What you will learn
- Handle digital evidence methodically
- Inspect metadata and logs
- Explain findings with reproducible evidence
Investigate files, metadata, logs, memory artifacts, and network captures to reconstruct events from digital evidence.
43 challenges available.
ForensicsLevel 1Files contain identification information called "magic bytes" at the beginning. Even if the extension is disguised,…
ForensicsLevel 1Photos and images contain metadata called EXIF. This metadata records shooting date, camera info, GPS coordinates,…
ForensicsLevel 1Binary files (executables, etc.) contain human-readable strings. Passwords, URLs, error messages, and other hints can…
ForensicsLevel 2Analyze Apache access.log to find traces of SQL injection attacks. Learn log analysis and pattern matching. Provided…
ForensicsLevel 2Analyze the macro code embedded in the Excel file to find the flag. Learn how to analyze Office document macros.…
ForensicsLevel 2PDF files contain multiple object streams. Find the flag hidden in one of them. Learn to understand PDF internal…
ForensicsLevel 2Analyze the SYSTEM file to retrieve connected USB device information and the hidden flag. Learn the basics of Windows…
ForensicsLevel 2Inspect the ext4 filesystem disk image `disk.img` and read the hidden secret file from the filesystem to recover the…
ForensicsLevel 2Clear-text HTTP traffic from a shop's internal network was captured. Among many requests, exactly one is the…
ForensicsLevel 2Analyze timestamps of multiple files to identify when the intrusion occurred and which hidden log is related to it.…
ForensicsLevel 2Analyze the process list recorded in memory.dump and find the flag contained in the suspicious process name. Learn the…
ForensicsLevel 2Recover deleted text files from the disk image and find the flag. Learn how to use file carving tools to recover…
ForensicsLevel 2Extract the message hidden in the LSB (Least Significant Bit) of a PNG file. Learn the basics of steganography…
ForensicsLevel 3Analyze Chrome history database and Cookie file to retrieve session information for a specific site. Learn browser…
ForensicsLevel 3Analyze the DNS query log `dns_queries.log` to detect data exfiltration via DNS tunneling. Find the host flooding a…
ForensicsLevel 3Analyze `mft_records.txt`, a dump of the NTFS Master File Table, to recover information about deleted files. A…
ForensicsLevel 3Analyze the authentication log `auth.log` to find traces of a brute-force attack. Aggregate failed logins per source…
ForensicsLevel 3Analyze the network-connection record `netstat_dump.txt` to identify the suspicious C&C connection. The single…
ForensicsLevel 3Analyze the memory-string record `memdump.txt` to recover the executed command history. Decode the Base64 strings and…
ForensicsLevel 3Recover the deleted record from the SQLite database `app.db` to obtain the flag. Deleted rows persist in the freelist,…
ForensicsLevel 3Decompress a file that has been compressed multiple times with different formats (zip, tar, gzip, bzip2). Learn to…
ForensicsLevel 3`secret_disk.img` is a genuine LUKS2 container. Brute-force `wordlist.txt` to find the weak passphrase, then decrypt…
ForensicsLevel 3`hidden.wav` hides a message encoded with on-off keying (OOK). Turn the tone on/off slots into bits and decode them to…
ForensicsLevel 4Extract a safe ZIP-formatted APK fixture and analyze the API secret recorded in its Android resources. No real device…