← All Challenges
Hypervisor Haunt
Forensics
100 pts
standard
Challenge Description
Multiple VMs were encrypted after suspicious actions in vCenter and ESXi shell history. Your task is to reconstruct the infrastructure compromise path.
Recover:
- Exploited CVE ID.
- Ransom extension used on virtual disks.
- Target datastore name.
- External staging host used by attacker script.
Flag format: HackCTF{...}
Files
Hints
Submit Flag
Login to submit a flag.