Category: forensics
Author: dark_darkl0rd
You have been tasked to recover the Skew1 part of the Windows BootKey (key for SysKey decryption). The bad news is that you need to submit not just the registry Cell Data of the Skew1 Class Name/Attribute but the entire Cell (Cell Size + Cell Data), as a continuous hex string (with or without the padding bytes).
Flag format ECSC{0102030405060708090A0B0C0D0E0F...}