Lesson pack 18 · Advanced · 90 minutes
Network forensics
Triage a packet capture: find the one conversation that matters, extract transferred files, and spot exfiltration over DNS.
Print this page for a paper plan - the navigation and links drop out.Student-facing version
Before the session
- Nothing to install. Students need a browser and https://ctfpal.com. Confirm the room can reach it once; after that it works offline.
- Read the lesson yourself first - about 15 minutes.
- Have one worked example ready to paste. The classroom link builder on the instructor page turns it into a URL that opens preloaded.
Objectives
Written as things a student can do afterwards, so they can be assessed rather than asserted.
- Use a protocol breakdown to decide where to look first
- Reassemble a TCP stream and read a plaintext protocol
- Extract files transferred over HTTP, FTP, or SMB
- Recognise DNS tunnelling and decode the exfiltrated payload
- Decrypt TLS from a capture when the key material is available, and say exactly what it takes
- Infer the structure of an undocumented binary protocol from repeated messages
Running order (90 min)
| Time | What happens |
|---|---|
| 0:00-0:09 | Frame the problemWhat the category looks like when you meet it cold, and why the naive approach fails. |
| 0:09-0:27 | Teach the methodThe technique itself, on the board or from the lesson. No tools open yet. |
| 0:27-0:50 | Demonstrate liveSame technique, in the workspace, on your worked example. Narrate every choice. |
| 0:50-1:21 | Practice setStudents work the challenges. Circulate rather than present. |
| 1:21-1:30 | Checkpoint and wrapCollect the artefact, name what comes next. |
Tools used
- PCAP analyzer for CTF network forensics - Drop a packet capture and extract HTTP objects, DNS queries, credentials, transferred files, and flags - with TLS decryption when you have the keys.https://ctfpal.com/?tool=pcap-analyzer
- PCAP overview: protocols, conversations and hosts - Open a capture and see what is in it before reading a single packet: the protocol histogram, the busiest conversations, and whether credentials or flags are already sitting in plaintext.https://ctfpal.com/?tool=pcap-overview
- Packet list and raw frame bytes - Walk a capture packet by packet with its dissection and its raw bytes, for the traffic that has no higher-level tab.https://ctfpal.com/?tool=pcap-packets
- Follow a TCP stream in the browser - Reassemble a TCP conversation from its segments and read it as one transcript, in order, with each direction separable.https://ctfpal.com/?tool=follow-tcp-stream
- DNS queries from a PCAP, and DNS exfiltration - List every DNS query and answer in a capture, and recognise the shape of data being smuggled out through subdomain labels.https://ctfpal.com/?tool=pcap-dns
- Find plaintext credentials in a packet capture - Scan a capture for passwords sent in the clear - HTTP Basic auth, login forms, FTP, Telnet, POP3, IMAP and SMTP.https://ctfpal.com/?tool=pcap-credentials
- Extract HTTP requests and responses from a PCAP - Pull every HTTP request and response out of a capture - URLs, headers, cookies, form bodies and transferred files - without opening Wireshark.https://ctfpal.com/?tool=http-from-pcap
- Search a packet capture for flags - Scan every packet payload in a capture for flag-shaped strings, including flags that straddle a TCP segment boundary.https://ctfpal.com/?tool=pcap-flag-search
- Decrypt TLS in a PCAP with an SSLKEYLOGFILE - Decrypt TLS 1.2 and TLS 1.3 traffic in a capture using the key log the challenge gave you, entirely in the browser.https://ctfpal.com/?tool=decrypt-tls-pcap
- Base32 decoder and encoder - Decode Base32 (RFC 4648) to text or bytes, with padding repair. Distinguishes Base32 from Base64 and hex automatically.https://ctfpal.com/?tool=base32-decoder
- Timestamp converter (Unix, ISO, FILETIME, HFS+) - Convert between Unix seconds and milliseconds, ISO 8601, local time, and the non-standard epochs used by Windows, macOS, and Flask.https://ctfpal.com/?tool=timestamp-converter
- Strings extractor for binaries and blobs - Pull printable ASCII and UTF-16 strings out of any file, filtered by length, with flag-pattern highlighting.https://ctfpal.com/?tool=strings-extractor
Reading
- PCAP triage: finding the flag in a hundred thousand packets - 7 min. Network forensics challenges hand you a capture and no question. The triage order that finds the answer fast - protocol hierarchy, conversations, streams - plus the exfiltration channels people actually hide flags in: DNS, ICMP, USB, and TLS you can decrypt.
- Reversing a binary protocol from a capture - 8 min. A CTF hands you a pcap of some custom protocol and no specification. The structures every hand-rolled protocol is built from - magic, length prefixes, TLV, varints - and a repeatable way to turn a hex dump into a parser that reads the flag out.
Practice set
Real picoCTF challenges tagged with this module’s techniques, easiest first. Assign the first three in class and the rest as homework.
- Ph4nt0m 1ntrud3r - picoCTF 2025, easy
- Printer Shares - picoCTF 2026, easy
- Eavesdrop - picoCTF 2022, medium
- FindAndOpen - picoCTF 2023, medium
- North-South - picoCTF 2026, medium
- Packets Primer - picoCTF 2022, medium
- PcapPoisoning - picoCTF 2023, medium
- Rogue Tower - picoCTF 2026, medium
- shark on wire 1 - picoCTF 2019, medium
- Printer Shares 2 - picoCTF 2026, hard
- Printer Shares 3 - picoCTF 2026, hard
- WebNet0 - picoCTF 2019, hard
Checkpoint (gradeable)
From a capture, produce the exfiltrated payload and the exact query sequence that carried it.
Deliberately a produced artefact rather than a quiz question: it is either there or it is not, which makes it fast to mark and hard to bluff. Every tool in ctfpal is deterministic, so two students who did the work correctly hand in the same value.
Where the room gets stuck
The habit to build is looking for the anomaly rather than reading the traffic. Ask students what is unusual before asking what it says - the answer is almost always in the outlier.
- Reading packets in order. A hundred thousand packets is a statistics problem first - protocol breakdown, conversation sizes, endpoint counts - and a reading problem second.
- Dismissing DNS as noise. Long labels, high query rates to one domain, and base32-looking subdomains are the standard exfiltration signature.
- Assuming TLS ends the investigation. Server names, certificates, timing and sizes survive encryption, and challenges often supply the key log anyway.
- Searching packet bytes for the flag format and concluding it is absent. Anything transferred is split across packets and often compressed or encoded in transit, so the search belongs on the reassembled stream.
- Believing the protocol column. It is a dissector's guess, usually from the port number, and the binary-protocol half of this module exists because the traffic that matters is the traffic no dissector claimed.
If a student wants the subject, not the answer
Chapter-level references, so a student can be pointed at twenty pages rather than at a book. Nothing here is required to complete the module.
- Attacking Network Protocols, James Forshaw. Chapter 2, Capturing Application Traffic. Capture positions and their blind spots, which decides what a pcap can and cannot contain.
- Attacking Network Protocols, James Forshaw. Chapter 3, Network Protocol Structures. The structural vocabulary - TLV, length prefixes, varints - that turns an unknown protocol into a parse.
- Attacking Network Protocols, James Forshaw. Chapter 5, Analysis from the Wire. A disciplined method for going from bytes on the wire to a description of the protocol.
- Practical IoT Hacking, Fotios Chantzis, Ioannis Stais, Paulino Calderon, Evangelos Deirmentzoglou, and Beau Woods. Chapter 5, Analyzing Network Protocols. Writing a dissector for a protocol nobody has documented, which is the CTF task in its professional form.
If you finish early
- Hand out a challenge from the cross-CTF index in this category - each one has published solutions to compare afterwards.
- Run the same input through Identify and let the class argue with the ranking. Disagreeing with a confidence score is where the technique actually lands.
- Ask a student to break their own example - construct an input that defeats the tool, and explain why.
Take this into a room
Markdown files, built here in your browser. They print, they open in anything, and they carry the challenge text - so the session works with no network in the room.