Clear it in 3 steps
-
Start the environment
-
Investigate the target
-
Submit the flag
Analyze the process list recorded in memory.dump and find the flag contained in the suspicious process name. Learn the basics of memory forensics. Provided file: memory.dump
Extract readable strings with strings memory.dump
Check the process list with grep -i process memory.dump
Look for a suspicious process name containing KINOCO