<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>NSA Codebreaker 2025 on XSS3cut10n3r</title><link>https://xss3cut10n3r.com/tags/nsa-codebreaker-2025/</link><description>Recent content in NSA Codebreaker 2025 on XSS3cut10n3r</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Sat, 03 Oct 2026 00:08:00 +0100</lastBuildDate><atom:link href="https://xss3cut10n3r.com/tags/nsa-codebreaker-2025/index.xml" rel="self" type="application/rss+xml"/><item><title>NSA Codebreaker 2025: My First Full Challenge</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/</link><pubDate>Sat, 03 Oct 2026 00:08:00 +0100</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/</guid><description>&lt;p&gt;The 2025 NSA Codebreaker Challenge was my first Codebreaker, and I completed all seven tasks, becoming one of 82 students to finish the full challenge. It was a chance to connect skills that I had often practiced separately: filesystem forensics, packet analysis, memory analysis, reverse engineering, cryptography, and application security.&lt;/p&gt;&#10;&lt;p&gt;The challenge used a fictional investigation into suspicious activity on a military development network. Each task carried the investigation forward, so an answer was more than a flag - it supplied context for the next question.&lt;/p&gt;</description></item><item><title>NSA Codebreaker 2025 - Task 7: Finale</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-7/</link><pubDate>Sat, 03 Oct 2026 00:07:00 +0100</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-7/</guid><description>&lt;p&gt;&lt;a href="https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/"&gt;← Series overview&lt;/a&gt;&lt;/p&gt;&#10;&lt;!-- Paste your Markdown content below this line. --&gt;&#10;&lt;h1 id="task-7---finale---vulnerability-research-exploitation"&gt;Task 7 - Finale - (Vulnerability Research, Exploitation)&lt;/h1&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;Now that we have access to the hidden channel the adversary is using, our military counterparts want to act quickly to destroy the adversary&amp;rsquo;s capacity to continue with their attack against our military networks.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;Analysts have been quickly scrutinizing the data from the privileged channel. They conclude that the adversary has downloaded a custom app to archive all messages sent in the channel locally to their phone. They have also surmised the adversary is running a recent version of Android on a Google Pixel phone. This is the opportunity we have been waiting for! If we can devise a way to exploit on to the adversary&amp;rsquo;s device we will have the advantage.&lt;/p&gt;</description></item><item><title>NSA Codebreaker 2025 - Task 6: Crossing the Channel</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-6/</link><pubDate>Sat, 03 Oct 2026 00:06:00 +0100</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-6/</guid><description>&lt;p&gt;&lt;a href="https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/"&gt;← Series overview&lt;/a&gt;&lt;/p&gt;&#10;&lt;!-- Paste your Markdown content below this line. --&gt;&#10;&lt;h1 id="task-6---crossing-the-channel---vulnerability-research"&gt;Task 6 - Crossing the Channel - (Vulnerability Research)&lt;/h1&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;This high visibility investigation has garnered a lot of agency attention. Due to your success, your team has designated you as the lead for the tasks ahead. Partnering with CNO and CYBERCOM mission elements, you work with operations to collect the persistent data associated with the identified Mattermost instance. Our analysts inform us that it was obtained through a one-time opportunity and we must move quickly as this may hold the key to tracking down our adversary! We have managed to create an account but it only granted us access to one channel. The adversary doesn&amp;rsquo;t appear to be in that channel.&lt;/p&gt;</description></item><item><title>NSA Codebreaker 2025 - Task 5: Putting It All Together</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-5/</link><pubDate>Sat, 03 Oct 2026 00:05:00 +0100</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-5/</guid><description>&lt;p&gt;&lt;a href="https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/"&gt;← Series overview&lt;/a&gt;&lt;/p&gt;&#10;&lt;h2 id="task-5---putting-it-all-together---cryptanalysis"&gt;Task 5 - Putting It All Together - (Cryptanalysis)&lt;/h2&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;NSA analysts confirm that there is solid evidence that this binary was at least part of what had been installed on the military development network. Unfortunately, we do not yet have enough information to update NSA senior leadership on this threat. We need to move forward with this investigation!&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;The team is stumped - they need to identify something about who was controlling this malware. They look to you. &amp;ldquo;Do you have any ideas?&amp;rdquo;&lt;/p&gt;</description></item><item><title>NSA Codebreaker 2025 - Task 4: Unpacking Insight</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-4/</link><pubDate>Sat, 03 Oct 2026 00:04:00 +0100</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-4/</guid><description>&lt;p&gt;&lt;a href="https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/"&gt;← Series overview&lt;/a&gt;&lt;/p&gt;&#10;&lt;h2 id="task-4---unpacking-insight---malware-analysis"&gt;Task 4 - Unpacking Insight - (Malware Analysis)&lt;/h2&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;Once back at NSA the team contacts the NSA liaison at FBI to see if they have any information about what was discovered in the configuration data. FBI informs us that the facility registered to host that domain is on a watchlist for suspected criminal activity. With this tip, the FBI acquires a warrant and raids the location. Inside the facility, the server is discovered along with a suspect. The suspect is known to the FBI as a low-level malware actor. During questioning, they disclose that they are providing a service to host malware for various cybercrime groups, but recently they were contacted by a much more secretive and sophisticated customer. While they don&amp;rsquo;t appear to know anything about who is paying for the service, they provide the FBI with the malware that was hosted.&lt;/p&gt;</description></item><item><title>NSA Codebreaker 2025 - Task 3: Digging Deeper</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-3/</link><pubDate>Sat, 03 Oct 2026 00:03:00 +0100</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-3/</guid><description>&lt;p&gt;&lt;a href="https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/"&gt;← Series overview&lt;/a&gt;&lt;/p&gt;&#10;&lt;h2 id="task-3---digging-deeper---reverse-engineering"&gt;Task 3 - Digging Deeper - (Reverse Engineering)&lt;/h2&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;The network administrators confirm that the IP address you provided in your description is an edge router. DAFIN-SOC is asking you to dive deeper and reverse engineer this device. Fortunately, their team managed to pull a memory dump of the device.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;Scour the device&amp;rsquo;s memory dump and identify anomalous or malicious activity to find out what&amp;rsquo;s going on.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;Your submission will be a list of IPs and domains, one per line. For example:&lt;/p&gt;</description></item><item><title>NSA Codebreaker 2025 - Task 2: The Hunt Continues</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-2/</link><pubDate>Sat, 03 Oct 2026 00:02:00 +0100</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-2/</guid><description>&lt;p&gt;&lt;a href="https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/"&gt;← Series overview&lt;/a&gt;&lt;/p&gt;&#10;&lt;h2 id="task-2---the-hunt-continues---network-forensics"&gt;Task 2 - The Hunt Continues - (Network Forensics)&lt;/h2&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;With your help, the team concludes that there was clearly a sophisticated piece of malware installed on that endpoint that was generating some network traffic. Fortunately, DAFIN-SOC also has an IDS which retained the recent network traffic in this segment.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;DAFIN-SOC has provided a PCAP to analyze. Thoroughly evaluate the PCAP to identify potential malicious activity.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;hr&gt;&#10;&lt;h2 id="downloads"&gt;Downloads&lt;/h2&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;strong&gt;PCAP to analyze:&lt;/strong&gt; &lt;code&gt;traffic.pcap&lt;/code&gt;&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;hr&gt;&#10;&lt;h2 id="task"&gt;Task&lt;/h2&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;strong&gt;Submit all the IP addresses that are assigned to the malicious device, one per line.&lt;/strong&gt;&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;hr&gt;&#10;&lt;h2 id="writeup"&gt;Writeup&lt;/h2&gt;&#10;&lt;p&gt;Upon opening the PCAP in Wireshark, I was greeted by approximately 2,400 packets consisting primarily of IPv4 and ARP traffic.&lt;/p&gt;</description></item><item><title>NSA Codebreaker 2025 - Task 1: Getting Started</title><link>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-1/</link><pubDate>Sat, 03 Oct 2026 00:01:00 +0100</pubDate><guid>https://xss3cut10n3r.com/posts/nsa-codebreaker-2025-task-1/</guid><description>&lt;p&gt;&lt;a href="https://xss3cut10n3r.com/posts/nsa-codebreaker-2025/"&gt;← Series overview&lt;/a&gt;&lt;/p&gt;&#10;&lt;h2 id="task-1---getting-started-forensics"&gt;Task 1 - Getting Started (Forensics)&lt;/h2&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;You arrive on site and immediately get to work. The DAFIN-SOC team quickly briefs you on the situation. They have noticed numerous anomalous behaviors, such as: tools randomly failing tests and anti-virus flagging on seemingly clean workstations. They have narrowed in on one machine they would like NSA to thoroughly evaluate.&lt;/p&gt;&#10;&lt;/blockquote&gt;&#10;&lt;blockquote&gt;&#10;&lt;p&gt;They have provided a zipped EXT2 image from this development machine. Help DAFIN-SOC perform a forensic analysis on this - looking for any suspicious artifacts.&lt;/p&gt;</description></item></channel></rss>