N-Tech — Workstation Incident
Incident briefing
On September 17, 2026, procurement employee Emma Carter reported that several business documents on her workstation could no longer be read. The workstation has been made available for investigation, together with collected Windows event logs and a network capture.
Determine how the incident began, what activity occurred on the endpoint, whether communication with another host took place, and which files were affected. Identify relevant indicators of compromise and reconstruct a timeline supported by evidence.
Distinguish observed facts from assumptions. Correlate accounts, process identifiers, command lines, file artifacts and network activity.
Evidence and investigation
Collected evidence is available under C:\NTech\Evidence.
Additional artifacts remain in the employee's Windows profile and
elsewhere on the workstation.
You may use Event Viewer, PowerShell, Wireshark and other supplied tools. Preserve the supplied evidence files and avoid executing suspect scripts during investigation.
Use the exported event logs as the supplied incident record. Live logs also contain subsequent preparation and login activity.
Historical records refer to the original workstation, N-TECH-WS01,
and its original IP address, 10.16.20.10. Your assigned machine may
have a different hostname and IP address.
Timestamps from different evidence sources may not align exactly. Record the time source and timezone used in your findings.
Investigation phases
- Email & Initial Access Analysis
- Endpoint Forensics: Persistence & Credential Access
- Network & Communication Analysis
- Ransomware Impact Analysis
- Timeline & Evidence Correlation
- Recovery
Submissions and recovery
Submit your findings through CTFd using each challenge's requested flag format. There are 15 challenges across six phases.
Work only on your assigned workstation. Other participants' machines and the CTFd infrastructure are outside the investigation scope.
Recovery instructions and the decryption key will be supplied during the final phase. Perform recovery only when instructed.
Successful recovery requires all six affected business documents to match their original SHA256 hashes. The instructor will validate recovery before issuing the completion flag.