Stolen Mount CTF
Quick Walkthrough of the TryHackMe Stolen Mount Easy CTF
CYBERSECURITYFORENSICSPACKET ANALYSIS
CyberPanther232
7/29/20251 min read
The Stolen Mount TryHackMe CTF was a short and entertaining room to help me learn more about the NFS protocol and raw data extraction in Wireshark. Initially I was enticed to complete this room by the challenge description. The room provides a scenario for which you are a forensic analyst looking into a security incident were data had been exfiltrated by a threat actor who abused weak login credentials and extracted data from an NFS file share.
Overall, this took CTF took me around 45 minutes even though it was a 30 minute room. I found the most difficult part was understanding how to extract the raw data in order to gather the data that was extracted during this incident. I found it very entertaining and educational. I recommend this for those looking to start becoming forensic analysts or those who are looking to get into Wireshark traffic analysis
Click on the image above to see the complete walkthrough on my GitHub!
