Challenge: Buttercup Get-Help
Threat actors commonly use file types in creative ways. As a CTF player, you must discover a mysterious file artifact and investigate its hidden treasure!
Already have an account? Sign In »

Module 1: Investigate
In this weekly challenge, you will operate in an investigative capacity to reveal what is hidden in a mysterious artifact.
- How to crack Zip passwords
- How to decompile CHM help files
- Microsoft PowerShell deserialization document
- Microsoft PowerShell encryption document
- Protip: . .\myScript leaves variables open in poweshell ISE
Who is this for?
Intermediate to advance career practitioners. Individuals new to cybersecurity may struggle to complete this as it involves some advanced security concepts. We encourage the use of any internet resources, community/colleague assistance in completion of the challenge.
What resources are available to help solve this challenge?
Online search, Discord community, colleagues or fellow practitioners.
Are write ups permitted?
Yes, write ups are permitted; however, please do not post answers directly. All write ups should include an appropriate link back to Cybrary and the Cybrary Course.

Matthew Mullins
Technical Manager, Red Team


Complete this entire course to earn a Challenge: Buttercup Get-Help Certificate of Completion