Investigate an account takeover via password reset

Not solved

A customer lost her account after clicking a genuine reset email. Work out how the attacker got the token and what they did with it.

Level
Advanced
Estimated time
~35 min
Points
0/95 pts
Questions
0/0 answered
OWASP
A07:2025
OWASP
A06:2025
CWE
CWE-640
CWE
CWE-644
soc-01 · read-only
Read-only shell. Type "help" for commands.