login

Ecosystem

  • Hacettepe Teknokent
  • Cyber Security Cluster
  • USOM · National Cyber Incident Response
  • KVKK Authority
  • llms.txt
© 2026 dset.com.tr · Doğanay Siber Emniyet Teknolojileri · All rights reserved.
“Kalite asla tesadüf değildir...”
TREN
← Catalog
Privacy
KVKK
GDPR
Cookies
Terms