August 2026 · Personal Project

TraceLabs DEFCON 34 CTF MVO Write-up

I won the Most Valuable OSINT for TraceLabs' Search Party CTF at DEFCON 32

This is the write-up for the CTF so others may be able to follow a similar pattern in their search.

OSINTEthicsWrite-up
The submission picture for the MVO

If you are here to read the more technical portion of my write-up, and not my own personal experience with the CTF and TraceLabs, then skip down to The MVO.

// Introduction

This year at DEFCON 34, I had the great pleasure of participating in TraceLab's OSINT4GOOD Capture The Flag (CTF). From it I won the award of Most Valuable Open-Source Intelligence (OSINT) for the intel I was able to find! This is my experience with the CTF and also my technical write-up for my methods in finding the Most Valuable OSINT (MVO).

I had never heard of TraceLabs before, but I was instantly hooked on the idea of using OSINT to help find missing people. OSINT is one of those Cybersecurity skills that I find absolutely fascinating, but I don't get a lot of opportunities to practice because it is hard to do in an ethical way. I've spent time testing OSINT tools on myself, but that isn't entirely unbiased since I know what I should be finding (like reading a book that you know the ending to). I refuse to use OSINT tools on friends and family, as all it takes is one piece of information to change the way I view someone, and I want to give them the chance to tell me that themselves.

So TraceLabs gives a great opportunity to try out OSINT in a way that not only is ethical, but can even be helpful (when practiced properly) through their SearchParty CTF challenges! Every few months, TraceLabs hosts a competition where they select a few real missing persons cases that are currently unsolved.

The rules are pretty straightforward: use only passive OSINT techniques to try to gather as much intel about the missing persons as possible to help locate them. Passive OSINT techniques are techniques that don't require any interaction with outside sources to gather intel. Essentially we are a bunch of civilian detectives trying to find useful evidence online. You wouldn't let a civilian walk across a crime scene, so hacking into accounts is a no-go. As well, a bunch of civilian detectives sending in news articles about the disappearance isn't very helpful to the police, who would likely know all of the reported info already, so those were not accepted for the CTF either.

What we are looking for is any publicly facing information on the internet that can point us in the direction of hopefully being able to find the missing person. I highly recommend reading previous CTF's write-ups because some of the intel people have found in a mere 4 hours of searching is amazing!

// Preparing for the CTF

This section is a little misleading, as I barely did any preparation for this CTF. Though I do have plans on what I want to do for the next one that I will mention at the end of this section.

For the past few years, my Mom and I have been going to DEFCON together. I was studying Cybersecurity and saw it as a good opportunity to learn from people who are active in the field with their most cutting edge techniques. My mom has always been a very logical problem solver, so even though she doesn't know much about the technology featured at DEFCON, she still is able to sort out a lot of the puzzles featured at different booths. The day before the CTF, we spent a few hours doing a scavenger hunt and listening to talks. My mom went to a panel by TraceLabs about using OSINT to find missing people, and we both wanted to learn more at the OSINT4Good booth at DEFCON. When we made our way over, we saw the signs they had up about their CTF and decided to register.

Unlike other CTFs at DEFCON, signup for the TraceLabs CTF was very thorough due to the delicate nature of dealing with real, active missing persons cases. They gave a distinct checklist that made sure that everyone who signed up understood what they were doing, knew how to participate within the guidelines they setup, and knew how to communicate with the TraceLabs coaches throughout the event. So, while I wasn't prepared inherently for this CTF, such as setting up sock puppet accounts ahead of time, I did start it feeling very prepared from all of TraceLabs' explanation of the event.

Next time, I plan to set up sock puppet accounts for most social media like Facebook, Instagram, and Twitter. Sock puppet accounts are about what they sound like, they are a facade account without a real person attached. This is important for the CTF as we don't know these missing people, and we don't want to risk someone coming back to us directly asking why we are snooping on social media. A sock puppet account can be deleted out of existence right after the CTF is over with, ideally, no outward evidence it ever existed

Similarly, I also want to configure TraceLabs' virtual machine for the event to make sure the data stays sandboxed from the rest of my computer. It's important to not hold onto any information after the event, and, to be honest, it felt strange clearing out my screenshots folder of pictures of people I don't know. The virtual machine is a computer within your computer. It uses all of your computer's hardware so it runs the same as any other computer, but because all of its data is held within your computer, you can wipe it whenever you need to. I would have been able to set it up at DEFCON, but their internet was spotty and I ended up using a personal hot spot. Since virtual machine files are very large downloads, I didn't want to use up all my data just to run out at the starting line.

I also think I want to set up a more thorough plan on how I want to use my 4 hours for the CTF. Going into this one, I had no idea how many cases we would be given or if each team was going to be assigned a case. It turns out that we had to find as much information that we could for 5 individuals in the 4 hours. To make sure everyone gets a fair search, I would like to set timers for myself to switch between the cases.

// The Most Valuable OSINT

Now onto what you all have been waiting for: What was the Most Valuable OSINT?

The intel was related to Missing Person 1 (MP1). Out of all 5 cases, this one was the longest open case, so it felt unlikely we would find anything new. I didn't work on the cases chronologically, so I didn't notice that it was such an old case until my Mom pointed it out. The Be On The Lookout (BOLO) had a picture of MP1, their legal name, where they went missing (for this competition all cases went missing in Las Vegas, where DEFCON is held), a description of what they were wearing, and a description of the vehicle they were last seen in.

For me, the first step with any OSINT is a simple search of the name. I used DuckDuckGo for the CTF as my main search engine as I wanted to avoid any AI usage (it's not prohibited but it is an ethical grey zone for this kind of search see Ethical Considerations). The search of MP1's name was not very helpful. Because the case had been going on for so long, it got picked up by a true crime podcast and gone viral. That muddies the waters substantially in doing any useful OSINT as virality-chasing news outlets will happily copy one another's homework and add their own embellishing speculations to each post. It's hard to tell what is real information that we could go off of in our search, and what is stuff that got made up to make the story look more interesting. It's an unfortunate reality of many cases that get popular via the True Crime genre.

I was feeling really defeated, coming off dead ends for two of the other MP cases. How was I supposed to find anything real about this person, when so many people are happy to make stuff up about them for clicks?

That's when my Mom pointed out from her own search of MP1's name that one of the news outlets mentioned an alias of MP1. The alias wasn't very original so searching that alone still didn't come up with any information about MP1. However, searching "Las Vegas "[MP1 Alias]"" came up with a hit of a Facebook account. The reason I put quotations around the alias was to narrow the search to only results that included the alias directly. This is called a "search operator" and the use of search operators to find sensitive information is called "dorking."

The Facebook account matched MP1's alias and location and had a truckload of pictures posted on the account. None of the pictures were from after MP1 went missing unfortunately, so no leads there. However, the pictures themselves offer up a lot of information about MP1. To completely verify that the account belonged to MP1, I took a few of the pictures and tested them in a facial recognition software, PimEyes. One of the requirements for the CTF is that all evidence can't be behind a paywall; while PimEyes has a premium version, I only used the free access features so that my results can be replicated. PimEyes was a success and matched the Facebook photos to MP1's BOLO picture despite the alias not matching the legal name listed on the BOLO. We have solid proof that the facebook page belonged to MP1. For my submission, I took a screenshot of the PimEyes results next to the Facebook page (in the image, this is labelled as 1).

Digging further into MP1's Facebook, I noticed they had a lot of photos of another person on their account. The photos were of them together in a car and of that person specifically driving the car. Whoever this person was (for convenience I am going to call them A), they were clearly very close with MP1 and may have some leads to their whereabouts. Facebook also has the feature of listing your romantic relationships if they also have a Facebook account, and lo and behold, MP1 listed that they were engaged.

Now the Facebook account for the fiancee to MP1 looked like it belonged to A, but it seemed a bit hard to prove. They had 2 pictures of themselves on the profile: one from somewhat far away where they were standing next to a vehicle, and one that was a dark side-profile where it looked like they were driving. One of the things I noticed immediately in these pictures is the vehicle in the first picture exactly matched the vehicle listed in the BOLO (#2 in the image), but the picture was cropped right at the license plate. That means that I really needed to verify that A owned this Facebook account, since that could be a gigantic lead!

Looking closer at MP1's Facebook, I realized there was a series of pictures of A that looked very similar to the side-profile picture: A was driving, wearing the same shirt in both pictures, and the backgrounds were of the same desert landscape. However, in these photos A was smiling and facing the camera--something a facial recognition software would a lot more easily place. I decided to throw the photos of A from MP1's Facebook into PimEyes and see what comes up.

PimEyes had 2 hits, and they were pictures I hadn't seen before (#3 in the image). A looked older in the pictures, so they were more recent than the ones on the Facebook accounts. PimEyes will tell users what website domain they sourced the images from, but you have to pay for them to link you to the specific webpage. One of the pictures came from a fairly unique url of a local news website for a locality in a different state (think something like "BuffaloNewYorkNews.com" which it wasn't that) and the other was from a Go Fund Me. I decided to look up the news website, since I thought it would be easier to find the news webpage than finding an image on a large website like Go Fund Me.

To be able to link A to the photo and to the fiancee's Facebook (remember I still hadn't proved that account was for sure A's account), I decided to look up the news website with A's name that was listed on the Facebook account. The search looked like "site:[news url] "[A's Name]"" using the search operators DuckDuckGo has for searching for results from a specific url. It was a hit and I found the news webpage with the picture that PimEyes had found! That means that the fiancee's Facebook account was A's for sure, and A had a picture of themselves standing next to a vehicle matching the BOLO vehicle description.

You're probably wondering, "What was the news article featuring A about?" Unfortunately, it was to announce A's passing. After MP1 had gone missing, A had moved towns and then passed away a few years later. The news article listed the funeral home that hosted the obituary, and searching "[funeral home name] "[A's name]"" brought me to their obituary (#4 in image). This is a really sad outcome with this case, but regardless this information is all helpful in aiding the search for MP1.

After this, I made sure to take screenshots of all the evidence I had found. I crudely Photoshopped the screenshots chronologically into one image, since submissions for the CTF only allowed for one image. I then wrote a short description of the evidence I found, linking it to the screenshots given in the submission. I don't have access to the description I wrote, but I remember I specifically wrote it in the same chronological order of how I found each evidence piece. I found that was the easiest to follow, and made the evidence easy to understand.

It took me a total of about an hour and a half to find and submit this information. From the start of me searching MP1's legal name to finding A's obituary, I would say it took about an hour. Then it took me half an hour to make my submission. I know I could have drawn out each part of the search into a submission to maximize the amount of points I would get, but submissions could get accepted or rejected. It was important to me that all the information I found was all linked together to be easily understood, and separating it risked having evidence rejected for things like syntax errors or not being understood without the previous context. In the end, what's most important to me is finding these people and not winning the competition.

// Conclusion

I really didn't know that this would win me anything at all. Prior to this submission, I had 2 submissions accepted and 2 rejected, so I felt like it was luck of the draw if this submission went through.

I am really thankful to my Mom throughout this CTF. She kept me focused on the goal of finding evidence that was going to help not what would get us points, and despite her downplaying it if you ask, she did help find information that lead me to finding the right stuff. It was important to her that we looked into all the cases, especially the cases that are of missing women of color and indigenous women who go missing and don't get found. I know without her I would have kept myself banging my head against the wall of meaningless dead ends rather than backing up and trying again.

After the event was over, we found ourselves very low on the leader board and sad for all these people who are out there being missed by their friends and family. We decided to go to a sports bar nearby and get some food to decompress. While we were there, I watched the winners get announced over the TraceLabs Discord server, and watched as the last winners, the Most Valuable OSINT (MVO), get posted. My first thought was "Oh, that's cool that they award the most helpful OSINT" then I looked and saw our team name: Snack Overflow. I quickly told my Mom and we celebrated our astonishing win.

The TraceLabs team that oversaw the competition said about the MVO, "This award goes to the team that submits a piece of intelligence that is either highly actionable or well documented, or both. In this case, it was both." While I don't know specifics on how TraceLabs takes action with the evidence, I am really glad to have helped with what otherwise is considered a cold case. I am also glad that taking so long to make sure my submission was understandable paid off in its documentation.

I learned so much from this competition, and I feel ready to work on the next one. Thank you to TraceLabs for hosting such an awesome event!