Every command this range teaches, decoded. Pick one on the left, or search above.
FORENSICS · LINUX · difficulty 5 · ~45 min · 18 steps
Sixteen gigabytes of RAM from a host that looked clean. Every process on it is a Windows process. One is lying.
A finance workstation was flagged by a firewall rule and nothing else — one outbound session to an address on a watchlist, from a process the endpoint agent considers legitimate and signed. Memory was captured before the machine was powered off. The disk has since been imaged and is clean: no unusual files, no scheduled tasks, no services, no persistence anywhere on it. It never touched the disk. Everything that ever ran on this machine exists only in the sixteen gigabytes you are holding, and the process it ran inside still has the right name, the right path and the right signature.