July Season: Ghost in the Machine
Three compromised boxes, three flags buried in the aftermath. Hunt the persistence, read the logs, and recover what the intruder left behind — all on sandboxes you fully control. Defensive practice only.
Archived season — playable for practice, no leaderboard points. Official write-ups are open.
The Quiet Cron
forensics · persistence · cron
Sudo Misery Loves Company
forensics · privesc · sudo
The Log Never Lies
forensics · log-analysis · ssh
The Log Never Lies
150 pts · decays to 75 · +25 first bloodA brute-force wave hit this host's SSH, and exactly one attempt succeeded. The attacker cleared their shell history, but the auth log remembers. Reconstruct the timeline: find the source that broke in, the account it landed on, and the flag left in that user's home.
The live sandbox for this challenge isn't available yet — brief and hints are open.
Hints
Failed and accepted logins both land in the auth log (/var/log/auth.log or journalctl -u ssh). Count failures per source to find the brute-forcer.
Submit flag
Sign in to submit flags and get on the board.
Archived — solves are for practice, not the leaderboard.
Season standings
loading standings…
