Silent Signal

Description

SIV Pipeline Forensics Group 4

SilentSignal.pcaparrow-up-right

Solution

The whole traffic seems to be in ICMP or Ping requests.

Silent_Signal.png

There's 28 almost identical ping requests...

Extract with tshark and inspect all fields

The only difference is the delta time, if we convert first delta to character it's S, which is first character of flag.

Silent_Signal-1.png
circle-check

Last updated