Surreaction - StarHackademINT 2023
Introduction This post is about an interesting forensic challenge that I solved during the StarHackademINT 2023 CTF. We were given a Quarantine folder coming from Windows Defender, and we had to find back the original filename on the internet. The structure of the given folder looks like this: Quarantine ├── Entries │ └── {80059732-0000-0000-6667-EF3396D235E7} ├── ResourceData │ └── 9F │ └── 9F598F562DDCFB69FA21A077BAD87F01A3F6258E └── Resources └── 9F └── 9F598F562DDCFB69FA21A077BAD87F01A3F6258E If we look on the internet, we can find some blog post that gives a lot of useful information on how to get the original files back....