Digital Forensics
Digital forensics is the art of recovering and analyzing evidence from digital sources. In CTFs, forensics challenges teach you to extract hidden information from image metadata, network packet captures, steganography, and disk images. You'll build a toolkit of command-line tools and learn to think like an investigator.
Guides for this path
Read these alongside the challenges below. The first one orients you; the rest go deeper on the techniques each step needs.
- The picoCTF Forensics Roadmap: file, strings, and Everything AfterCTF forensics roadmap: start with file, strings, and a hex view, then branch by type across images, audio, captures, disk, and memory. Ordered and linked.
- Image Metadata and EXIF Forensics for CTFEXIF metadata forensics for CTF: the flag hides in metadata, not pixels. Use exiftool, PNG text chunks, thumbnails, and strings to pull flags from EXIF and XMP.
- Wireshark and pcap Analysis for CTF ForensicsWireshark and tshark for CTF: analyze pcap files, follow TCP streams, find credentials, extract files, reconstruct DNS exfiltration, and apply display filters.
- Steganography Techniques for CTF CompetitionsCTF steganography techniques: LSB pixel manipulation, file-within-file extraction, audio spectrograms, and metadata analysis, plus when to use each one.
- CTF Disk Forensics: What to Do When Strings Returns NothingCTF disk forensics challenges hide data in one of six ways. A two-minute triage tells you which, and what an empty result means. Never guess at a disk image again.
- File Carving and Magic Bytes: Repairing Corrupted Files for CTFFix a corrupted header, repair a broken PNG, and carve embedded files by signature. A forensics field guide to magic bytes, binwalk, foremost, and polyglots for CTF.
- Step 01
File Inspection and Metadata
Every file carries metadata that most people never think about. EXIF data embedded in images can reveal GPS coordinates, camera models, and comments with hidden flags. Tools like exiftool, strings, and file let you peek inside any file. Start here to build the habit of looking beyond the obvious.
- Step 02
Network Packet Analysis
Network traffic captures (pcap files) record every packet crossing a network interface. With Wireshark or tshark you can reconstruct TCP streams, inspect HTTP requests, and find credentials or flags buried in plaintext traffic. This is a core forensics skill used in real incident response work.
- Step 03
Steganography
Steganography hides secret data inside innocent-looking media files. A flag might be encoded in the least-significant bits of an image's pixels, appended after a file's official end-of-file marker, or hidden in the color channels of a PNG. Tools like zsteg, steghide, and stegsolve are your allies here.
- Step 04
Disk and File System Forensics
When you have a raw disk image, tools like Autopsy, The Sleuth Kit, and binwalk let you mount the filesystem, recover deleted files, and examine partition tables. These challenges mirror real-world digital forensics where investigators analyze seized storage devices to reconstruct what happened.
- Step 05
Multi-Layer and Advanced Challenges
Real forensics investigations rarely involve just one technique. These challenges layer multiple forensics skills: file format quirks, embedded archives, Android APK analysis, and endianness-aware binary parsing. Work through them to solidify the full forensics toolkit.