Name: Who's Suing? | Category: Due Diligence | 300 pts Challenge: During a corporate due diligence investigation, OSINT investigators uncovered evidence suggesting that a company associated with Norberto Baesso Hilario became involved in legal proceedings during 2023. Investigators believe the lawsuit may reveal additional connections relevant to the case. Your task is to identify the civil action and determine the identity of the individual who initiated the legal proceedings.

What is the name of the plaintiff who filed a lawsuit against the company whose director is Norberto Baesso Hilario on 19 April 2023? Answer format: flag{first middle and last name} — underscore not required. Example: flag{John A Smith} Walkthrough: Searching for the name Norberto Baesso Hilario on OpenCorporates reveals that he is listed as a partner/manager of a company called KOPSCH CONFECÇÕES EIRELI.

Performing a targeted Google search using the query "KOPSCH CONFECCOES" "2023" "19" yields a Portuguese PDF document in the search results. Opening this file and searching for "KOPSCH" reveals key case details, including the lawsuit date and the plaintiff's name. Link: https://publicidadelegal.gazetasp.com.br/wp-content/uploads/2024/03/pl_import_687cea117f713_gsp-22032024-certificado-8.pdf Accepted flags: flag{ELAINE ROSA GAMA CAMPOI MEI} flag{ELAINE ROSA GAMA CAMPOI} Name: Historical Handle | Category: Social Media | 200 pts Challenge: During an online threat intelligence investigation, analysts discovered a Telegram channel involved in the trading of social media accounts and offering account closure services.

While reviewing messages and activity logs from the channel, investigators identified references to a Telegram account that had changed its identity. What was the Telegram username associated with the account @kk4k44 in September 2024? Answer format: flag{@username} Walkthrough: First, retrieve the numeric user ID associated with the target Telegram account.

Log into Telegram Web, search for the username, and open the profile chat — the user ID will be visible in the browser address bar. Copy this ID and paste it into the SangMata Telegram bot (@SangMata_BOT), which queries past database logs to reveal historical display names and usernames used by that account. Accepted flags: flag{QOK6L} flag{@QOK6L} flag{@qok6l} flag{qok6l} Name: Where Did It Land? | Category: Due Diligence | 300 pts Challenge: During the investigation into the suspect's movements, authorities uncovered a photograph of an aircraft believed to be connected to the suspect's travel.

The image is attached to this challenge. Investigators must analyze the photograph and use open-source aviation intelligence to identify the aircraft and trace its movements on the relevant date. At which airport was this aircraft located on 11 February 2025 at around 11:00 UTC?

Note: Submit the airport code only. Answer format: flag{ABC} Walkthrough: Examining the image reveals the aircraft tail number (registration C-GHQQ). Searching for C-GHQQ on ADS-B Exchange and filtering historical data for 11 February 2025 at 11:00 UTC confirms that the aircraft was located at Toronto Pearson International Airport (YYZ/CYYZ).

Since the question had the wrong date, the following answers were also accepted: Accepted flags: flag{YUL} flag{YYZ} flag{CYYZ} Name: Lost at Sea - 1 | Category: Maritime | 100 pts Challenge: You are an intelligence analyst who has received a high-resolution satellite image showing two unidentified objects in the middle of the open ocean. Your mission is to identify both objects using OSINT techniques. Identify the object highlighted inside the red square.

Your answer should include the object's type/name and its associated number. For example, if the object is identified as Submarine 23, the flag should be flag{Submarine_23} Walkthrough: At first glance, the object visually resembles a large rocket or spacecraft positioned on a barge in the open ocean. Performing a reverse image search using the cropped image identifies multiple publicly available articles and reports discussing offshore transportation of SpaceX hardware with matching satellite imagery, identifying the object as SpaceX Ship 40 (Starship 40).

This can also be confirmed by searching the complete satellite image on platforms such as SOAR. Flag: flag{SHIP_40} Name: Lost at Sea - 2 | Category: Maritime | 100 pts Challenge: Identify the vessel marked in the image and determine its IMO number. If the vessel's name is Atlas and its IMO number is 1234567, the flag should be: flag{Atlas_1234567} Walkthrough: The reports identified in Task 1 mention that the Starship hardware was being transported by the tug vessel Normand Ranger.

Searching for Normand Ranger in a maritime vessel tracking platform such as MarineTraffic, VesselFinder, or Equasis reveals its identifying information, including the IMO number. Vessel Name: Normand Ranger | IMO Number: 9413432 Source: https://edition.cnn.com/2026/08/03/science/spacex-starship-indian-ocean-recovery-satellite-images Accepted flags: flag{Normand_Ranger_9413432} flag{NORMAND_RANGER_9413432} Name: Crowd on the Horizon - 1 | Category: Physical Security | 100 pts Challenge: You are an intelligence analyst supporting a VIP convoy protection team. Before the convoy begins its movement, your team receives an image showing an ongoing public protest.

Your role is to assess the situation and provide actionable intelligence that could impact route planning and operational security. Determine the country where the protest is taking place. Flag format: flag{Country_Name} Walkthrough: Visible clues include pillars and public infrastructure, text in a local language, a metro station and surrounding urban landscape, and other characteristics commonly associated with Asian cities, suggesting the protest is somewhere in Asia.

Zooming in further reveals a partially visible flag in the background that, though slightly blurred, strongly indicates Bangladesh. Flag: flag{BANGLADESH} Name: Crowd on the Horizon - 2 | Category: Physical Security | 200 pts Challenge: Identify the primary cause or trigger of the protest. Understanding the underlying issue helps assess the protest's potential intensity, duration, and likelihood of escalation, enabling the convoy team to make informed operational decisions.

Submit the name of the key individual directly associated with the identified trigger. For example, if the individual is John Doe, the flag would be flag{John_Doe}. Walkthrough: Using Bangladesh as the primary search term, search for recent news articles containing images resembling the one provided.

Comparing the crowd, banners, location, and surrounding environment with news coverage helps identify the specific protest event. Cross-referencing against open-source event databases such as the Global Protest Tracker reveals the protest was triggered by the killing of Sharif Osman Bin Hadi. Source: https://carnegieendowment.org/features/global-protest-tracker Accepted flags: flag{SHARIF_OSMAN_BIN_HADI} flag{OSMAN_HADI} flag{OSMAN_GONI} Name: From Photo to Footprint - 1 | Category: Social Media | 200 pts Challenge: During an ongoing police investigation, officers received only a facial photograph of a potential suspect from an anonymous source.

No identifying information such as a name, email address, or phone number was provided. Investigators must leverage OSINT techniques to trace the individual's digital footprint, uncover their identity, and identify any publicly available information linked to the suspect. What is this person's personal email address?

Answer format: flag{email@example.com} Walkthrough: Performing a reverse image search reveals the target's name, Humam Abo Alraja, and leads to his social media profiles, including LinkedIn. To discover his email address, generate potential pattern combinations across major providers (e.g., @gmail.com, @outlook.com) or use LinkedIn email lookup extensions such as ContactOut or SignalHire. Flag: flag{HUMAMABOALRAJA@GMAIL.COM} Name: From Photo to Footprint - 2 | Category: Social Media | 300 pts Challenge: What was the username of the deleted X (formerly Twitter) account that this person previously used?

Answer format: flag{@username} Walkthrough: Leveraging the target's LinkedIn profile with a browser extension like SignalHire reveals two associated X (formerly Twitter) accounts: @humamaboalraja and @HomamAlhasan. Flag: flag{@HOMAMALHASAN} Name: Who's the Host? | Category: Social Media | 200 pts Challenge: Further analysis revealed that the suspect had rented an Airbnb property. To gather additional information about the suspect's stay, investigators need to identify and contact the property owner or listing host associated with the rental.

What is the full name of the Airbnb apartment owner (host/lister)? Link: https://www.airbnb.com/rooms/24881666 Answer format: flag{first last} — underscore not required Walkthrough: Navigate to the provided link and visit the host's profile page. Open your browser's Developer Tools (Inspect Element) to extract the full direct URL of the profile image.

Running a reverse image search on this image URL unveils matching profiles across multiple social media platforms, revealing the host's actual name. Accepted flags: flag{GERALD SCHÖNBUCHER} flag{GERALD SCHOENBUCHER} Name: Beyond the Domain - 1 | Category: Threat Intelligence | 100 pts Challenge: You are working as a Threat Intelligence Investigator conducting an external attack-surface assessment for BDO Germany. Your objective is to identify publicly exposed infrastructure and third-party services that could potentially provide useful information to threat actors targeting the company.

Understanding this infrastructure can help the security team identify potential exposure and reduce the risk of phishing, impersonation, and other targeted attacks. Which email service is used by bdo.de? Answer format: flag{email service} — underscore not required Walkthrough: Searching for BDO Germany reveals their official website, bdo.de.

Performing DNS reconnaissance using a platform like DNSDumpster reveals an MX record pointing to mx2.hc697-83.eu.iphmx.com. Searching for this hostname indicates the organization utilizes Cisco Secure Email (formerly Cisco IronPort). Accepted flags: flag{cisco email} flag{cisco secure} flag{cisco secure email} flag{cisco email security} flag{cisco ironport} flag{ironport} Name: Beyond the Domain - 2 | Category: Threat Intelligence | 200 pts Challenge: Which two additional domains can be associated with bdo.de?

Answer format: flag{website1.com,website2.com} Walkthrough: Navigating to bdo.de and examining its source code reveals an embedded Google Tag. Performing a reverse search on this Google Tag using a tool like DNSlytics uncovers two additional websites using the exact same tag ID. Accepted flags: flag{bdo-oldenburg.de,bdo-tuc.de} flag{bdo-tuc.de,bdo-oldenburg.de} www. and http/s prefixes are also accepted.

Note: "Beyond the Domain - 1 & 2" (MX record lookup, then reverse-searching a Google Tag ID to find related domains) could be visualized using Maltego Graph connecting a domain to its MX records, then pivoting from a Google Tag ID to sibling domains. It's core infrastructure/affiliate-mapping investigation (domain → MX → Tag ID → related domains), using Maltego's Transforms for DNS and tracking-code pivoting. Name: Shadow Brand - 1 | Category: Brand Protection | 200 pts Challenge: Intelligence suggests that threat actors are impersonating the brand across multiple online platforms to lure victims into fraudulent websites.

During the investigation, you receive a screenshot of a conversation between a scammer and a victim. Unfortunately, the message containing the malicious URL has been deleted before it could be captured. Your objective is to use the available evidence and OSINT techniques to uncover the remaining infrastructure used by the threat actors.

Note: Do not access the domain, as it may be potentially dangerous. Determine another social media platform where the threat actor or scam group is actively promoting its fraudulent campaign. If the platform is Instagram, the flag would be: flag{Instagram} Walkthrough: The only artifact provided is a screenshot of a Telegram conversation showing a display name and username.

Since usernames are often reused across platforms, they provide a strong pivot point. Using SOCMINT tools and username search techniques reveals a matching profile on Bluesky: https://bsky.app/profile/elegantgoodall7.bsky.social, matching the username observed in the Telegram conversation. Accepted flags: flag{Bluesky} flag{bsky} Name: Shadow Brand - 2 | Category: Brand Protection | 100 pts Challenge: Using the information gathered from the first task, identify the typosquatted domain being used by the threat actors to redirect victims to their phishing website.

If the legitimate domain is google and the threat actor uses go0gle, the flag would be: flag{go0gle} Walkthrough: Reviewing the Bluesky profile's posts, replies, and comment threads reveals a comment referencing the domain berkleyopt. In the original Telegram conversation, the scammer was discussing berkleypot. Comparing the two names reveals a subtle character transposition, a common typosquatting technique, confirming berkleyopt as the fraudulent domain.

Flag: flag{berkleyopt} Name: Following the Bitcoin Trail - 1 | Category: Fraud | 200 pts Challenge: You are a cyber threat intelligence analyst investigating a large-scale online fraud campaign. The only evidence recovered so far is a screenshot containing an email address believed to be associated with the threat actor. Begin your investigation using the evidence provided.

Trace the associated Bitcoin transaction and identify the wallet address that appears in the transaction inputs. Intelligence indicates that the transaction contains a large number of inputs. Answer format: flag{1A2b3C} Walkthrough: The screenshot contains a Bitcoin wallet address, the starting point for the investigation.

Searching the wallet address using a blockchain explorer such as WalletExplorer shows two transactions. Since the challenge specifies the transaction was received, inspect the incoming transaction. Opening it reveals a large number of input addresses; one address appears repeatedly, contributing multiple inputs: 1Mz7153HMuxXTuR2R1t78mGSdzaAtNbBWX.

Flag: flag{1Mz7153HMuxXTuR2R1t78mGSdzaAtNbBWX} Name: Following the Bitcoin Trail - 2 | Category: Fraud | 100 pts Challenge: After locating the transaction, analyze the list of transaction inputs. Determine the amount of Bitcoin associated with Input 45 (the final input in the transaction). Example: if the value of Input 45 is 1.234 BTC, the flag would be flag{1.234} Walkthrough: While viewing the transaction details in the blockchain explorer, navigate to the final input (Input 45), where the corresponding Bitcoin amount is displayed: 0.0022139 BTC.

Accepted flags: flag{0.0022139} flag{0.00221390} Name: Following the Bitcoin Trail - 3 | Category: Fraud | 300 pts Challenge: Intelligence suggests that the threat group might use another Bitcoin wallet to pay for premium subscriptions on paste-sharing platforms or other online services, allowing them to continue publishing announcements and communicating with victims. Using the intelligence gathered during the previous tasks, identify this additional Bitcoin wallet address. If the wallet address is 1A2b3C, the flag would be: flag{1A2b3C} Walkthrough: At this stage, two wallet addresses and the transaction timing are known and can be used as pivot points.

Searching the wallet addresses, transaction details, and related indicators leads to reports linking the activity to the NotPetya ransomware campaign. Visiting RansomLook.io's Crypto section and searching for the NotPetya group lists multiple associated Bitcoin wallets, including an additional wallet not previously identified: 13KBb1G7pkqcJcxpRHg387roBj2NX7Ufyf. Flag: flag{13KBb1G7pkqcJcxpRHg387roBj2NX7Ufyf} Name: Finding the Author | Category: Due Diligence | 100 pts Challenge: During an OSINT investigation, analysts are tracking the digital footprint of an individual known as Bob Fabien "BZ" Zinga.

Investigators believe that a resume associated with this individual has been shared online and need to identify the source behind its publication. What is the Google GAIA ID of the email account that posted the Bob Fabien "BZ" Zinga resume? Answer format: flag{109482039184750293817} Walkthrough: Searching for "Bob Fabien 'BZ' Zinga resume" reveals the target's resume hosted on Google Docs.

Extracting the Google Doc ID from the URL (1OP5rj77-WWBAbhoublqxScD851Y0xgxVKx5OA-TKd_4) and inputting it into an OSINT tool like GHunt identifies the Google account details of the document's uploader. Flag: flag{02388806070359922223} Name: WiFi Footprint | Category: Threat Intelligence | 100 pts Challenge: Following the arrest of a suspect, digital forensics investigators examined the suspect's mobile phone and recovered information about a previously connected WiFi network. The network was associated with the password "klrt0713", but its physical location was unknown.

Investigators believe that identifying the wireless access point associated with this network could help determine where the suspect had been staying or residing. Using the recovered WiFi information, determine in which city the suspect was living. Answer format: flag{AP Name} — underscore not required Walkthrough: Searching for the Wi-Fi password "klrt0713" in Wi-Fi databases such as P3WiFi reveals the wireless MAC address and associated coordinates.

Opening the coordinates on a map identifies the town where the access point is located. Accepted flags: flag{KRANJSKA_GORA} flag{KRANJSKA GORA} Name: The Disappeared Website | Category: Trust & Safety | 200 pts Challenge: You work as a Threat Intelligence Investigator for CHRIST, a well-known German jewelry and watch retailer. During an investigation into online brand impersonation, your team has identified evidence of a fraudulent website that was active in September 2023 and closely replicated the design and template of the official christ.de website.

The impersonating website is no longer accessible, so investigators must rely on historical records and archived webpages to identify the fraudulent domain and uncover additional information about the operation. What was the domain name of the impersonating website in September 2023? Answer format: flag{website.com} Walkthrough: One method for identifying an impersonating website is a favicon search: obtain the target website's favicon and calculate its MD5 hash, or use a service such as Favicon Hash to obtain the hash.

The resulting hash can then be searched via a service such as SilentPush to find other domains/websites reusing the same favicon, helping identify phishing or impersonating websites. Flag: flag{ultraper.click} Name: The Hidden Alias - 1 | Category: Fraud | 100 pts Challenge: A victim has reported a suspected fraud scam conducted through WhatsApp. As part of the investigation, you have been provided with a screenshot/export of the victim's WhatsApp conversation with the suspected scammer. Examine the provided WhatsApp conversation and identify the username/online alias being used by the suspected scammer.

Flag format: flag{username} — e.g. if the username is @test_abc, the flag would be flag{@test_abc} Walkthrough: At the top of the chat, the only visible identifier is "ED", which is not sufficient on its own. However, the conversation contains a shortened URL: https://rb.gy/mpy8sf, which redirects to an image hosted on ImgBB: https://ibb.co/nqfdVj8B. The voucher image itself appears unremarkable, so the next step is to examine its EXIF metadata using a tool such as the Stego Toolkit EXIF Data Extractor.

The metadata reveals the string @ED_led. Accepted flags: flag{@ED_LED} flag{ED_LED} Name: The Hidden Alias - 2 | Category: Frau