ctf-forensics
Provides digital forensics and signal analysis techniques for CTF challenges. Use when analyzing disk images, memory dumps, event logs, network captures, cryptocurrency transactions, steganography, PDF analysis, Windows registry, Volatility, PCAP, Docker images, coredumps, side-channel power traces, DTMF audio spectrograms, packet timing analysis, CD audio disc images, or recovering deleted files and credentials.
DeepseekModel
Curated skill
Quality Good · 48
v1.0.0
Get
https://deepseekmodel.com/api/download.php?id=konggithubdev-ncsa-ctf-ai-2026-agents-skills-ctf-forensics-skill-md&format=skill
Download .skill
Standard format with system_prompt and model_config, ready for any agent framework
The actual content of the system_prompt field in the .skill file.
name ctf-forensics description Provides digital forensics and signal analysis techniques for CTF challenges. Use when analyzing disk images, memory dumps, event logs, network captures, cryptocurrency transactions, steganography, PDF analysis, Windows registry, Volatility, PCAP, Docker images, coredumps, side-channel power traces, DTMF audio spectrograms, packet timing analysis, CD audio disc images, or recovering deleted files and credentials. license MIT compatibility Requires filesystem-based agent (Claude Code or similar) with bash, Python 3, and internet access for tool installation. allowed-tools Bash Read Write Edit Glob Grep Task WebFetch WebSearch metadata {"user-invocable":"false"} CTF Forensics & Blockchain Quick reference for forensics CTF challenges. Each technique has a one-liner here; see supporting files for full details. Prerequisites Python packages (all platforms): pip install volatility3 Pillow numpy matplotlib Linux (apt): apt install binwalk foremost libimage-exiftool-perl tshark sleuthkit \ ffmpeg steghide testdisk john pcapfix macOS (Homebrew): brew install binwalk exiftool wireshark sleuthkit ffmpeg \ testdisk john-jumbo Ruby gems (all platforms): gem install zsteg Additional Resources 3d-printing.md - 3D printing forensics (PrusaSlicer binary G-code, QOIF, heatshrink) windows.md - Windows forensics (registry, SAM, event logs, recycle bin, NTFS alternate data streams, USN journal, PowerShell history, Defender MPLog, WMI persistence, Amcache) network.md - Network forensics basics (tcpdump, TLS/SSL keylog decryption, TLS master key extraction from coredump, Wireshark, PCAP, port scanning, SMB3 decryption, 5G/NR protocols, WordPress recon, credentials, USB HID steno, BCD encoding, HTTP file upload exfiltration, split archive reassembly via timestamp ordering) network-advanced.md - Advanced network forensics (packet interval timing encoding, USB HID mouse/pen drawing recovery, NTLMv2 hash cracking, TCP flag covert channel, DNS last-byte steganography, DNS trailing byte binary encoding, multi-layer PCAP with XOR + ZIP and mDNS key, Brotli decompression bomb seam analysis, SMB RID recycling via LSARPC, Timeroasting MS-SNTP hash extraction) disk-and-memory.md - Core disk/memory forensics (Volatility, disk mounting/carving, VM/OVA/VMDK, VMware snapshots, coredumps, Windows KAPE triage, PowerShell ransomware, Android forensics, Docker container forensics, cloud storage forensics, BSON reconstruction, TrueCrypt/VeraCrypt mounting) disk-advanced.md - Advanced disk and memory techniques (deleted partitions, ZFS forensics, GPT GUID encoding, VMDK sparse parsing, memory dump string carving, ransomware key recovery, WordPerfect macro XOR, minidump ISO 9660 recovery, APFS snapshot recovery, RAID 5 XOR recovery) disk-recovery.md - Disk recovery and extraction patterns (LUKS master key recovery, PRNG timestamp seed brute-force, VBA macro binary recovery, FemtoZip decompression, XFS filesystem reconstruction, tar duplicate entry extraction, nested matryoshka filesystem extraction, anti-carving via null byte interleaving, BTRFS subvolume/snapshot recovery, FAT16 free space data recovery, FAT16 deleted file recovery via Sleuth Kit fls/icat, ext2 orphaned inode recovery via fsck) steganography.md - General steganography (binary border stego, PDF multi-layer stego, SVG keyframes, PNG reorder, file overlays, GIF frame diff Morse code, GZSteg + spammimic, spreadsheet frequency recovery, Kitty terminal graphics protocol decoding, ANSI escape sequence steganography, autostereogram solving, two-layer byte+line interleaving, multi-stream video container stego, progressive PNG layered XOR decryption) stego-image.md - Image-specific steganography (JPEG unused DQT table LSB, BMP bitplane QR extraction, image puzzle reassembly, F5 JPEG DCT ratio detection, PNG unused palette entry stego, QR code tile reconstruction, seed-based pixel permutation + multi-bitplane QR, JPEG thumbnail pixel-to-text mapping, conditional LSB with pixel filtering, JPEG slack space, nearest-neighbor interpolation stego, RGB parity steganography) stego-advanced.md - Advanced steganography (FFT frequency domain, DTMF audio, SSTV+LSB, custom frequency dual-tone keypad, multi-track audio differential subtraction, cross-channel multi-bit LSB, audio FFT musical notes, audio metadata octal encoding, nested tar whitespace encoding, audio waveform binary encoding, audio spectrogram hidden QR, video frame accumulation, reversed audio, JPEG XL TOC permutation steganography) linux-forensics.md - Linux/app forensics (log analysis, Docker image forensics, attack chains, browser credentials, Firefox history, TFTP, TLS weak RSA, USB audio, Git directory recovery, KeePass v4 cracking, Git reflog/fsck squash recovery, browser artifact analysis (Chrome/Chromium/Firefox history, cookies, downloads, local storage, session restore), corrupted git blob repair via byte brute-force, VBA macro Excel cell data to ELF binary extraction) signals-and-hardware.md - Hardware signal decoding with decode code (VGA frame parsing, HDMI TMDS symbol decode, DisplayPort 8b/10b + LFSR descrambler), Voyager Golden Record audio, Saleae Logic 2 UART decode, Flipper Zero .sub files, side-channel power analysis (DPA), keyboard acoustic side-channel, CD audio disc image steganography (CIRC de-interleaving + spiral rendering), Linux input_event keylogger dump parsing Quick Start Commands # File analysis file suspicious_file exiftool suspicious_file # Metadata binwalk suspicious_file # Embedded files strings -n 8 suspicious_file hexdump -C suspicious_file | head # Check magic bytes # Disk forensics sudo mount -o loop,ro image.dd /mnt/evidence fls -r image.dd # List files photorec image.dd # Carve deleted files # Memory forensics (Volatility 3) vol3 -f memory.dmp windows.info vol3 -f memory.dmp windows.pslist vol3 -f memory.dmp windows.filescan See disk-and-memory.md for full Volatility plugin reference, VM forensics, and coredump analysis. Log Analysis grep -iE "(flag|part|piece|fragment)" server.log # Flag fragments grep "FLAGPART" server.log | sed 's/.*FLAGPART: //' | uniq | tr -d '\n' # Reconstruct sort logfile.log | uniq -c | sort -rn | head # Find anomalies See linux-forensics.md for Linux attack chain analysis and Docker image forensics. Windows Event Logs (.evtx) Key Event IDs: 1001 - Bugcheck/reboot 1102 - Audit log cleared 4720 - User account created 4781 - Account renamed RDP Session IDs (TerminalServices-LocalSessionManager): 21 - Session logon succeeded 24 - Session disconnected 1149 - RDP auth succeeded (RemoteConnectionManager, has source IP) import Evtx.Evtx as evtx with evtx.Evtx( "Security.evtx" ) as log: for record in log.records(): print (record.xml()) See windows.md for full event ID tables, registry analysis, SAM parsing, USN journal, and anti-forensics detection. NTFS Alternate Data Streams (ADS): Hidden data attached to files via named NTFS streams. Invisible to dir /Explorer. Detect with fls -r image.dd | grep ":" , extract with icat . See windows.md . When Logs Are Cleared If attacker cleared event logs, use these alternative sources: USN Journal ($J) - File operations timeline (MFT ref, timestamps, reasons) SAM registry - Account creation from key last_modified timestamps PowerShell history - ConsoleHost_history.txt (USN DATA_EXTEND = command timing) Defender MPLog - Separate log with threat detections and ASR events Prefetch - Program execution evidence User profile creation - First login time (profile dir in USN journal) See windows.md for detailed parsing code and anti-forensics detection checklist. Steganography steghide extract -sf image.jpg zsteg image.png # PNG/BMP analysis stegsolve # Visual analysis Binary border stego: Black/white pixels in 1px image border encode bits clockwise FFT frequency domain: Image data hidden in 2D FFT magnitude spectrum; try np.fft.fft2 visualization DTMF audio: Phone tones encoding data; decode with multimon-ng -a DTMF Multi-layer PDF: Check hidden comments, post-EOF data, XOR with keywords, ROT18 final layer SSTV + LSB: SSTV signal may be red herring; check 2-bit LSB of audio samples with stegolsb SVG keyframes: Animation keyTimes / values attributes encode binary/Morse via fill color alternation PNG chunk reorder: Fix chunk order: IHDR → ancillary → IDAT (in order) → IEND File overlays: Check after IEND for appended archives with overwritten magic bytes APNG frame extraction: Animated PNG has multiple frames; extract with apngdis or parse fdAT / fcTL chunks. See steganography.md . PNG height/CRC manipulation: Modify IHDR height field, brute-force until CRC matches to reveal hidden rows. See steganography.md . Pixel coordinate chain stego: Linked-list traversal where R=data byte, G/B=next pixel coordinates. See stego-image.md . AVI frame differential: XOR consecutive video frames to reveal hidden data in pixel differences. See stego-image.md . Custom freq DTMF: Non-standard dual-tone frequencies; generate spectrogram first ( ffmpeg -i audio -lavfi showspectrumpic ), map custom grid to keypad digits, decode variable-length ASCII JPEG DQT LSB: Unused quantization tables (ID 2, 3) carry LSB-encoded data; access via Image.open().quantization and extract bit 0 from each of 64 values Multi-track audio subtraction: Two nearly-identical audio tracks in MKV/video; sox -m a0.wav "|sox a1.wav -p vol -1" diff.wav cancels shared content, flag appears in spectrogram of difference signal (5-12 kHz band) Packet interval timing: Identical packets with two distinct interval values (e.g., 10ms/100ms) encode binary; filter by interface, compute inter-packet deltas, threshold to bits See steganography.md and stego-advanced.md for full code examples and decoding workflows. PDF Analysis exiftool document.pdf # Metadata (often hides flags!) pdftotext document.pdf - # Extract text strings document.pdf | grep -i flag binwalk document.pdf # Embedded files Advanced PDF stego (Nullcon 2026 rdctd): Six techniques -- invisible text separators, URI annotations with escaped braces, Wiener deconvolution on blurred images, vector rectangle QR codes, compressed object streams ( mutool clean -d ), document metadata fields. See steganography.md for full PDF steganography techniques and code. Disk / VM / Memory Forensics # Disk images sudo mount -o loop,ro image.dd /mnt/evidence fls -r image.dd && photorec image.dd # VM images (OVA/VMDK) tar -xvf machine.ova 7z x disk.vmdk -oextracted "Windows/System32/config/SAM" -r # Memory (Volatility 3) vol3 -f memory.dmp windows.pslist vol3 -f memory.dmp windows.cmdline vol3 -f memory.dmp windows.netscan vol3 -f memory.dmp windows.dumpfiles --physaddr <addr> # String carving strings -a -n 6 memdump.bin | grep -E "FLAG|SSH_CLIENT|SESSION_KEY" # Coredump gdb -c core.dump # info registers, x/100x $rsp, find "flag" See disk-and-memory.md for full Volatility plugin reference, VM forensics, and VMware snapshots. See disk-advanced.md for deleted partition recovery, ZFS forensics, and ransomware analysis. Windows Password Hashes # Extract with impacket, crack with hashcat -m 1000 python -c "from impacket.examples.secretsdump import *; SAMHashes('SAM', LocalOperations('SYSTEM').getBootKey()).dump()" See windows.md for SAM details and network-advanced.md for NTLMv2 cracking from PCAP. Bitcoin Tracing Use mempool.space API: https://mempool.space/api/tx/<TXID> Peel chain: ALWAYS follow LARGER output; round amounts indicate peels Uncommon File Magic Bytes Magic Format Extension Notes OggS Ogg container .ogg Audio/video RIFF RIFF container .wav , .avi Check subformat %PDF PDF .pdf Check metadata & embedded objects GCDE PrusaSlicer binary G-code .g , .bgcode See 3d-printing.md Common Flag Locations PDF metadata fields (Author, Title, Keywords) Image EXIF data Deleted files (Recycle Bin $R files) Registry values Browser history Log file fragments Memory strings WMI Persistence Analysis Pattern (Backchimney): Malware uses WMI event subscriptions for persistence (MITRE T1546.003). python PyWMIPersistenceFinder.py OBJECTS.DATA Look for FilterToConsumerBindings with CommandLineEventConsumer Base64-encoded PowerShell in consumer commands Event filters triggered on system events (logon, timer) See windows.md for WMI repository analysis details. Network Forensics Quick Reference TFTP netascii: Binary transfers corrupted; fix with data.replace(b'\r\n', b'\n').replace(b'\r\x00', b'\r') TLS keylog decryption: Import SSLKEYLOGFILE or RSA private key into Wireshark (Edit → Preferences → Protocols → TLS) TLS weak RSA: Extract cert, factor modulus, generate private key with rsatool , add to Wireshark USB audio: Extract isochronous data with tshark -e usb.iso.data , import as raw PCM in Audacity NTLMv2 from PCAP: Extract server challenge + NTProofStr + blob from NTLMSSP_AUTH, brute-force WPA/WEP WiFi decryption: aircrack-ng -w wordlist capture.pcap cracks WPA handshake; WEP cracked with enough IVs. See network.md . PCAP repair: pcapfix -d corrupted.pcap repairs broken PCAP headers/checksums for Wireshark loading. See network.md . USB HID keyboard decoding: Extract 8-byte HID reports from USB captures; byte 2 = keycode, byte 0 = modifiers (Shift). See network-advanced.md . dnscat2 reassembly: Decode hex/base32 subdomain labels, strip 9-byte dnscat2 header, deduplicate retransmissions, reassemble payload. See network-advanced.md . USB keyboard LED exfiltration: Host-to-device HID SET_REPORT packets toggle Caps Lock LED. Timing encodes Morse code. See network-advanced.md . See network.md for SMB3 decryption, credential extraction, and linux-forensics.md for full TLS/TFTP/USB workflows. Browser Forensics Chrome/Edge: Decrypt Login Data SQLite with AES-GCM using DPAPI master key Firefox: Query places.sqlite -- SELECT url FROM moz_places WHERE url LIKE '%flag%' See linux-forensics.md for full browser credential decryption code. Additional Technique Quick References Docker image forensics: Config JSON preserves ALL RUN commands even after cleanup. tar xf app.tar then inspect config blob. See linux-forensics.md . Linux attack chains: Check auth.log , .bash_history , recent binaries, PCAP. See linux-forensics.md . RAID 5 XOR recovery: Two disks of a 3-disk RAID 5 → XOR byte-by-byte to recover the third: bytes(a ^ b for a, b in zip(disk1, disk3)) . See disk-advanced.md . PowerShell ransomware: Extract scripts from minidump, find AES key, decrypt SMTP attachment. See disk-and-memory.md . Linux ransomware + memory dump: If Volatility is unreliable, recover AES key via raw-memory candidate scanning and magic-byte validation; re-extract zip cleanly to avoid missing files/false negatives. See disk-advanced.md .
Keywords that activate this skill. Click one to copy it.
This skill does not provide trigger words.
The downloaded .skill package contains the following fields.
| Field | Description |
|---|---|
| format | Format tag (skill/v1) |
| skill_id | Unique skill ID |
| name | Skill name |
| version | Version |
| description | Description |
| category | Categories (array) |
| trigger_words | Trigger words |
| tags | Tags |
| source | Source |
| source_url | Source URL (this page) |
| exported_at | Exported at (set per download) |
| system_prompt | System prompt body |
| model_config | Model config: provider / model / temperature / max_tokens / top_p |
| examples | Examples |
| install_guide | Import guide for Coze / Dify / Claude / custom frameworks |
The same skill can be exported in different platform formats.