CTF link.
We found out a user account has been compromised on our network. We took a packet capture of the time that we believe the remote login happened. Can you find out what the username of the compromised account is?
Flag format: swampCTF{
username
}
If we examine the .pcap file in network miner, we can access Credential information.

We see that the username is adamkadaban.
swampCTF{adamkadaban
}