$ ls ~/writeups
- #001easyBrunnerCTF
Bears
Posts
BrunnerCTF misc/forensics challenge extracting data from a mascot image (embedded metadata, not LSB stego).
READ WRITEUP →
- #002easy-mediumBrunnerCTF
Company Discount
Posts
BrunnerCTF forensics/malware challenge analyzing a defanged .hta file delivering a company discount email scam.
READ WRITEUP →
- #003easyBrunnerCTF
Forensic Invoice
Posts
BrunnerCTF forensics/malware challenge analyzing a macro-enabled Office document with a malicious VBA payload.
READ WRITEUP →
- #004mediumBrunnerCTF
Free Play
Posts
BrunnerCTF forensics challenge analyzing a 2009-era game save file and screenshot to recover a hidden flag.
READ WRITEUP →
- #005hardBrunnerCTF
The Missing Recipe
Posts
BrunnerCTF forensics/network DFIR challenge reconstructing an attack from a ~40MB PCAP to recover a hidden flag.
READ WRITEUP →
- #006mediumBrunnerCTF
Welcome Aboard
Posts
BrunnerCTF web challenge involving request smuggling through an employee wiki with multiple infrastructure layers.
READ WRITEUP →
- #007hardNxCTF
The Forgotten Incident
Posts
Hard forensics/web challenge following a URL-encoded path traversal (CVE-2021-41773 pattern) through synthetic evidence artifacts to the hidden forensic store.
READ WRITEUP →
- #008mediumNxCTF
Labyrinth
Posts
Reverse engineering challenge inverting a 4-chunk 16-round Feistel network with AES S-boxes and an anti-debug ptrace key-poison.
READ WRITEUP →
- #009hardNxCTF
Whitebox
Posts
Hard reversing challenge inverting a Chow-style white-box AES (9 table rounds + final byte encoding) to recover the secret key-free.
READ WRITEUP →
- #010mediumNxCTF
Hackers Vault
Posts
Web exploitation challenge abusing a race condition in the token refresh flow to bypass a role check and retrieve the flag.
READ WRITEUP →
- #011mediumHack The Box
Fireflow
Posts
Medium HTB Linux box chaining Langflow RCE (CVE-2026-33017), password reuse, MCP JWT alg:none forgery, and Kubernetes nodes/proxy to root.
READ WRITEUP →
No signal found. Try a broader search or clear the active tags.