Clear it in 3 steps
-
Start the environment
-
Investigate the target
-
Submit the flag
An attacker enumerating SMB shares on the network was captured. Download the packet capture (traffic.pcap), follow the SMB (TCP/445) traffic, and extract the flag leaked in a file listing/read.
Follow the SMB (TCP/445) traffic in traffic.pcap; you can see share and file enumeration
The Public and backup shares are decoys; focus on credentials.txt in the IT share
Extract tcp.payload and read the strings; the flag is inside the READ Response