How the swarm works a case, told from the record.
Long reads on single runs: what the agents decided in the first minutes, what they called themselves, which tools they reached for and what those tools gave back, where they argued, what they found and what they missed. Every claim in a post points at the board, the ledger, the trace or a sealed job output. The answers to public challenges stay out of these pages; the methods are all here.
The hardest cases, run by run.
Run notes · Bogus Bill: the key to the laptop was on the phoneBelkaCTF 6, worked by the swarm across an iPhone and a Windows laptop: a vault opened with a key found in a note on the phone, a cropped bank screenshot rebuilt from what the crop left behind, a phone Shortcut's cipher re-implemented to read a secret channel, and the questions it did not answer.
Run notes · Encrypt Them All: the keys never touched a command lineAli Hadi's Encrypt Them All, worked by the swarm: a rush for the same seat, a BitLocker volume opened by learning from each failed attempt, secrets passed by reference and never printed, and a critic that signed exact hashes.
Run notes · Meeting Location: the case was in the free spaceAli Hadi's Meeting Location challenge, worked by the swarm with every agent in a tool-less microVM and every heavy step a sealed job: a sweep of the whole free space, a clock that ran backwards, an argument about who did what, and a password nobody found.
Every earlier run has its write-up beside its record.
Before this blog, each run was written up in the repository next to its board, its ledger and its trace. They stay there, and they are listed here with what each case asked. The case ledger has the figures for every one of them.
- BelkaCTF 6, Bogus Bill
A cashier takes a counterfeit fifty. From the suspect's iPhone and his laptop, identify the owner, his conspirators, the print lab, the printer, the designer, the batch timings, the ATM he tested on, the offshore bank and his statement.
- BelkaCTF 6, Bogus Bill, first run
The same eighteen tasks, on the same two images, with the swarm started from the console rather than a terminal.
- Web server, third run
Given a disk image and a memory image of a breached Windows web server, work out what was done, what was added, what was installed, what shellcode was used, and build the timeline. Eight questions and a bonus.
- Web server, second run
The same eight questions and bonus, on the same evidence, against a rebuilt harness.
- Web server, first run
The first case the swarm ever worked: a breached Windows web server, eight questions and a bonus.
- Web server, on a Linux server
The same case, on a rented Linux server over SSH, with no desktop and none of the macOS guards.
- Where did the administrator go
A domain administrator's files are gone and nobody knows what happened. Find out what happened to this system, and how.
- Meeting location
A first investigation found nothing. Find what the suspect uses to hide his activity, restore those methods and tools, and then find where the meeting is.
- Encrypt them all
Three encryption puzzles on one machine: an encrypted document with no known password, a BitLocker volume, and a key pair with a file encrypted to it.
- NTFS hidden files
Five things were hidden on this volume using the file system itself. Find all five and explain how each was hidden.
- SysInternals
The user downloaded what they thought was a well-known tool suite, double-clicked it, and nothing opened. Since then the machine has been slow. Work out what happened, and when.
- Browser policy violation
An internal investigation for human resources. They believe an employee is using a web browser that does not comply with policy.
- BSides Amman workshop image
A system used for illegal activity. Two accounts are suspects. Sixteen questions, and every answer needs the command and its output quoted.
- Alternate data streams
An image prepared to test hiding executables in file system streams, running them from there, whether the antivirus scans them, and how every one of those can be detected.
- Mystery hacked system
An employee found a message written in a file on their system and reported it. Find out how the system was hacked, and prove it.
- User policy violation
A workstation image. Find the policy violation and prove it.
- The attacker's own machine
The only disk in the set that belongs to the attacker rather than a victim. Reconstruct what was done: the tools, the targets, the loot and the timeline.
- Compromised Hadoop cluster
Three disk images from one cluster, a master and two slaves. Answer each question per machine.
- Compromised Linux web server
The first non-Windows image in the set. Find how the actor got in, what was modified, and what persistence was left.
- RansomCare
Two memory dumps of machines hit by ransomware. No disk, no file system, nothing to carve. Find the ransomware's code, dump it, and explain what happened to the victim.
- Malware in unallocated space
A system was compromised and the only evidence left is its unallocated disk space. No partition table, no file system, and a catalog that came back empty.