ctf-forensics

Provides digital forensics and signal analysis techniques for CTF challenges. Use when analyzing disk images, memory dumps, event logs, network captures, cryptocurrency transactions, steganography, PDF analysis, Windows registry, Volatility, PCAP, Docker images, coredumps, side-channel power traces,

By ljagiello · 7,521 installs

npx skills add ljagiello/ctf-skills --skill ctf-forensics

Source repository · Upstream listing

CTF Forensics & Blockchain Quick reference for forensics CTF challenges. Each technique has a one liner here; see supporting files for full details. Prerequisites Python packages (all platforms): Linux (apt): macOS (Homebrew): Ruby gems (all platforms): Additional Resources [3d printing.md](3d printing.md) 3D printing forensics (PrusaSlicer binary G code, QOIF, heatshrink) [windows.md](windows.md) Windows forensics (registry, SAM, event logs, recycle bin, NTFS alternate data streams, USN journal, PowerShell history, Defender MPLog, WMI persistence, Amcache) [network.md](network.md) Network forensics basics (tcpdump, TLS/SSL keylog decryption, TLS master key extraction from coredump, Wireshark, PCAP, port scanning, SMB3 decryption, 5G/NR protocols, WordPress recon, credentials, USB HID steno, BCD encoding, HTTP file upload exfiltration, split archive reassembly via timestamp ordering) [network advanced.md](network advanced.md) Advanced network forensics (packet interval timing encoding, NTLMv2 hash cracking, TCP flag covert channel, DNS last byte steganography, DNS trailing byte binary encoding, multi layer PCAP with XOR + ZIP and mDNS key, Brotli decompression bomb seam analysis, SMB RID recycling via LSARPC, Timeroasting MS SNTP hash extraction, dnscat2 reassembly, RADIUS shared secret cracking, RC4 stream identification, ICMP payload byte rotation, ICMP ping time delay covert channel) [peripheral capture.md](peripheral capture.md) USB/HID/Bluetooth peripheral traffic reconstruction (USB HID mouse/pen drawing recovery, USB HID keyboard capture decoding, USB keyboard LED Morse code exfiltration, USB HID keyboard arrow key navigation tracking, Bluetooth RFCOMM packet reassembly) [disk and memory.md](disk and memory.md) Core disk/memory forensics (Volatility, disk mounting/carving, VM/OVA/VMDK, VMware snapshots, GIMP raw memory dump visual inspection, coredumps, Windows KAPE triage, PowerShell ransomware, Android forensics, Docker container forensics, cloud storage forensics, BSON reconstruction, TrueCrypt/VeraCrypt mounting) [disk advanced.md](disk advanced.md) Advanced disk and memory techniques (deleted partitions, ZFS forensics, GPT GUID encoding, VMDK sparse parsing, memory dump string carving, ransomware key recovery, WordPerfect macro XOR, minidump ISO 9660 recovery, APFS snapshot recovery, RAID 5 XOR recovery, HFS+ resource fork recovery, Kyoto Cabinet hash DB forensics, SQLite edit history reconstruction) [disk recovery.md](disk recovery.md) Disk recovery and extraction patterns (LUKS master key recovery, PRNG timestamp seed brute force, VBA macro binary recovery, FemtoZip decompression, XFS filesystem reconstruction, tar duplicate entry extraction, nested matryoshka filesystem extraction, anti carving via null byte interleaving, BTRFS subvolume/snapshot recovery, FAT16 free space data recovery, FAT16 deleted file recovery via Sleuth Kit fls/icat, ext2 orphaned inode recovery via fsck, corrupted ZIP header repair) [steganography.md](steganography.md) General steganography (binary border stego, PDF multi layer stego, SVG keyframes, PNG reorder, file overlays, GIF frame diff Morse code, GZSteg + spammimic, spreadsheet frequency recovery, Kitty terminal graphics protocol decoding, ANSI escape sequence steganography, autostereogram solving, two layer byte+line interleaving, multi stream video container stego, progressive PNG layered XOR decryption, QR code reconstruction from curved reflection) [stego image.md](stego image.md) Image specific steganography (JPEG unused DQT table LSB, BMP bitplane QR extraction, image puzzle reassembly, F5 JPEG DCT ratio detection, PNG unused palette entry stego, QR code tile reconstruction, seed based pixel permutation + multi bitplane QR, JPEG thumbnail pixel to text mapping, conditional LSB with pixel filtering, JPEG slack space, nearest neighbor interpolation stego, RGB parity steganography) [stego advanced.md](stego advanced.md) Advanced steganography part 1: audio and signal techniques (FFT frequency domain, DTMF audio, SSTV+LSB, DotCode barcode, custom frequency dual tone keypad, multi track audio differential subtraction, cross channel multi bit LSB, audio FFT musical notes, audio metadata octal encoding, nested tar whitespace encoding, DeepSound audio stego with password cracking, audio waveform binary encoding, audio spectrogram hidden QR) [stego advanced 2.md](stego advanced 2.md) Advanced steganography part 2: video, image transform, and format specific techniques (video frame accumulation, reversed audio, video frame averaging, JPEG XL TOC permutation steganography, Arnold's Cat Map descrambling, high resolution SSTV custom FM demodulation, MJPEG FFD9 trailing byte stego, EXIF zlib + Stegano pixel patterns, PDF xref covert channel, ANSI escape code stego, pixel wise ECB deduplication) [linux forensics.md](linux forensics.md) Linux/app forensics (log analysis, Docker image forensics, attack chains, browser credentials, Firefox history, TFTP, TLS weak RSA, USB audio, Git directory recovery, KeePass v4 cracking, Git reflog/fsck squash recovery, browser artifact analysis (Chrome/Chromium/Firefox history, cookies, downloads, local storage, session restore), corrupted git blob repair via byte brute force, VBA macro Excel cell data to ELF binary extraction, Python in memory source recovery via pyrasite) [signals and hardware.md](signals and hardware.md) Hardware signal decoding with decode code (VGA frame parsing, HDMI TMDS symbol decode, DisplayPort 8b/10b + LFSR descrambler), Voyager Golden Record audio, Saleae Logic 2 UART decode, Flipper Zero .sub files, side channel power analysis (DPA), keyboard acoustic side channel, CD audio disc image steganography (CIRC de interleaving + spiral rendering), caps lock LED Morse code from video, Linux input event keylogger dump parsing, serial UART from WAV audio, USB MIDI Launchpad grid reconstruction When to Pivot If you recover an encrypted blob and the hard part becomes RSA, AES, or lattice work, switch to /ctf crypto . If the evidence really points to malware staging, beacon config extraction, or packed samples, switch to /ctf malware . If the artifact is a web app backup or API dump and the remaining problem is application logic, switch to /ctf web . If the forensic evidence is really an encoding puzzle, steganography trick, or esoteric format rather than true forensics, switch to /ctf misc . If you need to trace infrastructure, attribute actors, or investigate public records from forensic findings, switch to /ctf osint . If the recovered artifact is a compiled binary or firmware that needs disassembly and analysis, switch to /ctf reverse . Quick Start Commands See [disk and memory.md](disk and memory.md) for full Volatility plugin reference, VM forensics, and coredump analysis. Log Analysis See [linux forensics.md](linux forensics.md) for Linux attack chain analysis and Docker image forensics. Windows Event Logs (.evtx) Key Event IDs: 1001 Bugcheck/reboot 1102 Audit log cleared 4720 User account created 4781 Account renamed RDP Session IDs (TerminalServices LocalSessionManager): 21 Session logon succeeded 24 Session disconnected 1149 RDP auth succeeded (RemoteConnectionManager, has source IP) See [windows.md](windows.md) for full event ID tables, registry analysis, SAM parsing, USN journal, and anti forensics detection. NTFS Alternate Data Streams (ADS): Hidden data attached to files via named NTFS streams. Invisible to dir /Explorer. Detect with fls r image.dd grep ":" , extract with icat . See [windows.md](windows.md ntfs alternate data streams). When Logs Are Cleared If attacker cleared event logs, use these alternative sources: 1. USN Journal ($J) File operations timeline (MFT ref, timestamps, reasons) 2. SAM registry Account creation from key last modified timestamps 3. PowerShell history ConsoleHost history.txt (USN DATA EXTEND = command timing) 4. Defender MPLog Separate log with threat detections and ASR events 5. Prefetch Program execution evidence 6. User profile creation First login time (profile dir in USN journal) See [windows.md](windows.md) for detailed parsing code and anti forensics detection checklist. Steganography Binary border stego: Black/white pixels in 1px image border encode bits clockwise FFT frequency domain: Image data hidden in 2D FFT magnitude spectrum; try np.fft.fft2 visualization DTMF audio: Phone tones encoding data; decode with multimon ng a DTMF Multi layer PDF: Check hidden comments, post EOF data, XOR with keywords, ROT18 final layer SSTV + LSB: SSTV signal may be red herring; check 2 bit LSB of audio samples with stegolsb SVG keyframes: Animation keyTimes / values attributes encode binary/Morse via fill color alternation PNG chunk reorder: Fix chunk order: IHDR → ancillary → IDAT (in order) → IEND File overlays: Check after IEND for appended archives with overwritten magic bytes APNG frame extraction: Animated PNG has multiple frames; extract with apngdis or parse fdAT / fcTL chunks. See [steganography.md](steganography.md apng animated png frame extraction icectf 2016). PNG height/CRC manipulation: Modify IHDR height field, brute force until CRC matches to reveal hidden rows. See [steganography.md](steganography.md png heightcrc manipulation for hidden content h4ckit ctf 2016). Pixel coordinate chain stego: Linked list traversal where R=data byte, G/B=next pixel coordinates. See [stego image.md](stego image.md pixel coordinate chain steganography h4ckit ctf 2016). AVI frame differential: XOR consecutive video frames to reveal hidden data in pixel differences. See [stego image.md](stego image.md avi frame differential pixel steganography h4ckit ctf 2016). Custom freq DTMF: Non standard dual tone frequencies; generate spectrogram first ( ffmpeg i audio lavfi showspectrumpic ), map custom grid to keypad digits, decode variable length ASCII JPEG DQT LSB: Unused quantization tables (ID 2, 3) carry LSB encoded data; access via Image.open().quantization and extract bit 0 from each of 64 values Multi track audio subtraction: Two nearly identical audio tracks in MKV/video; sox m a0.wav " sox a1.wav p vol 1" diff.wav cancels shared content, flag appears in spectrogram of difference signal (5 12 kHz band) Packet interval timing: Identical packets with two distinct interval values (e.g., 10ms/100ms) encode binary; filter by interface, compute inter packet deltas, threshold to bits See [steganography.md](steganography.md), [stego advanced.md](stego advanced.md), and [stego advanced 2.md](stego advanced 2.md) for full code examples and decoding workflows. PDF Analysis Advanced PDF stego (Nullcon 2026 rdctd): Six techniques invisible text separators, URI annotations with escaped braces, Wiener deconvolution on blurred images, vector rectangle QR codes, compressed object streams ( mutool clean d ), document metadata fields. See [steganography.md](steganography.md) for full PDF steganography techniques and code. Disk / VM / Memory Forensics See [disk and memory.md](disk and memory.md) for full Volatility plugin reference, VM forensics, and VMware snapshots. See [disk advanced.md](disk advanced.md) for deleted partition recovery, ZFS forensics, and ransomware analysis. Windows Password Hashes See [windows.md](windows.md) for SAM details and [network advanced.md](network advanced.md) for NTLMv2 cracking from PCAP. Bitcoin Tracing Use mempool.space API: https://mempool.space/api/tx/<TXID Peel chain: ALWAYS follow LARGER output; round amounts indicate peels Uncommon File Magic Bytes Magic Format Extension Notes OggS Ogg container .ogg Audio/video RIFF RIFF container .wav , .avi Check subf