General Skills Level 5 300 points

Anti-Forensics - Evidence Elimination

Mission

After intrusion the attacker tried to cover their tracks, truncating part of `/challenge/auth_syslog.log` and clearing shell history -- but traces remain. Find the unnatural time gap in the primary log, then match it against the recovered systemd journal in `/challenge/journal_recovered.txt`; the single entry that falls inside that window records the erased activity and holds the flag. This is a read-only analysis showing that anti-forensics leaves traces in secondary sources.

#anti-forensics#log-deletion#stealth#evasion

Clear it in 3 steps

Not started
  1. Start the environment

  2. Investigate the target

  3. Submit the flag