Cyber Detective OSINT CTF “Life Online” Writeup


Q: What US political party does James over here support?


Q: Where did James spend his childhood?


Q: In what city does James work?


Q: What CITY is Sarah going on holiday to at the end of February?


Q: The team has been trying to work out where Person of Interest, Sarah, walks her dog. This is part of building up a profile of her movements. Can you have a look to see if you can find the TOWN in which Sarah tends to take the dog out to?


Q: There’s a new Person of Interest, George something or other. Can you find anything interesting on him? Something he perhaps thinks you can’t work out?


Q: We’ve obtained what we believe to be an office CCTV camera feed. We have reason to suspect that it is overlooking one of the work desks belonging to one of our targets. Can you confirm the COLOUR of the DESK SURFACE and the COLOUR of the DESK LEGS, just so we can be sure of what we’re seeing and task the reconnaissance team further.


Q: James has a habit of getting in the way of things ;).


Q: We’re trying to plan when is best to break into James’ house to plant a bug. What time does he start work? (UK time).


Q: We’ve been watching a bloke called George recently, you might have already done some work on him. … In particular, we’re after an access key for a program his company uses so that the team can ex-filtrate information to aid with our ongoing fraud investigations.


Q: Our intelligence analysts have reported that a whole bunch of our targets are having a party together on a Saturday night soon. We want to deploy agents to see whats going on, but we can’t risk blowing our cover turning up in a car. The road is pretty quiet and the property has very clear view of its surroundings, our reports suggest. Find the location of the party and the best BUS ROUTE NUMBER to reach the party from Principality Stadium, Cardiff — where the surveillance team will be deployed from.


Q: Our analysts have been trying to get proof of a target’s phone number. We want to move ahead with the arrest but we must get evidence that the phone number we’ve got is indeed theirs. We need to be sure. Due to the highly sensitive nature of the case, we cannot confirm the target’s name with you at this time. Please have a look to see if you can find their phone number. When you call the target’s number what are the LAST THREE WORDS you hear (you can also just enter the phone number as your answer and that is fine as well)?



