Clear it in 3 steps
-
Start the environment
-
Investigate the target
-
Submit the flag
capture.bin is generated from the FLAG injected at startup. Parse KBIN TLV records and XOR-decode type 0x42 with 0x5A to recover the flag.
Inspect capture.bin and identify the target record
parse KBIN TLV records and XOR-decode type 0x42 with 0x5A
Verify that the reconstructed value has FLAG{...} format