Clear it in 3 steps
-
Start the environment
-
Investigate the target
-
Submit the flag
Do not use a Kubernetes API, host mount, privileged container, or escape. Read the static privileged-mount audit and recover the flag from mount-review evidence.
Inspect artifacts/k8s/privileged-mount-audit.txt
Find payload_b64 on the mount-review record
Base64-decode the value