# eCPPT - Powershell for Pentesters CTF 1 Flag 4

**URL:** <https://legacy-community.ine.com/t/ecppt-powershell-for-pentesters-ctf-1-flag-4/5968>\
**Category:** Penetration Testing Professional\
**Tags:** red\
**Created:** [June 8, 2025, 4:55pm UTC](https://legacy-community.ine.com/t/ecppt-powershell-for-pentesters-ctf-1-flag-4/5968 "2025-06-08T16:55:35Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![MarwanKandeel](https://avatars.discourse-cdn.com/v4/letter/m/eb9ed0/32.png) [@MarwanKandeel](https://legacy-community.ine.com/u/MarwanKandeel)\
**Post date:** [June 8, 2025, 4:55pm UTC](https://legacy-community.ine.com/t/ecppt-powershell-for-pentesters-ctf-1-flag-4/5968/1 "2025-06-08T16:55:35Z")

</div>

Hi,

I’m stuck with CTF 1 (the first lab) flag 4. I have been trying for days with not luck. I compromised the web.prod machine pivoting from server.prod. I was able to open a session using Evil-WINRM. I even have powershell session opened on web.prod. I did even exploit a script and elevated the credentials to administrative.

The task says flag 4 is available on C drive. I was able to browse the entire file system but nothing was there. I browsed all possible folders even hidden ones. I ran a search task with recursive on all folders including hidden ones and couldn’t find flag 4.

Please tell me where is it located?
