What problem does it solve? CTF forensics challenges require analyzing diverse evidence artifacts like packet captures, disk images, memory dumps, logs, and steganographic files, and this Skill provides a structured entry point to the full forensics methodology for solving them. ## Core Features & Use Cases - Multi-artifact analysis: Covers packet captures, disk images, memory dumps, log files, file carving, steganography, and data recovery scenarios. - Reference-driven workflow: Routes to the complete technical manual in the skill library and selects in-depth references on demand. - Evidence preservation: Keeps original attachments intact and records derived files in separate directories without directly submitting flags. - Use Case: Given a challenge attachment containing a suspicious pcap file, load this Skill to follow the forensics manual, extract hidden data, and produce a candidate flag with documented evidence. ## Quick Start Load the ctf-forensics skill and analyze the attached challenge file to identify hidden or recoverable flag evidence.