Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Ctf Forensics

ASecurity

CTF forensics playbook — quick wins on pcaps, memory dumps, disk images, and stego files: binwalk carving, Wireshark object export, Volatility's five commands that solve most memory challenges, steghide/zsteg/exiftool stego battery. Load when the handout is a capture, image, or dump file. Signals: "forensics"/"stego" category, .pcap/.pcapng, .mem/.raw/.vmem, .dd/.img/.E01, a lone .png/.jpg/.wav, "incident", "suspicious traffic".

20 stars
0 votes
0 copies
2 views
Added 10/5/2026
ai-agentsgonode

Works with

cli

Security Analysis

A100/100

Scanned 10/5/2026

$npx -y skills add NoorQureshi/SploitAgent --skill ctf-forensics --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Ctf Forensics?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Ctf Forensics
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/noorqureshi-ctf-forensics/badge)](https://www.skillsdirectory.com/skills/noorqureshi-ctf-forensics)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: ctf-forensics
description: >
  CTF forensics playbook — quick wins on pcaps, memory dumps, disk images, and stego files:
  binwalk carving, Wireshark object export, Volatility's five commands that solve most memory
  challenges, steghide/zsteg/exiftool stego battery. Load when the handout is a capture, image, or
  dump file. Signals: "forensics"/"stego" category, .pcap/.pcapng, .mem/.raw/.vmem, .dd/.img/.E01,
  a lone .png/.jpg/.wav, "incident", "suspicious traffic".
domain: ctf
type: technique
stability: learning
modes: [pentest, defense]
severity: medium
cwe: []
tools: [wireshark, tshark, binwalk, foremost, volatility3, exiftool, steghide, zsteg, strings, bulk_extractor]
schema_version: 1
---

# CTF forensics and stego

## When it applies
The handout is an artifact to investigate: a packet capture, memory dump, disk image, or an
innocent-looking media file. This skill is the CTF quick-win battery — the 80% of challenges that
fall to standard tooling run in the right order. For real-IR depth (timelines, root cause,
attacker methodology) defer to `defense-dfir-triage`, `defense-malware-triage`,
`defense-log-analysis`; here the only objective is finding the flag in the haystack.

## Why it works
CTF forensics artifacts are constructed, not organic: the flag was placed by an author using a
standard technique (appended data, an HTTP download, a deleted file, an LSB embedding), and each
technique has a canonical tool. Running the *standard battery in order* surfaces the planted
artifact faster than clever hypotheses, because the author used the same tools you have.

## Method
1. **Universal first pass (every file, 2 minutes).**
   ```
   file <f>; exiftool <f>; strings -n 8 <f> | grep -iE 'flag|pass|key|{' ; binwalk <f>
   ```
   `file` lying about the type (wrong extension/magic) is itself a classic stage one. Metadata
   (exiftool) hides flags in comment/author/GPS fields. `binwalk -eM` extracts embedded archives
   recursively — appended zip-after-image is the most common stage one of all.
2. **pcap (.pcap/.pcapng).**
   - Open in Wireshark; check *Protocol Hierarchy* and *Conversations* first — the odd protocol
     or the one giant stream is the lead.
   - Export objects: *File → Export Objects → HTTP/SMB/TFTP* — downloaded files (exfil zips,
     images) come out whole.
   - Follow TCP streams; flag-in-cleartext-chat is common. `tshark -r cap.pcap -Y 'http' -T fields
     -e http.request.uri` for quick scripting.
   - Exfil channels: DNS (long encoded subdomains — decode base32/64/hex of the labels), ICMP
     payload bytes, TLS where a `keys.log`/RSA key is provided (set the key log in preferences).
   - USB pcaps: `usb.capdata` keystroke/mouse reconstruction (map HID codes back to characters).
3. **Memory dumps (.mem/.raw/.vmem) — Volatility 3, the five that solve most:**
   ```
   vol -f dump.mem windows.info            # profile/OS
   vol -f dump.mem windows.pslist          # the odd process (notepad, mspaint, truecrypt)
   vol -f dump.mem windows.cmdline         # commands with passwords/flags as args
   vol -f dump.mem windows.filescan | grep -iE 'flag|secret|\.zip|\.png'
   vol -f dump.mem windows.dumpfiles --physaddr <addr>   # carve the file out
   ```
   Then per the story: `hashdump` (crack the SAM), `malfind`, clipboard/notepad plugins, browser
   history plugins. And the cheap shot first: `strings dump.mem | grep flag{`.
4. **Disk images (.dd/.img/.E01).** Mount or autopsy-free carve:
   - `fls -r <img>` / `icat` (Sleuth Kit) — list and read files; **deleted files** (`fls -rd`)
     are where flags hide; recover by inode with `icat`.
   - `foremost -i <img> -o out/` or `photorec` — carve by signature when the filesystem is
     damaged or the challenge is raw.
   - `bulk_extractor <img>` — one-shot sweep of URLs, emails, credit cards, keys; grep its output.
   - Check slack/unallocated space and alternate partitions (`mmls` shows the layout; a hidden
     second partition is a classic).
5. **Stego battery (images/audio) — run all, not one.**
   - PNG: `zsteg -a img.png` (LSB and friends, automatic); `pngcheck -v` for odd chunks.
   - JPEG: `steghide extract -sf img.jpg` (try empty passphrase first, then challenge title /
     description words); `stegseek` for fast passphrase cracks; `outguess`; check DCT with
     `stegoveritas` which runs the whole battery at once.
   - Any image: inspect the planes visually (StegSolve-style: bit-plane views reveal QR codes and
     text), compare against an original if the challenge gives one (diff = the payload).
   - Audio: open in Audacity — spectrogram view shows drawn text/QR; morse in the waveform;
     reversed audio; DTMF tones (decode with a dial-tone decoder).
   - Whitespace/zero-width text in provided .txt files; `snow` for whitespace stego.
6. **Chain the stages.** CTF forensics is layered: binwalk gives a password-protected zip → the
   password is in pcap stream 7 → the zip has a QR image → zsteg on the QR. When a stage yields a
   password/key, apply it to every locked artifact you already hold.

## Gotchas
- **Wrong file magic is stage one, not a broken download** — fix the header (`file` says data but
  binwalk sees a zip at offset 0x100 → carve from there).
- **`binwalk -e` without `-M`** misses nested archives — always recurse; also watch for
  false-positive signatures at huge offsets.
- **Volatility profile mismatches fail silently** — if `pslist` looks empty/garbage, the image is
  a different OS build or it's a Linux dump (needs a custom profile / `linux.*` plugins).
- **Steghide passphrases come from the challenge text** — title, description, lyrics of the
  linked song. Try them before brute-forcing.
- **Encrypted volumes (VeraCrypt) in disk images** — the password is elsewhere in the challenge
  (memory dump, deleted note); don't brute a VeraCrypt container, hunt the hint.
- **Corrupted-by-author files** (QR with wrong alignment patterns, PNG with bad CRC) — repair
  tools (`pcrt`, online QR fixers) beat redrawing by hand.

## Verify success
A flag in the event format extracted from the artifact, with a reproducible extraction path (the
exact tool chain and parameters) written down — other players' flags differ, so "found a string"
must survive re-running the battery from the original handout file.

## References
Volatility 3 docs; Sleuth Kit (`fls`/`icat`/`mmls`); Wireshark object export; stegoveritas,
zsteg, stegseek. IR-grade methodology: `defense-dfir-triage`, `defense-malware-triage`.
Triage via `ctf-methodology`.

Attribution

NoorQureshiNoorQureshi
View sourceSee grades on GitHubMore from NoorQureshi →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698431 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →