Clear it in 3 steps
-
Start the environment
-
Investigate the target
-
Submit the flag
Perform custom Linux-kernel memory-profile matching with a safe static fixture. Match the BUILD_ID records in vmlinux, custom_kernel.dump, and profile.json, then analyze the matching symbol-profile record. No real memory dump or Volatility is required.
Check BUILD_ID in evidence/vmlinux
Match it with required_build_id in custom_kernel.dump
Decode linux_pslist_b64 from the matching profile.json