Network forensics
Triage a packet capture: find the one conversation that matters, extract transferred files, and spot exfiltration over DNS.
By the end you can
- Use a protocol breakdown to decide where to look first
- Reassemble a TCP stream and read a plaintext protocol
- Extract files transferred over HTTP, FTP, or SMB
- Recognise DNS tunnelling and decode the exfiltrated payload
- Decrypt TLS from a capture when the key material is available, and say exactly what it takes
- Infer the structure of an undocumented binary protocol from repeated messages
1. Read
PCAP triage: finding the flag in a hundred thousand packets
Network forensics challenges hand you a capture and no question. The triage order that finds the answer fast - protocol hierarchy, conversations, streams - plus the exfiltration channels people actually hide flags in: DNS, ICMP, USB, and TLS you can decrypt.
Reversing a binary protocol from a capture
A CTF hands you a pcap of some custom protocol and no specification. The structures every hand-rolled protocol is built from - magic, length prefixes, TLV, varints - and a repeatable way to turn a hex dump into a parser that reads the flag out.
2. Use the tools
In the order they come up while solving. Read what each one does, or go straight to the workspace tab that runs it.
- PCAP analyzer for CTF network forensics
Drop a packet capture and extract HTTP objects, DNS queries, credentials, transferred files, and flags - with TLS decryption when you have the keys.
Open it in the workspace - PCAP overview: protocols, conversations and hosts
Open a capture and see what is in it before reading a single packet: the protocol histogram, the busiest conversations, and whether credentials or flags are already sitting in plaintext.
Open it in the workspace - Packet list and raw frame bytes
Walk a capture packet by packet with its dissection and its raw bytes, for the traffic that has no higher-level tab.
Open it in the workspace - Follow a TCP stream in the browser
Reassemble a TCP conversation from its segments and read it as one transcript, in order, with each direction separable.
Open it in the workspace - DNS queries from a PCAP, and DNS exfiltration
List every DNS query and answer in a capture, and recognise the shape of data being smuggled out through subdomain labels.
Open it in the workspace - Find plaintext credentials in a packet capture
Scan a capture for passwords sent in the clear - HTTP Basic auth, login forms, FTP, Telnet, POP3, IMAP and SMTP.
Open it in the workspace - Extract HTTP requests and responses from a PCAP
Pull every HTTP request and response out of a capture - URLs, headers, cookies, form bodies and transferred files - without opening Wireshark.
Open it in the workspace - Search a packet capture for flags
Scan every packet payload in a capture for flag-shaped strings, including flags that straddle a TCP segment boundary.
Open it in the workspace - Decrypt TLS in a PCAP with an SSLKEYLOGFILE
Decrypt TLS 1.2 and TLS 1.3 traffic in a capture using the key log the challenge gave you, entirely in the browser.
Open it in the workspace - Base32 decoder and encoder
Decode Base32 (RFC 4648) to text or bytes, with padding repair. Distinguishes Base32 from Base64 and hex automatically.
Open it in the workspace - Timestamp converter (Unix, ISO, FILETIME, HFS+)
Convert between Unix seconds and milliseconds, ISO 8601, local time, and the non-standard epochs used by Windows, macOS, and Flask.
Open it in the workspace - Strings extractor for binaries and blobs
Pull printable ASCII and UTF-16 strings out of any file, filtered by length, with flag-pattern highlighting.
Open it in the workspace
3. Try one now
Generated in your browser and checked in your browser. No account, nothing to download, and a fresh one whenever you want another.
4. Practise on the real thing
Real picoCTF challenges that use these techniques, easiest first. 20 match in total - see the full index.
Common mistakes
The wrong turns this topic reliably produces. Written as the mistake rather than the rule, because the rule is easy to agree with and easy to walk straight past.
- Reading packets in order. A hundred thousand packets is a statistics problem first - protocol breakdown, conversation sizes, endpoint counts - and a reading problem second.
- Dismissing DNS as noise. Long labels, high query rates to one domain, and base32-looking subdomains are the standard exfiltration signature.
- Assuming TLS ends the investigation. Server names, certificates, timing and sizes survive encryption, and challenges often supply the key log anyway.
- Searching packet bytes for the flag format and concluding it is absent. Anything transferred is split across packets and often compressed or encoded in transit, so the search belongs on the reassembled stream.
- Believing the protocol column. It is a dissector's guess, usually from the port number, and the binary-protocol half of this module exists because the traffic that matters is the traffic no dissector claimed.
Checkpoint
From a capture, produce the exfiltrated payload and the exact query sequence that carried it.
Teaching note
The habit to build is looking for the anomaly rather than reading the traffic. Ask students what is unusual before asking what it says - the answer is almost always in the outlier.
Go deeper
The lessons above are written to get you through a challenge. These go after the subject instead. Each one opens our notes on that chapter - what it argues, what to take from it and where it stops - so this is somewhere to read now rather than a book to buy first. Nothing here is affiliate-linked or sold by us.
Chapter 2, Capturing Application Traffic
Attacking Network Protocols - James Forshaw
Capture positions and their blind spots, which decides what a pcap can and cannot contain.
Chapter 3, Network Protocol Structures
Attacking Network Protocols - James Forshaw
The structural vocabulary - TLV, length prefixes, varints - that turns an unknown protocol into a parse.
Chapter 5, Analysis from the Wire
Attacking Network Protocols - James Forshaw
A disciplined method for going from bytes on the wire to a description of the protocol.
Chapter 5, Analyzing Network Protocols
Practical IoT Hacking - Fotios Chantzis, Ioannis Stais, Paulino Calderon, Evangelos Deirmentzoglou, and Beau Woods
Writing a dissector for a protocol nobody has documented, which is the CTF task in its professional form.
Every book the curriculum cites has a page in the library.