24/7 ONLINE · 09:00–00:00◆Hacettepe Teknokent / Ankara
+90 536 662 38 09[email protected]
DSETDoğanay Siber Emniyet
  • Services
  • Academy
  • Simulator
  • Blog
    BlogArticles · technical write-ups · guidesAnnouncementsLatest DSET news · bulletinsVideo GalleryTraining · demos · cyber security videos
  • About Us
    About UsThe DSET story · vision · teamSimulators and ToolsFree interactive calculators, simulators and diagnosis wizardsSector SolutionsFinance · Healthcare · Public Sector · E-Commerce · 7 industriesReference CasesReal DSET cases · industry outcomesSite SearchAll content · articles · services · casesFrequently Asked QuestionsCommon questions · quick answersContactPhone · WhatsApp · address · form
  • Tracking System
    Customer LoginAccount dashboard · request trackingForensics RequestDigital evidence · examination requestData Recovery RequestDisk · RAID · recovery requestPrice CalculatorATK 2026 reference · 9 services
KAOS
TREN
DSETCustomer Panel

Sign in to your account

Request tracking, quote approval and your history in one panel.

Loading security verification...
DSET Customer Panel AES 256 GCM encrypted session
DSET AI
AF-3DFB-RAM · Bellek / RAM

Ghost Process in Memory

DOWNLOADABLE raw RAM image (2 MiB). Dozens of credentials in memory but most are harmless cache (decoy). Correlate to find the malicious process (svchost masquerade) and the real credential it used to exfiltrate.

Scenario

A workstation memory dump. Cached, LSA and WiFi credentials are scattered in memory; most are old and harmless (decoy). A malicious process, with a name imitating svchost.exe (a homoglyph), runs from C:\Users\Public, sends data to a C2 via HTTP-POST and exfiltrates a service account. Skill: not reporting a random pwd=, but correlating the credential in the exfiltrating process's context. Mistaking a cached credential for real evidence breaks soundness.

Anti-forensics techniques

  • Process masquerade (homoglyph of svchost)
  • Noise: many harmless cached credentials (decoy)
  • Plaintext credential + C2 trace in memory

Provided artifacts

  • Raw RAM image (2 MiB)

Sample questions

  1. q1: Name of the malicious process? (masquerade)
  2. q2: Password used for exfiltration?
  3. q3: Exfiltration (C2) destination IP?
  4. trap1: Do NOT report the cached harmless credential (Welcome1) as the exfil evidence.

Soundness trap

Cached credentials in memory (Welcome1, Spring2025!) look real but are unrelated to the exfil; presenting one as evidence is heavily penalized. The real evidence is only the credential in the malicious process's C2 context.

Scoring

Process-credential correlation accuracy + cache-decoy resistance (soundness).

DOWNLOADABLE

Download and solve

Download artifact

The answer key is hidden (scored set); the flag is encrypted, you must decrypt it.

Solve in your browser

DSETDoğanay Siber Emniyet

Digital Forensics · Data Recovery · Cyber Security · Information Security · Technical Examination · Expert Opinion · KVKK & GDPR Compliance · Digital Transformation Consulting · advanced training programs offered by DSET Academy.

+90 536 662 38 09[email protected]Hacettepe Teknokent · Üniversiteler Mah. 1596. Cad. 6. AR-GE Blokları C Blok No:6C Z.Kat · Beytepe · Çankaya · ANKARAOur Google Business Profile7/24 Online · 09.00 → 00.00 · Pazartesi · Pazar

Our Services

  • Digital Forensics
  • Data Recovery
  • KAOS Local Artificial Intelligence
  • Cyber Security
  • KVKK-GDPR Consultancy
  • DSET Academy
  • Incident Simulator & Threat Heatmap
  • Website Security
  • Information Security
  • Adli Bilişim Benchmark'ı

Support & Help

  • About Us
  • Price Calculator
  • Frequently Asked Questions
  • Contact
  • EU AI Act Article 4 Guide
  • Sector Solutions
  • KVKK Disclosure Statement
  • GDPR · EU Data Rights
  • Privacy Policy
  • Cookie Policy
  • Terms of Service

Quick Links

  • Solutions
  • DFB Benchmark
  • Blog
  • Video Gallery
  • DSET Academy
  • Case Simulator
  • Reference Cases
  • Site Search
  • DSET AI Assistant
  • Digital Forensics Request Form
  • Data Recovery Request Form
  • Customer Login

Ecosystem

  • Hacettepe Teknokent
  • Cyber Security Cluster
  • USOM · National Cyber Incident Response
  • KVKK Authority
  • llms.txt
© 2026 dset.com.tr · Doğanay Siber Emniyet Teknolojileri · All rights reserved.
“Kalite asla tesadüf değildir...”
TREN
← Catalog
Privacy
KVKK
GDPR
Cookies
Terms