Clear it in 3 steps
-
Start the environment
-
Investigate the target
-
Submit the flag
capture.txt is generated from the FLAG injected at startup. Select flow=exfil payload_hex and XOR-decrypt with 0x5A to recover the flag.
Inspect capture.txt and identify the target record
select flow=exfil payload_hex and XOR-decrypt with 0x5A
Verify that the reconstructed value has FLAG{...} format