Lesson pack 19 · Advanced · 120 minutes
Memory and disk forensics
Answer the three questions a memory image is asked - what was running, what was typed, what was on disk - and know why a scan beats a list.
Print this page for a paper plan - the navigation and links drop out.Student-facing version
Before the session
- Nothing to install. Students need a browser and https://ctfpal.com. Confirm the room can reach it once; after that it works offline.
- Read the lesson yourself first - about 14 minutes.
- Have one worked example ready to paste. The classroom link builder on the instructor page turns it into a URL that opens preloaded.
Objectives
Written as things a student can do afterwards, so they can be assessed rather than asserted.
- Distinguish a raw memory image from a crash dump or hibernation file before analysing it
- Explain why psscan finds processes pslist cannot, and what that costs in validation
- Recover command lines from a Windows image, including the UTF-16 problem
- Locate and carve a registry hive out of a dump and read persistence from it
- Read ext, FAT and NTFS structures well enough to recover a deleted or resident file
- Read the boot record chain and say where a bootkit would have to live
Running order (120 min)
| Time | What happens |
|---|---|
| 0:00-0:12 | Frame the problemWhat the category looks like when you meet it cold, and why the naive approach fails. |
| 0:12-0:36 | Teach the methodThe technique itself, on the board or from the lesson. No tools open yet. |
| 0:36-1:06 | Demonstrate liveSame technique, in the workspace, on your worked example. Narrate every choice. |
| 1:06-1:48 | Practice setStudents work the challenges. Circulate rather than present. |
| 1:48-2:00 | Checkpoint and wrapCollect the artefact, name what comes next. |
Tools used
- Memory dump, disk image and registry hive analysis - Scan a Windows memory image for processes, command lines, file objects and registry hives - and read ext4, FAT, NTFS $MFT and registry hives - entirely in the browser.https://ctfpal.com/?tool=memory-disk-registry-forensics
- Strings extractor for binaries and blobs - Pull printable ASCII and UTF-16 strings out of any file, filtered by length, with flag-pattern highlighting.https://ctfpal.com/?tool=strings-extractor
- File type identifier by magic bytes - Drop a file and identify what it really is from its signature, regardless of extension. Also finds file headers embedded inside other files.https://ctfpal.com/?tool=file-signature-identifier
- Hex viewer and hexdump - Inspect any file byte by byte with a side-by-side hex and ASCII view, offsets, and structure highlighting.https://ctfpal.com/?tool=hex-viewer
- Timestamp converter (Unix, ISO, FILETIME, HFS+) - Convert between Unix seconds and milliseconds, ISO 8601, local time, and the non-standard epochs used by Windows, macOS, and Flask.https://ctfpal.com/?tool=timestamp-converter
Reading
- Memory dump triage: what was running, what was typed, what was on disk - 5 min. A raw memory image answers three questions and you should ask them in that order. Why psscan beats pslist for a challenge, where command lines actually live, and how to get from a dump to a registry hive.
- Disk image forensics: partitions, deleted files, and slack - 5 min. A forensics challenge hands you a raw disk image and no map. The layered way to take it apart - partition table, filesystem, deleted files, unallocated space, and slack - so the flag stops hiding in the gaps between files.
- The boot process as a target: MBR, VBR, and bootkits - 4 min. Before the OS loads, a chain of tiny programs runs from the first sectors of the disk - and a forensics challenge can hide a flag, or a bootkit, right there. How the boot chain works and how to analyse the sectors it lives in.
Practice set
Real picoCTF challenges tagged with this module’s techniques, easiest first. Assign the first three in class and the rest as homework.
- Corrupted file - picoMini by CMU-Africa, easy
- DISKO 1 - picoGym Exclusive, easy
- advanced-potion-making - picoMini by redpwn, medium
- Bitlocker-1 - picoCTF 2025, medium
- Dear Diary - picoCTF 2024, medium
- Disk, disk, sleuth! - picoCTF 2021, medium
- Disk, disk, sleuth! II - picoCTF 2021, medium
- DISKO 2 - picoGym Exclusive, medium
- DISKO 3 - picoGym Exclusive, medium
- DISKO 4 - picoCTF 2026, medium
- Event-Viewing - picoCTF 2025, medium
- UnforgottenBits - picoCTF 2023, hard
Checkpoint (gradeable)
Given a raw Windows memory image, produce the process tree, identify the process that should not be there, and recover the command line it was started with.
Deliberately a produced artefact rather than a quiz question: it is either there or it is not, which makes it fast to mark and hard to bluff. Every tool in ctfpal is deterministic, so two students who did the work correctly hand in the same value.
Where the room gets stuck
The UTF-16 point lands better as a demonstration than as a statement: run strings without -el on a dump, get nothing, run it with -el, and get the whole command history. Students who see that once never forget it.
- Trusting a process list from a compromised machine. The list is a linked list the malware can edit; a scan for the structure signature is not.
- Running strings on a Windows dump without -el and concluding there is nothing there. Most of what you want is UTF-16.
- Deleting is not erasing, but neither is it permanent. A recovered file needs its metadata source stated, because a carved file and an MFT-recovered file are different claims.
- Reading empty plugin output as a clean machine. Every plugin depends on matching the image to the right kernel build or symbol set, and the mismatch shows up as silence rather than as an error.
- Treating the page file and unallocated space as out of scope. A process that exited leaves its strings in both, and 'what was typed' often survives nowhere else on the image.
If a student wants the subject, not the answer
Chapter-level references, so a student can be pointed at twenty pages rather than at a book. Nothing here is required to complete the module.
- Practical Forensic Imaging, Bruce Nikkel. Chapter 6, Forensic Image Acquisition. How the image you are handed was made, and what that decides about what can still be recovered from it.
- Practical Forensic Imaging, Bruce Nikkel. Chapter 8, Special Image Access Topics. Encrypted volumes, RAID sets and virtual machine disks - the cases where the image will not simply mount.
- Rootkits and Bootkits, Alex Matrosov, Eugene Rodionov, and Sergey Bratus. Chapter 5, Operating System Boot Process Essentials. The boot chain in the detail the MBR and VBR challenges assume you already have.
- Rootkits and Bootkits, Alex Matrosov, Eugene Rodionov, and Sergey Bratus. Chapter 18, Approaches to Analyzing Hidden Filesystems. What to do when the filesystem itself is the thing lying to you.
If you finish early
- Hand out a challenge from the cross-CTF index in this category - each one has published solutions to compare afterwards.
- Run the same input through Identify and let the class argue with the ranking. Disagreeing with a confidence score is where the technique actually lands.
- Ask a student to break their own example - construct an input that defeats the tool, and explain why.
Take this into a room
Markdown files, built here in your browser. They print, they open in anything, and they carry the challenge text - so the session works with no network in the room.