Skip to content
All modules
AdvancedModule 18 of 2790 minutes

Network forensics

Triage a packet capture: find the one conversation that matters, extract transferred files, and spot exfiltration over DNS.

Assumes16. File forensics and carving

By the end you can

  • Use a protocol breakdown to decide where to look first
  • Reassemble a TCP stream and read a plaintext protocol
  • Extract files transferred over HTTP, FTP, or SMB
  • Recognise DNS tunnelling and decode the exfiltrated payload
  • Decrypt TLS from a capture when the key material is available, and say exactly what it takes
  • Infer the structure of an undocumented binary protocol from repeated messages

1. Read

2. Use the tools

In the order they come up while solving. Read what each one does, or go straight to the workspace tab that runs it.

3. Try one now

Generated in your browser and checked in your browser. No account, nothing to download, and a fresh one whenever you want another.

4. Practise on the real thing

Real picoCTF challenges that use these techniques, easiest first. 20 match in total - see the full index.

Common mistakes

The wrong turns this topic reliably produces. Written as the mistake rather than the rule, because the rule is easy to agree with and easy to walk straight past.

  • Reading packets in order. A hundred thousand packets is a statistics problem first - protocol breakdown, conversation sizes, endpoint counts - and a reading problem second.
  • Dismissing DNS as noise. Long labels, high query rates to one domain, and base32-looking subdomains are the standard exfiltration signature.
  • Assuming TLS ends the investigation. Server names, certificates, timing and sizes survive encryption, and challenges often supply the key log anyway.
  • Searching packet bytes for the flag format and concluding it is absent. Anything transferred is split across packets and often compressed or encoded in transit, so the search belongs on the reassembled stream.
  • Believing the protocol column. It is a dissector's guess, usually from the port number, and the binary-protocol half of this module exists because the traffic that matters is the traffic no dissector claimed.

Checkpoint

From a capture, produce the exfiltrated payload and the exact query sequence that carried it.

Teaching note

The habit to build is looking for the anomaly rather than reading the traffic. Ask students what is unusual before asking what it says - the answer is almost always in the outlier.

Go deeper

The lessons above are written to get you through a challenge. These go after the subject instead. Each one opens our notes on that chapter - what it argues, what to take from it and where it stops - so this is somewhere to read now rather than a book to buy first. Nothing here is affiliate-linked or sold by us.

Every book the curriculum cites has a page in the library.