Lesson pack 16 · Core · 90 minutes
File forensics and carving
Identify files by their bytes, find data appended past a format's end marker, and pull evidence out of images, archives and documents.
Print this page for a paper plan - the navigation and links drop out.Student-facing version
Before the session
- Nothing to install. Students need a browser and https://ctfpal.com. Confirm the room can reach it once; after that it works offline.
- Read the lesson yourself first - about 22 minutes.
- Have one worked example ready to paste. The classroom link builder on the instructor page turns it into a URL that opens preloaded.
Objectives
Written as things a student can do afterwards, so they can be assessed rather than asserted.
- Identify a file's real type regardless of extension
- Find and extract data hidden after a format's terminator
- Read EXIF, PNG chunks, and JPEG segments for metadata and appended payloads
- Take a PDF or Office document apart by object and stream, and find the active content in it
- Read an archive's central directory against its local headers, and spot the mismatch that hides a file
- Repair a deliberately corrupted header
Running order (90 min)
| Time | What happens |
|---|---|
| 0:00-0:09 | Frame the problemWhat the category looks like when you meet it cold, and why the naive approach fails. |
| 0:09-0:27 | Teach the methodThe technique itself, on the board or from the lesson. No tools open yet. |
| 0:27-0:50 | Demonstrate liveSame technique, in the workspace, on your worked example. Narrate every choice. |
| 0:50-1:21 | Practice setStudents work the challenges. Circulate rather than present. |
| 1:21-1:30 | Checkpoint and wrapCollect the artefact, name what comes next. |
Tools used
- File type identifier by magic bytes - Drop a file and identify what it really is from its signature, regardless of extension. Also finds file headers embedded inside other files.https://ctfpal.com/?tool=file-signature-identifier
- Magic byte and file signature table - Look up any file format by its magic bytes, or any byte sequence by format - including the trailers that mark where a file ends.https://ctfpal.com/?tool=magic-byte-lookup
- Strings extractor for binaries and blobs - Pull printable ASCII and UTF-16 strings out of any file, filtered by length, with flag-pattern highlighting.https://ctfpal.com/?tool=strings-extractor
- Hex viewer and hexdump - Inspect any file byte by byte with a side-by-side hex and ASCII view, offsets, and structure highlighting.https://ctfpal.com/?tool=hex-viewer
- PNG chunk analyzer - Walk a PNG chunk by chunk, validate CRCs, read tEXt and zTXt metadata, and find data hidden after IEND or in non-standard chunks.https://ctfpal.com/?tool=png-chunk-analyzer
- JPEG marker and segment analyzer - Parse JPEG markers, read APP segments and comments, and extract data appended after the end-of-image marker.https://ctfpal.com/?tool=jpeg-marker-analyzer
- EXIF metadata viewer - Read EXIF, GPS coordinates, camera details, timestamps, and embedded comments from images - the metadata that answers OSINT challenges.https://ctfpal.com/?tool=exif-viewer
- ZIP archive inspector - Read a ZIP’s central directory and local headers, spot mismatches used to hide files, and check encryption and compression per entry.https://ctfpal.com/?tool=zip-archive-inspector
- PDF object and stream analyzer - Walk PDF objects, decompress streams, extract embedded files and JavaScript, and find text hidden under redaction boxes.https://ctfpal.com/?tool=pdf-object-analyzer
- Office macro and OLE extractor - Extract VBA macros from DOCM, XLSM, and legacy OLE documents, and deobfuscate the string-concatenation tricks they hide behind.https://ctfpal.com/?tool=office-macro-extractor
Reading
- The first ten minutes: a triage playbook for any CTF challenge - 8 min. Most challenges are lost to flailing, not to difficulty. Here is a repeatable order of operations for an unknown blob, an unknown file, and an unknown service - and the point at which you should stop guessing and start reading.
- Archive attacks: ZIP crypto, known plaintext, and Zip Slip - 7 min. Cracking a password-protected archive without cracking the password, why legacy ZipCrypto falls to twelve known bytes, path traversal through an entry name, and the structural tricks that make one archive hold two different sets of files.
- Document forensics: taking apart a PDF and an Office file - 7 min. A PDF is a graph of objects and an Office document is a zip of XML. Both hide things in places a viewer never renders. How to enumerate the structure, pull out streams and macros, and follow what the document tries to fetch.
Practice set
Real picoCTF challenges tagged with this module’s techniques, easiest first. Assign the first three in class and the rest as homework.
- Big Zip - picoGym Exclusive, easy
- binhexa - picoCTF 2024, easy
- CanYouSee - picoCTF 2024, easy
- Corrupted file - picoMini by CMU-Africa, easy
- endianness - picoCTF 2024, easy
- First Grep - picoCTF 2019, easy
- Glory of the Garden - picoCTF 2019, easy
- advanced-potion-making - picoMini by redpwn, medium
- Bitlocker-2 - picoCTF 2025, medium
- Blast from the past - picoCTF 2024, medium
- B1g_Mac - picoCTF 2019, hard
- Virtual Machine 1 - picoCTF 2023, hard
Checkpoint (gradeable)
Given a polyglot file, extract every embedded file it contains and state the offset and signature of each.
Deliberately a produced artefact rather than a quiz question: it is either there or it is not, which makes it fast to mark and hard to bluff. Every tool in ctfpal is deterministic, so two students who did the work correctly hand in the same value.
Where the room gets stuck
Students reach for the steganography solver too early here. Make them run strings and check the magic bytes first, every time - most 'stego' challenges at this level are a ZIP glued onto a PNG.
- Reaching for a steganography solver before running strings and checking the magic bytes. Most 'stego' challenges at this level are an archive glued onto an image.
- Trusting the file size. Every container format has a defined end, and the bytes after it are invisible to anything that respects the format.
- Extracting an archive to look inside it. Extraction runs the format's own logic, including path traversal in stored names - read the directory first.
- Repairing a broken header by pasting one in from another file. Dimensions, colour type and chunk offsets live in that header too, so the image opens, renders as noise, and looks repaired.
- Reading a document's text instead of its objects. The interesting part of a PDF or an Office file is the stream nobody renders - an embedded object, a macro, an external reference - and a text extractor is built to skip exactly that.
If a student wants the subject, not the answer
Chapter-level references, so a student can be pointed at twenty pages rather than at a book. Nothing here is required to complete the module.
- Practical Forensic Imaging, Bruce Nikkel. Chapter 3, Forensic Image Formats. Container formats treated as evidence, with the metadata and integrity structures spelled out.
- Practical Forensic Imaging, Bruce Nikkel. Chapter 9, Extracting Subsets of Forensic Images. Carving at offsets, done rigorously enough to defend afterwards rather than just quickly.
- Malware Data Science, Joshua Saxe with Hillary Sanders. Chapter 1, Basic Static Malware Analysis. What static file structure alone can tell you before anything is executed or decoded.
- Evasive Malware, Kyle Cucci. Chapter 2, Malware Triage and Behavioral Analysis. A triage order for unknown files that scales past the one-file-at-a-time habit CTFs teach.
If you finish early
- Hand out a challenge from the cross-CTF index in this category - each one has published solutions to compare afterwards.
- Run the same input through Identify and let the class argue with the ranking. Disagreeing with a confidence score is where the technique actually lands.
- Ask a student to break their own example - construct an input that defeats the tool, and explain why.
Take this into a room
Markdown files, built here in your browser. They print, they open in anything, and they carry the challenge text - so the session works with no network in the room.