Blog

How the swarm works a case, told from the record.

Long reads on single runs: what the agents decided in the first minutes, what they called themselves, which tools they reached for and what those tools gave back, where they argued, what they found and what they missed. Every claim in a post points at the board, the ledger, the trace or a sealed job output. The answers to public challenges stay out of these pages; the methods are all here.

New posts arrive in the Atom feed, and every post is also published as Markdown for anyone, or any agent, that wants the text without the page.
Earlier cases, on the record

Every earlier run has its write-up beside its record.

Before this blog, each run was written up in the repository next to its board, its ledger and its trace. They stay there, and they are listed here with what each case asked. The case ledger has the figures for every one of them.

  • BelkaCTF 6, Bogus Bill21 September 2026 · s83fd

    A cashier takes a counterfeit fifty. From the suspect's iPhone and his laptop, identify the owner, his conspirators, the print lab, the printer, the designer, the batch timings, the ATM he tested on, the offshore bank and his statement.

  • BelkaCTF 6, Bogus Bill, first run20 September 2026 · s821c

    The same eighteen tasks, on the same two images, with the swarm started from the console rather than a terminal.

  • Web server, third run18 September 2026 · sf4b2

    Given a disk image and a memory image of a breached Windows web server, work out what was done, what was added, what was installed, what shellcode was used, and build the timeline. Eight questions and a bonus.

  • Web server, second run18 September 2026 · sf6df

    The same eight questions and bonus, on the same evidence, against a rebuilt harness.

  • Web server, first run18 September 2026 · s2cb9

    The first case the swarm ever worked: a breached Windows web server, eight questions and a bonus.

  • Web server, on a Linux server21 September 2026 · s3096

    The same case, on a rented Linux server over SSH, with no desktop and none of the macOS guards.

  • Where did the administrator go18 September 2026 · sb6b3

    A domain administrator's files are gone and nobody knows what happened. Find out what happened to this system, and how.

  • Meeting location18 September 2026 · s5d10

    A first investigation found nothing. Find what the suspect uses to hide his activity, restore those methods and tools, and then find where the meeting is.

  • Encrypt them all18 September 2026 · s864a

    Three encryption puzzles on one machine: an encrypted document with no known password, a BitLocker volume, and a key pair with a file encrypted to it.

  • NTFS hidden files18 September 2026 · sfcc3

    Five things were hidden on this volume using the file system itself. Find all five and explain how each was hidden.

  • SysInternals18 September 2026 · sd1d1

    The user downloaded what they thought was a well-known tool suite, double-clicked it, and nothing opened. Since then the machine has been slow. Work out what happened, and when.

  • Browser policy violation18 September 2026 · s8810

    An internal investigation for human resources. They believe an employee is using a web browser that does not comply with policy.

  • BSides Amman workshop image18 September 2026 · s2f66

    A system used for illegal activity. Two accounts are suspects. Sixteen questions, and every answer needs the command and its output quoted.

  • Alternate data streams18 September 2026 · sbe18

    An image prepared to test hiding executables in file system streams, running them from there, whether the antivirus scans them, and how every one of those can be detected.

  • Mystery hacked system18 September 2026 · s9f20

    An employee found a message written in a file on their system and reported it. Find out how the system was hacked, and prove it.

  • User policy violation18 September 2026 · s0ae9

    A workstation image. Find the policy violation and prove it.

  • The attacker's own machine18 September 2026 · s9da9

    The only disk in the set that belongs to the attacker rather than a victim. Reconstruct what was done: the tools, the targets, the loot and the timeline.

  • Compromised Hadoop cluster18 September 2026 · s9a5f

    Three disk images from one cluster, a master and two slaves. Answer each question per machine.

  • Compromised Linux web server18 September 2026 · s9d83

    The first non-Windows image in the set. Find how the actor got in, what was modified, and what persistence was left.

  • RansomCare18 September 2026 · s69d3

    Two memory dumps of machines hit by ransomware. No disk, no file system, nothing to carve. Find the ransomware's code, dump it, and explain what happened to the victim.

  • Malware in unallocated space18 September 2026 · s1839

    A system was compromised and the only evidence left is its unallocated disk space. No partition table, no file system, and a catalog that came back empty.