Clear it in 3 steps
Start the environment
Investigate the target
Submit the flag

An attacker enumerating SMB shares on the network was captured. Download the packet capture (traffic.pcap), follow the SMB (TCP/445) traffic, and extract the flag leaked in a file listing/read.
Follow the SMB (TCP/445) traffic in traffic.pcap; you can see share and file enumeration
The Public and backup shares are decoys; focus on credentials.txt in the IT share
Extract tcp.payload and read the strings; the flag is inside the READ Response