Skip to content

Commit 9c6930d

Browse files
committed
finalize empirec2
1 parent 112d18d commit 9c6930d

File tree

19 files changed

+1219
-206
lines changed

19 files changed

+1219
-206
lines changed

content/ctfwriteups/empirec2.md

Lines changed: 646 additions & 2 deletions
Large diffs are not rendered by default.

public/categories/c2/index.html

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -151,11 +151,11 @@ <h1>
151151

152152
<article class="post-entry tag-entry">
153153
<header class="entry-header">
154-
<h2 class="entry-hint-parent">Empire C2 - Writeup
154+
<h2 class="entry-hint-parent">Empire is at Risk - Writeup
155155
</h2>
156156
</header>
157-
<footer class="entry-footer">0 min&nbsp;·&nbsp;connar</footer>
158-
<a class="entry-link" aria-label="post link to Empire C2 - Writeup" href="http://localhost:1313/ctfwriteups/empirec2/"></a>
157+
<footer class="entry-footer">8 min&nbsp;·&nbsp;connar</footer>
158+
<a class="entry-link" aria-label="post link to Empire is at Risk - Writeup" href="http://localhost:1313/ctfwriteups/empirec2/"></a>
159159
</article>
160160
</main>
161161

public/categories/c2/index.xml

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,11 +8,17 @@
88
<language>en-us</language>
99
<atom:link href="http://localhost:1313/categories/c2/index.xml" rel="self" type="application/rss+xml" />
1010
<item>
11-
<title>Empire C2 - Writeup</title>
11+
<title>Empire is at Risk - Writeup</title>
1212
<link>http://localhost:1313/ctfwriteups/empirec2/</link>
1313
<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
1414
<guid>http://localhost:1313/ctfwriteups/empirec2/</guid>
15-
<description></description>
15+
<description>&lt;p&gt;In this challenge we are given:&lt;/p&gt;
16+
&lt;blockquote&gt;
17+
&lt;p&gt;A pcap file (capture.pcap)&lt;/p&gt;
18+
&lt;p&gt;A powershell dump (powershell.DMP)&lt;/p&gt;
19+
&lt;/blockquote&gt;
20+
&lt;p&gt;A lot of times hard difficulty challenges are related to C2 traffic, and in this challenge we are given a pcap file that indicates there is a chance this might be the case. Simply searching for &lt;code&gt;Empire C2&lt;/code&gt; (Empire from the title of the challenge) will yield results related to an Empire C2 Framework.&lt;/p&gt;
21+
&lt;p&gt;Navigating through some posts, a very good one that I used as a reference while solving the challenge was:&lt;/p&gt;</description>
1622
</item>
1723
</channel>
1824
</rss>

public/categories/index.html

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -148,11 +148,14 @@ <h1>Categories</h1>
148148
</header>
149149

150150
<ul class="terms-tags">
151+
<li>
152+
<a href="http://localhost:1313/categories/c2/">c2 <sup><strong><sup>1</sup></strong></sup> </a>
153+
</li>
151154
<li>
152155
<a href="http://localhost:1313/categories/forensics/">Forensics <sup><strong><sup>1</sup></strong></sup> </a>
153156
</li>
154157
<li>
155-
<a href="http://localhost:1313/categories/malware/">Malware <sup><strong><sup>9</sup></strong></sup> </a>
158+
<a href="http://localhost:1313/categories/malware/">Malware <sup><strong><sup>10</sup></strong></sup> </a>
156159
</li>
157160
<li>
158161
<a href="http://localhost:1313/categories/network-traffic/">Network-traffic <sup><strong><sup>1</sup></strong></sup> </a>

public/categories/index.xml

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -36,6 +36,13 @@
3636
<guid>http://localhost:1313/categories/phishing/</guid>
3737
<description></description>
3838
</item>
39+
<item>
40+
<title>C2</title>
41+
<link>http://localhost:1313/categories/c2/</link>
42+
<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
43+
<guid>http://localhost:1313/categories/c2/</guid>
44+
<description></description>
45+
</item>
3946
<item>
4047
<title>Forensics</title>
4148
<link>http://localhost:1313/categories/forensics/</link>

public/categories/malware/index.html

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -221,6 +221,15 @@ <h2 class="entry-hint-parent">Analyzing Beep Malware
221221
<a class="entry-link" aria-label="post link to Analyzing Beep Malware" href="http://localhost:1313/posts/beepmalware/"></a>
222222
</article>
223223

224+
<article class="post-entry tag-entry">
225+
<header class="entry-header">
226+
<h2 class="entry-hint-parent">Empire is at Risk - Writeup
227+
</h2>
228+
</header>
229+
<footer class="entry-footer">8 min&nbsp;·&nbsp;connar</footer>
230+
<a class="entry-link" aria-label="post link to Empire is at Risk - Writeup" href="http://localhost:1313/ctfwriteups/empirec2/"></a>
231+
</article>
232+
224233
<article class="post-entry tag-entry">
225234
<header class="entry-header">
226235
<h2 class="entry-hint-parent">Exploring OneNote Forensic tools

public/categories/malware/index.xml

Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -97,6 +97,19 @@ Let&amp;rsquo;s dive into what the Windows API is and why it&amp;rsquo;s crucial
9797
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;
9898
&lt;/span&gt;&lt;/span&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;&lt;span style=&#34;color:#66d9ef&#34;&gt;exit&lt;/span&gt;
9999
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;So, let&amp;rsquo;s open the dll in IDA and view the specific function:&lt;/p&gt;</description>
100+
</item>
101+
<item>
102+
<title>Empire is at Risk - Writeup</title>
103+
<link>http://localhost:1313/ctfwriteups/empirec2/</link>
104+
<pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
105+
<guid>http://localhost:1313/ctfwriteups/empirec2/</guid>
106+
<description>&lt;p&gt;In this challenge we are given:&lt;/p&gt;
107+
&lt;blockquote&gt;
108+
&lt;p&gt;A pcap file (capture.pcap)&lt;/p&gt;
109+
&lt;p&gt;A powershell dump (powershell.DMP)&lt;/p&gt;
110+
&lt;/blockquote&gt;
111+
&lt;p&gt;A lot of times hard difficulty challenges are related to C2 traffic, and in this challenge we are given a pcap file that indicates there is a chance this might be the case. Simply searching for &lt;code&gt;Empire C2&lt;/code&gt; (Empire from the title of the challenge) will yield results related to an Empire C2 Framework.&lt;/p&gt;
112+
&lt;p&gt;Navigating through some posts, a very good one that I used as a reference while solving the challenge was:&lt;/p&gt;</description>
100113
</item>
101114
<item>
102115
<title>Exploring OneNote Forensic tools</title>

public/ctfwriteups/chinesewindowsupgrader/index.html

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -279,7 +279,7 @@ <h1 class="post-title entry-hint-parent">
279279
<a class="next" href="http://localhost:1313/ctfwriteups/empirec2/">
280280
<span class="title">Next »</span>
281281
<br>
282-
<span>Empire C2 - Writeup</span>
282+
<span>Empire is at Risk - Writeup</span>
283283
</a>
284284
</nav>
285285

0 commit comments

Comments
 (0)