← All Challenges
Pocket Breach
Forensics
100 pts
standard
Challenge Description
An executive received a smishing message and later unauthorized cloud sessions appeared. Investigate mobile artifacts and correlate with login telemetry.
Recover :
- Malicious domain in SMS URL.
- First unauthorized session epoch.
- Correlated city from device cache.
- Suspicious source IP tied to token abuse.
Flag format: HackCTF{...}
Files
Hints
Submit Flag
Login to submit a flag.