ctf-forensics

Community

CTF forensics: disk, memory, network artifacts.

Authorramzxy
Version1.0.0
Installs0

System Documentation

What problem does it solve?

This Skill provides a consolidated reference for digital forensics and blockchain analysis in Capture The Flag (CTF) challenges, enabling rapid identification and contextualization of artifacts across multiple data sources.

Core Features & Use Cases

  • Cross-source artifact analysis: Analyze disk images, memory dumps, Windows event logs, PCAPs, and blockchain traces to discover evidence and flags.
  • Guided workflows: Offers step-by-step procedures and quick-reference commands to reproduce investigations and validate findings.
  • Forensic techniques reference: Provides common techniques, tools, and data formats used in forensics to accelerate training and challenges.

Quick Start

  • Scan a disk image for embedded artifacts: binwalk image.dd
  • Inspect memory dumps and event logs for indicators: vol3 -f memory.dmp windows.info
  • Review network captures for flag-like indicators: tshark -r capture.pcap -Y "http" -T json

Dependency Matrix

Required Modules

None required

Components

Standard package

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: ctf-forensics
Download link: https://github.com/ramzxy/CTF/archive/main.zip#ctf-forensics

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.