<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Write-ups on Ahmad Massd — Security Blog</title><link>https://p0peye-blog.pages.dev/categories/write-ups/</link><description>Recent content in Write-ups on Ahmad Massd — Security Blog</description><generator>Hugo -- gohugo.io</generator><language>en</language><managingEditor>ahmad.massad.ir@gmail.com (Ahmad Massad)</managingEditor><webMaster>ahmad.massad.ir@gmail.com (Ahmad Massad)</webMaster><copyright>© 2026 Ahmad Massad</copyright><lastBuildDate>Wed, 20 Aug 2025 00:00:00 +0000</lastBuildDate><atom:link href="https://p0peye-blog.pages.dev/categories/write-ups/index.xml" rel="self" type="application/rss+xml"/><item><title>Aliens CTF — DFIR: 7 Oct</title><link>https://p0peye-blog.pages.dev/posts/aliens-ctf-dfir/</link><pubDate>Wed, 20 Aug 2025 00:00:00 +0000</pubDate><author>ahmad.massad.ir@gmail.com (Ahmad Massad)</author><guid>https://p0peye-blog.pages.dev/posts/aliens-ctf-dfir/</guid><description>&lt;h2 class="relative group"&gt;Challenge: 7 Oct
 &lt;div id="challenge-7-oct" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#challenge-7-oct" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;

&lt;h3 class="relative group"&gt;Description
 &lt;div id="description" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#description" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h3&gt;
&lt;blockquote&gt;&lt;p&gt;We stormed one of the enemy&amp;rsquo;s concentration areas and after completing the operation, we took some devices to investigate and obtain intelligence. One device belongs to a leader. We believe information is being leaked through a spy. Search the device to find the spy and location details — the enemy was planning a prisoner recovery operation and location information had been leaked to them.&lt;/p&gt;</description></item><item><title>Cyber Warriors CTF — Forensics: Investigation Nashmi APT</title><link>https://p0peye-blog.pages.dev/posts/cyber-warriors-ctf-nashmi-apt/</link><pubDate>Sat, 16 Aug 2025 00:00:00 +0000</pubDate><author>ahmad.massad.ir@gmail.com (Ahmad Massad)</author><guid>https://p0peye-blog.pages.dev/posts/cyber-warriors-ctf-nashmi-apt/</guid><description>&lt;p&gt;&lt;figure&gt;&lt;img
 class="my-0 rounded-md"
 loading="lazy"
 decoding="async"
 fetchpriority="low"
 alt=""
 src="https://miro.medium.com/v2/resize:fit:700/1*xmjWlgRCiaWpY7CiFRfAHg.png"
 &gt;&lt;/figure&gt;
&lt;/p&gt;

&lt;h2 class="relative group"&gt;Introduction
 &lt;div id="introduction" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#introduction" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;Our Security Operations Center (SOC) detected suspicious activity originating from an internal employee workstation. The employee — a finance team member — reported slow system performance and unexpected behavior. Shortly after, EDR logs showed signs of malware persistence and suspicious outbound traffic.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Mission:&lt;/strong&gt; Analyze a full memory image of the compromised machine, identify the scope of the infection, and answer key investigation questions.&lt;/p&gt;</description></item></channel></rss>