Clear it in 3 steps
-
Start the environment
-
Investigate the target
-
Submit the flag
Analyze the SYSTEM file to retrieve connected USB device information and the hidden flag. Learn the basics of Windows forensics. Provided file: SYSTEM
USB history is stored in SYSTEM\\CurrentControlSet\\Enum\\USBSTOR
Search USB history with strings SYSTEM | grep -i USBSTOR
Check hidden data with grep KINOCO SYSTEM