Welcome⚓︎

Introduction⚓︎
The SANS Holiday Hack Challenge 2025 dropped participants into a winter town taken over by gnomes. The gnomes were breaking things across city hall, the hotel, the park, and the retro shop. The challenge covers multi-domain CTF on a total of 27 objectives and five difficulty tiers.
I worked on 21 objective covering a wide range of discipline: hunting leaked SAS (Shared Access Signature) tokenand misconfigured Azure Storage accounts, exploiting IDOR (Insecure Direct Object Reference) vulnerabilities, cracking IMAP configurations, reverse engineering binaries, and performing RCE with privilege escalation.
Story⚓︎
ACT I
The Counter Hack crew is in the Neighborhood festively preparing for the holidays when they are suddenly overrun by lively Gnomes in Your Home! There must have been some magic in those Gnomes, because, due to some unseen spark, some haunting hocus pocus, they have come to life and are now scurrying around the Neighborhood.
ACT II
The Gnomes’ nefarious plot seems to involve stealing refrigerator parts. But why?
ACT III
The Gnomes want to transform the neighborhood so that it’s frozen solid year-round, an environmental disaster. But who is the mastermind behind the Gnomes’ wickedness?
Map⚓︎

Navigation tip
Even with less than 50 pages, there's still quite a bit of information to read through. To make things a little easier, you can use P or , to go to the previous section, N or . to navigate to the next section, and S, F, or / to open up the search dialog.
TL;DR if you keep pressing N or . from this point forward, you'll hit all the content in the right order!
Answers⚓︎
Act I⚓︎
1. Its All About Defang -
2. Neighborhood Watch Bypass -
3. Santa's Gift-Tracking Service Port -
4. Visual Networking Thinger -
5. Visual Firewall Thinger -
6. Intro to Nmap -
7. Blob Storage Challenge in the neighborhood -
8. Spare Key -
9. The Open Door -
10. Owner -
Act II⚓︎
11. Retro Recovery -
12. Mail Detective -
13. IDORable Bistro -
14. Dosis Network Down -
15. Rogue Gnome Identity Provider -
16. Quantgnome Leap -
17. Going in Reverse -
Act III⚓︎
18. Gnome Tea -
20. Snowcat RCE & Priv Esc -
21. Schrödinger's Scope -
23. On the Wire -