Write-up for 2 forensics challenges at THCon : https://cryptax.github.io/thcon2026-breach/
THCon 2026 - Forensics Challenges
Don’t forget to lock This is the first challenge of the Forensics category. 1 We seized a suspect's computer and managed to capture a RAM dump before it was powered off, along with an encrypted disk. Your objective is to decrypt the drive. We get a chall.tar.gz Solving the challenge The tar.gz contains 2 files: an ELF and a raw: 1 2 3 drwxr-xr-x aurel/aurel 0 2026-03-09 16:46 files/ -rw-r--r-- aurel/aurel 1072693248 2026-03-09 16:46 files/disk.






