Clear it in 3 steps
-
Start the environment
-
Investigate the target
-
Submit the flag
Recovered files sit under `/challenge/evidence/`. Analyze the metadata (Exif / docProps) across the photos (`IMG_*.jpg`) and Office documents, and identify the single file whose tag is not an ordinary application name but the identifier string of a personal export tool that embeds the flag. The many normal metadata entries are decoys.
Systematically extract metadata (EXIF, docProps) from every file in /challenge/evidence/
One photo's Software tag (or one document's author) holds an unusual value
The flag is embedded in that single metadata value