pentest-ctf-forensics
Digital forensics, steganography, and packet analysis for CTF challenges and investigation.
来源信息
- 仓库
- jd-opensource/JoySafeter
- 最近来源活动
- 2026年2月11日 09:17
- 检测到的 SKILL.md 语言
- 英语
- 星标
- 312
- 分支
- 58
安装方式
默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。
检查来源文件
决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。
文件资源管理器
3 个文件正在显示 SKILL.md
SKILL.md
来源说明 · 只读预览- name
- pentest-ctf-forensics
- description
- Digital forensics, steganography, and packet analysis for CTF challenges and investigation.
# Pentest CTF Forensics
## Purpose
Extract hidden information from various artifacts: memory dumps, network captures (PCAP), images, and disk images.
## Core Workflow
1. **File Analysis**: Identify file type, metadata, and embedded strings using `file`, `exiftool`, and `strings`.
2. **Steganography**: Detect and extract hidden data in images/audio using `steghide` and `stegsolve`.
3. **Network Forensics**: Analyze PCAP files for suspicious traffic and flag transmission using `wireshark` or `tshark`.
4. **Memory Forensics**: Analyze memory dumps for processes, connections, and injected code using `volatility`.
5. **Data Extraction**: Carve files and recover deleted data using `foremost` and `binwalk`.
## References
- `references/tools.md`
- `references/workflows.md`
在 GitHub 查看