Skip to content
Back to skills

Ctf Forensics

ASecurity

CTF forensics playbook — quick wins on pcaps, memory dumps, disk images, and stego files: binwalk carving, Wireshark object export, Volatility's five commands that solve most memory challenges, steghide/zsteg/exiftool stego battery. Load when the handout is a capture, image, or dump file. Signals: "forensics"/"stego" category, .pcap/.pcapng, .mem/.raw/.vmem, .dd/.img/.E01, a lone .png/.jpg/.wav, "incident", "suspicious traffic".

  • 20 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added October 5, 2026
ai-agentsgonode

Works with

  • cli

Security analysis

A100/100

Scanned October 5, 2026

npx -y skills add NoorQureshi/SploitAgent --skill ctf-forensics --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Ctf Forensics?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Ctf Forensics
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/noorqureshi-ctf-forensics/badge)](https://www.skillsdirectory.com/skills/noorqureshi-ctf-forensics)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: ctf-forensics
description: >
  CTF forensics playbook — quick wins on pcaps, memory dumps, disk images, and stego files:
  binwalk carving, Wireshark object export, Volatility's five commands that solve most memory
  challenges, steghide/zsteg/exiftool stego battery. Load when the handout is a capture, image, or
  dump file. Signals: "forensics"/"stego" category, .pcap/.pcapng, .mem/.raw/.vmem, .dd/.img/.E01,
  a lone .png/.jpg/.wav, "incident", "suspicious traffic".
domain: ctf
type: technique
stability: learning
modes: [pentest, defense]
severity: medium
cwe: []
tools: [wireshark, tshark, binwalk, foremost, volatility3, exiftool, steghide, zsteg, strings, bulk_extractor]
schema_version: 1
---

# CTF forensics and stego

## When it applies
The handout is an artifact to investigate: a packet capture, memory dump, disk image, or an
innocent-looking media file. This skill is the CTF quick-win battery — the 80% of challenges that
fall to standard tooling run in the right order. For real-IR depth (timelines, root cause,
attacker methodology) defer to `defense-dfir-triage`, `defense-malware-triage`,
`defense-log-analysis`; here the only objective is finding the flag in the haystack.

## Why it works
CTF forensics artifacts are constructed, not organic: the flag was placed by an author using a
standard technique (appended data, an HTTP download, a deleted file, an LSB embedding), and each
technique has a canonical tool. Running the *standard battery in order* surfaces the planted
artifact faster than clever hypotheses, because the author used the same tools you have.

## Method
1. **Universal first pass (every file, 2 minutes).**
   ```
   file <f>; exiftool <f>; strings -n 8 <f> | grep -iE 'flag|pass|key|{' ; binwalk <f>
   ```
   `file` lying about the type (wrong extension/magic) is itself a classic stage one. Metadata
   (exiftool) hides flags in comment/author/GPS fields. `binwalk -eM` extracts embedded archives
   recursively — appended zip-after-image is the most common stage one of all.
2. **pcap (.pcap/.pcapng).**
   - Open in Wireshark; check *Protocol Hierarchy* and *Conversations* first — the odd protocol
     or the one giant stream is the lead.
   - Export objects: *File → Export Objects → HTTP/SMB/TFTP* — downloaded files (exfil zips,
     images) come out whole.
   - Follow TCP streams; flag-in-cleartext-chat is common. `tshark -r cap.pcap -Y 'http' -T fields
     -e http.request.uri` for quick scripting.
   - Exfil channels: DNS (long encoded subdomains — decode base32/64/hex of the labels), ICMP
     payload bytes, TLS where a `keys.log`/RSA key is provided (set the key log in preferences).
   - USB pcaps: `usb.capdata` keystroke/mouse reconstruction (map HID codes back to characters).
3. **Memory dumps (.mem/.raw/.vmem) — Volatility 3, the five that solve most:**
   ```
   vol -f dump.mem windows.info            # profile/OS
   vol -f dump.mem windows.pslist          # the odd process (notepad, mspaint, truecrypt)
   vol -f dump.mem windows.cmdline         # commands with passwords/flags as args
   vol -f dump.mem windows.filescan | grep -iE 'flag|secret|\.zip|\.png'
   vol -f dump.mem windows.dumpfiles --physaddr <addr>   # carve the file out
   ```
   Then per the story: `hashdump` (crack the SAM), `malfind`, clipboard/notepad plugins, browser
   history plugins. And the cheap shot first: `strings dump.mem | grep flag{`.
4. **Disk images (.dd/.img/.E01).** Mount or autopsy-free carve:
   - `fls -r <img>` / `icat` (Sleuth Kit) — list and read files; **deleted files** (`fls -rd`)
     are where flags hide; recover by inode with `icat`.
   - `foremost -i <img> -o out/` or `photorec` — carve by signature when the filesystem is
     damaged or the challenge is raw.
   - `bulk_extractor <img>` — one-shot sweep of URLs, emails, credit cards, keys; grep its output.
   - Check slack/unallocated space and alternate partitions (`mmls` shows the layout; a hidden
     second partition is a classic).
5. **Stego battery (images/audio) — run all, not one.**
   - PNG: `zsteg -a img.png` (LSB and friends, automatic); `pngcheck -v` for odd chunks.
   - JPEG: `steghide extract -sf img.jpg` (try empty passphrase first, then challenge title /
     description words); `stegseek` for fast passphrase cracks; `outguess`; check DCT with
     `stegoveritas` which runs the whole battery at once.
   - Any image: inspect the planes visually (StegSolve-style: bit-plane views reveal QR codes and
     text), compare against an original if the challenge gives one (diff = the payload).
   - Audio: open in Audacity — spectrogram view shows drawn text/QR; morse in the waveform;
     reversed audio; DTMF tones (decode with a dial-tone decoder).
   - Whitespace/zero-width text in provided .txt files; `snow` for whitespace stego.
6. **Chain the stages.** CTF forensics is layered: binwalk gives a password-protected zip → the
   password is in pcap stream 7 → the zip has a QR image → zsteg on the QR. When a stage yields a
   password/key, apply it to every locked artifact you already hold.

## Gotchas
- **Wrong file magic is stage one, not a broken download** — fix the header (`file` says data but
  binwalk sees a zip at offset 0x100 → carve from there).
- **`binwalk -e` without `-M`** misses nested archives — always recurse; also watch for
  false-positive signatures at huge offsets.
- **Volatility profile mismatches fail silently** — if `pslist` looks empty/garbage, the image is
  a different OS build or it's a Linux dump (needs a custom profile / `linux.*` plugins).
- **Steghide passphrases come from the challenge text** — title, description, lyrics of the
  linked song. Try them before brute-forcing.
- **Encrypted volumes (VeraCrypt) in disk images** — the password is elsewhere in the challenge
  (memory dump, deleted note); don't brute a VeraCrypt container, hunt the hint.
- **Corrupted-by-author files** (QR with wrong alignment patterns, PNG with bad CRC) — repair
  tools (`pcrt`, online QR fixers) beat redrawing by hand.

## Verify success
A flag in the event format extracted from the artifact, with a reproducible extraction path (the
exact tool chain and parameters) written down — other players' flags differ, so "found a string"
must survive re-running the battery from the original handout file.

## References
Volatility 3 docs; Sleuth Kit (`fls`/`icat`/`mmls`); Wireshark object export; stegoveritas,
zsteg, stegseek. IR-grade methodology: `defense-dfir-triage`, `defense-malware-triage`.
Triage via `ctf-methodology`.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…