← All Challenges
Cloud Shadow
Forensics
200 pts
standard
Challenge Description
Security detected suspicious internal email access without password resets or MFA prompts. Investigation suggests OAuth app abuse and token replay across cloud services.
Identify:
- Malicious OAuth application client ID.
- First external IP that used the stolen token.
- Target tenant short name.
- Abused high-risk permission scope.
Flag format: HackCTF{...}
Files
Hints
Submit Flag
Login to submit a flag.