Et tu, Hacker?

Instructions

Pasted image 20220908145621

Solution

First I dumped the evtx file to xml.

evtx_dump.py bruteforce.evtx > bruteforce.xml

Now I had a cleanly formatted file: et-tu-1

Looking through the logs, they all appear to be targeting user ericm. et-tu-2

Flag:

MetaCTF{ericm}

Next: The Best Laid Plans...