SwampCTF 2024 Forensics: Notoriously Tricky Login Mess (Part 1) Writeup

CTF link.

We found out a user account has been compromised on our network. We took a packet capture of the time that we believe the remote login happened. Can you find out what the username of the compromised account is?

Flag format: swampCTF{username}

If we examine the .pcap file in network miner, we can access Credential information.

We see that the username is adamkadaban.

Aleyna Doğan
Aleyna Doğan

I'm Aleyna Doğan, a Senior Cyber Threat Intelligence Analyst specializing in cyber threat intelligence, OSINT investigations, and digital risk monitoring. This blog is where I share hands-on cybersecurity content, including TryHackMe writeups, PortSwigger labs, and practical learning resources.

Articles: 150

Leave a Reply

Your email address will not be published. Required fields are marked *