Clear it in 3 steps
-
Start the environment
-
Investigate the target
-
Submit the flag
Do not use AWS credentials, a metadata endpoint, or Lambda. Analyze the local simulated CloudTrail chain and recover the flag from the artifact-recovery event.
Inspect artifacts/aws/cloudtrail-chain.jsonl
Find the JSON line whose event is artifact-recovery
Base64-decode payload_b64