Forensic Riddle #4

The Riddle:

Today’s riddle is very short. You are on a lonely island. You have a new laptop with a plain vanilla installation of Windows XP and a PIN-locked mobile phone with emergency calls disabled. The phone’s PIN is hidden in a slack space of c:\boot.ini. Using only OS tools retrieve the PIN, unlock the phone, call for help and leave the island.

Answer here

Forensic Riddle #3

Another Friday, another riddle.

The Riddle:

  • The malicious Portable Executable (PE) file has been executed by another process immediately after all *.pf files have been removed from the %SystemRoot%\Prefetch folder; Prefetching is on, yet the Prefetch file associated with the malicious file cannot be found; why?


Answer here