What problem does it solve?
This Skill eliminates the guesswork in CTF forensics challenges by providing structured, battle-tested techniques for analyzing disk images, memory dumps, network captures, steganography, and hardware signals. It transforms overwhelming forensic artifacts into actionable steps, helping you recover flags faster.
Core Features & Use Cases
- Disk and Memory Forensics: Recover deleted files, analyze memory dumps with Volatility, mount VM images, and extract encryption keys from LUKS or TrueCrypt volumes.
- Network Traffic Analysis: Decrypt TLS sessions, extract credentials from PCAP files, decode covert channels in DNS and ICMP, and reassemble split archives from HTTP transfers.
- Steganography and Signal Analysis: Detect hidden data in images, audio, video, PDFs, and terminal art; decode VGA/HDMI signals, side-channel power traces, and keyboard acoustic recordings.
Quick Start
Use the ctf-forensics skill to analyze the provided forensic artifact and recover the hidden flag.