skills/jd-opensource/joysafeter/pentest-ctf-forensics

pentest-ctf-forensics

SKILL.md

Pentest CTF Forensics

Purpose

Extract hidden information from various artifacts: memory dumps, network captures (PCAP), images, and disk images.

Core Workflow

  1. File Analysis: Identify file type, metadata, and embedded strings using file, exiftool, and strings.
  2. Steganography: Detect and extract hidden data in images/audio using steghide and stegsolve.
  3. Network Forensics: Analyze PCAP files for suspicious traffic and flag transmission using wireshark or tshark.
  4. Memory Forensics: Analyze memory dumps for processes, connections, and injected code using volatility.
  5. Data Extraction: Carve files and recover deleted data using foremost and binwalk.

References

  • references/tools.md
  • references/workflows.md
Weekly Installs
24
GitHub Stars
182
First Seen
Feb 18, 2026
Installed on
github-copilot24
codex24
kimi-cli24
gemini-cli24
amp24
cursor24