root@z2r:~/blog/tags#grep -r "base64" ./posts
<Tag: base64 />
Found 1 post with this tag.
CTF WRITEUPSFORENSICS
THM - After Hours
A hunt through a resort's offline WMI repository that traces a fileless backdoor from a "clean" event-log binding down through Base64-and-UTF16-encoded PowerShell, a reflectively-loaded .NET payload hidden in a custom Win32_HardwareTelemetry class, and a quietly planted net user backdoor account.