picoCTF 2022 | Sleuthkit Apprentice Write-up

Challenge description

Download this disk image and find the flag. Note: if you are using the webshell, download and extract the disk image into /tmp not your home directory.

Category: Forensics


Having downloaded the file, I used binwalk -e to extract the disk image.

Navigating to the extracted directory, I first attempted grep -r pico to try and find a flag, but no dice.

Perhaps a different term could work? Let’s try flag.txt instead.

That’s a hit!

Knowing the file’s location, I just had to navigate there and obtain the flag

