NITE Team 4

NITE Team 4

评价数不足
Delicate Drive ( A.018 - October 2018 )
由 LeikRad 制作
This is a walkthrough for the Open World Campaing, Mission Group Delicate Drive ( A.018 - October 2018 )
   
奖励
收藏
已收藏
取消收藏
CODENAME : DELICATE DRIVE
NITE Team 4 recently identified Maria Sagastume as DelicateDrive, a Black Hat responsible many recent attacks against the American Banking system. Agent you are to help our recruitment team by giving the intel requested. Sagastume is a high value asset and this mission is time sensitive, get to work Agent.

This Open World Operation contains 3 missions, each with multiple parts.

This guide is meant to be used as a resource and will contain hints in order to help you solve the missions, but it will not contain the actual answers.

If at any time you feel like you need more help please go to either the discussion board or the Discord channel[discord.gg] and there will be fellow agents happy to help you.

The missions and parts are the following:
  1. A.018 - October 2018 - Part One
    • A.018 - Part One : Phase 1
    • A.018 - Part One : Phase 2
    • A.018 - Part One : Phase 3
  2. A.018 - October 2018 - Part Two
    • A.018 - Part Two : Phase 1
    • A.018 - Part Two : Phase 2
    • A.018 - Part Two : Phase 3
  3. A.018 - October 2018 - Part Three
    • A.018 - Part Three : Phase 1
    • A.018 - Part Three : Phase 2
    • A.018 - Part Three : Phase 3
A.018 - October 2018 - Part One
NITE Team 4 recently identified Maria Sagastume as DelicateDrive, a Black Hat responsible many recent attacks against the American Banking system. Ascertain her current status and location, and our recruitment team will determine how best to proceed.
Remember to read the briefing document,[media.niteteam4.com] it may contain useful information.

A.018 - Part One : Phase 1
Difficulty: Advanced
  • Hint 1Briefing mentions an archive number, you can use it here.[archive.blackwatchmen.com]

  • Hint 2Make sure to read the document.

  • Hint 3There is a mac address and a vendor, what module uses those two bits of information?

A.018 - Part One : Phase 2
Difficulty: Advanced
  • Hint 1Make sure to dig thoroughly through his phone.

  • Hint 2Maybe in the messages he mentioned something that could help you.

  • Hint 3He mentions a city and visitations periods, I wonder if that can help narrow down the location.

  • Hint 4Look at the city's wikipedia page, under economy.
A.018 - October 2018 - Part Two
It appears ICE apprehended Maria Sagastume on a routine immigrant sweep of the Phoenix area. They are likely unaware of her criminal activity, however, it is only a matter of time until the US intelligence community learns of Sagastume’s incarceration and realize they have the notorious DelicateDrive in custody.
Remember to read the briefing document,[media.niteteam4.com] it may contain useful information, and be sure to click the maltego nt4 entities in the support tab.

A.018 - Part Two : Phase 1
Difficulty: Advanced
  • Hint 1Briefing mentions communications between two people, what module can gather intel on people?

  • Hint 2Mr Sagastume must have talked about Maria to his attorney.

  • Hint 3Maybe XKeyscore can help.

A.018 - Part Two : Phase 2
Difficulty: Advanced
  • Hint 1The briefing mentions a domain.

  • Hint 2Some people are oblivous to what they receive in their email.

  • Hint 3They're currently hiring maybe they'll fall for a false CV application.

  • Hint 4After you're inside the network make sure to have a look around for subdomains, maybe you can find a registry.

  • Hint 5You'll need to use your heads to figure out how to use their registry.

  • Hint 6You already have her ARN number from the document, now you just need to use it.

A.018 - Part Two : Phase 3
Difficulty: Advanced
  • Hint 1Where can you get an active directory from?

  • Hint 2Maybe it's on the current computer, you just need to find the target path with a scan.

  • Hint 3Where is she being held?

  • Hint 4The active directories are city specific.

  • Hint 5 -- All the info you need to find the correct file is in her registry database.

  • Hint 6 -- After you upload the expedite order check her registry maybe something new has appeared.
A.018 - October 2018 - Part Three
NITE Team 4’s Off-Net Intrusion Group (ONIGRU) 15 was set to receive Maria Sagastume on Oct 18 at La Aurora International Airport (GUA) in Guatemala City. However, it appears a third party contacted Guatemalan authorities and outbid us. Sagastume is now being held by the Guatemalan Armed Forces, who will transfer her to the other party at any moment.
Remember to read the briefing document,[http//tbd] it may contain useful information, and be sure to click the maltego nt4 entities in the support tab.

A.018 - Part Three : Phase 1
Difficulty: Advanced
  • Hint 1Briefing mentions a deportation document, what module can gather intel on people and organizations?

  • Hint 2The maltego nt4 entities gave you a person and two organizations, maybe they are connected.

  • Hint 3Since she is being deported, maybe it's considered a shipping transaction.

  • Hint 4 -- In the briefing there was an archive number, you can use it here,[archive.blackwatchmen.com] maybe you can cross-reference the departure and a certain vehicle leaving.

  • Hint 5 -- How much time does it take to get from the Phoenix-Mesa Airport (AZA) to Guatemala?

  • Hint 6 -- You have a departure time, how long it takes to get there and a list of vehicles leaving. Now just cross-reference.

A.018 - Part Three: Phase 2
Difficulty: Advanced
  • Hint 1The briefing mentions coordinates maybe you can use those in the StingerOS.

  • Hint 2You got a license plate from part one, now you need to track it.

  • Hint 3You can scan for wireless signatures, maybe that will help.

  • Hint 4There seem to be a lot of cell towers nearby, maybe you can find their domain and infiltrate their network.

  • Hint 5Sfuzzer and Fingerprint might help you find the correct subdomain.

  • Hint 6Now that you're inside their network, maybe you can use their celltowers to track the driver's phone.

  • Hint 7You've gotten his phone, now look for key individuals or facilities you can use in XKeyscore.

A.018 - Part Three: Phase 3
Difficulty: Advanced
  • Hint 1You got XKeyscore entities from the phone, maybe try to find out who is the captain, there should be some indication in the phone.

  • Hint 2Maybe if you try the Captain and the organization, you'll get something.

  • Hint 3You got a new entity, maybe that person has had further contact with the Captain.

  • Hint 4That email, it mentions a product being moved between two places, maybe it's illegal.

  • Hint 5 -- You need to find a name of a key individual, maybe a simple online search can help you out.

  • Hint 6 -- Remember Google is your friend here.

  • Hint 7 -- The key individual was vice-president at the time of the accusations against the administration.
13 条留言
Codemonkey 2021 年 8 月 9 日 下午 1:46 
I'm sure I'm being dumb, but I can't figure out the time table to make cross referencing work for A.018 - Part Three : Phase 1:

I got the departure time from the document from XKeyScore: 16:14 MST
Then I got the travel time from Google maps: 6 hr 40 min
So arrival time would be: 22:54 MST
The registered vehicle times are in CST, so arrival time then is: 23:54

The last vehicle recorded is at 21:49 , so that's not it. Then let's assume arrival is 23:54 on the previous day so that I would have to look at the first (military) vehicle leaving in the morning : nope that's not it either.

Where am I going wrong?
HiddenGuardian 2021 年 7 月 19 日 上午 5:59 
really? Once you submit the Commanding Officer that should be it mission over 100% completion.
Sawta 2021 年 5 月 7 日 上午 11:15 
I've entered the text for the final part of Phase 3, and the mission completed. Is the text supposed to stay there or go away? Because it's still there for me. Identify the Commanding Officer in charge of Sagastume's imprisonment.

I already put in the VPs name from CICIG and got a reward. Is that text about the CO supposed to disappear or stick around? Maybe I skipped a step?
dubesor 2020 年 11 月 17 日 下午 5:37 
ok turns out that just the game/case is illogical. Game leads you to believe it's taking place in 2018 but you need to forget that year and date entirely and only look at 2014/2015 . Nonsensical.
dubesor 2020 年 11 月 17 日 下午 5:16 
I am inside the phone of Simon Marroquin and I have gone over everything many times. I think that the CO is Teniente Jorje Estrada but game doesn't seem to access that or any other formats of his name. I checked all files and crossreferences everything ingame. Your google tip is not helpful at all........... I need a hint for how to get from hint 4 to hint 5. There are no names in between.
RBR M. Verstappen [bot] 2020 年 6 月 24 日 下午 1:20 
Still dont know to find the departure document at part 3 phrase 1. Would like some helps
Fabius_der_1 2020 年 4 月 27 日 上午 8:24 
@sars same problem.
did you make it
Sars 2020 年 3 月 23 日 上午 10:53 
Need a little help with part one phase 2:
I have tried the GPS location and the name for the Eloy Detention Center
but none of them work
erikwarming 2019 年 7 月 19 日 上午 7:34 
Its not the best mission. You have to google/wikipedia some stuff
erikwarming 2019 年 7 月 19 日 上午 6:09 
@jonopado a deep search of the domains reveal a subdomain. You can connect to this one with hydra. There you get the transport code