ctf-forensics
CommunityCTF forensics: disk, memory, network artifacts.
Authorramzxy
Version1.0.0
Installs0
System Documentation
What problem does it solve?
This Skill provides a consolidated reference for digital forensics and blockchain analysis in Capture The Flag (CTF) challenges, enabling rapid identification and contextualization of artifacts across multiple data sources.
Core Features & Use Cases
- Cross-source artifact analysis: Analyze disk images, memory dumps, Windows event logs, PCAPs, and blockchain traces to discover evidence and flags.
- Guided workflows: Offers step-by-step procedures and quick-reference commands to reproduce investigations and validate findings.
- Forensic techniques reference: Provides common techniques, tools, and data formats used in forensics to accelerate training and challenges.
Quick Start
- Scan a disk image for embedded artifacts: binwalk image.dd
- Inspect memory dumps and event logs for indicators: vol3 -f memory.dmp windows.info
- Review network captures for flag-like indicators: tshark -r capture.pcap -Y "http" -T json
Dependency Matrix
Required Modules
None requiredComponents
Standard package💻 Claude Code Installation
Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.
Please help me install this Skill: Name: ctf-forensics Download link: https://github.com/ramzxy/CTF/archive/main.zip#ctf-forensics Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
Agent Skills Search Helper
Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.