Clear it in 3 steps
-
Start the environment
-
Investigate the target
-
Submit the flag
cloud_inventory.json and approved.json are generated from the FLAG injected at startup. Verify forensic-reader's s3:GetObject path and URL-safe-Base64-decode parts to recover the flag.
Inspect cloud_inventory.json and approved.json and identify the target record
verify forensic-reader's s3:GetObject path and URL-safe-Base64-decode parts
Verify that the reconstructed value has FLAG{...} format