Digital Forensics CTF Challenges
Disk, memory, disk image & timeline triage.
Round duration
12 hours
Format
Jeopardy-style CTF
Team size
1–3 members
Digital forensics is the one category where you are not attacking a system — you are reconstructing one after the fact. A disk image, a memory dump or a packet capture lands in front of you, and your job is to work out what happened, who did it and when, then prove it with the artefact that proves it.
The core discipline is triage under time pressure. Real forensic work is about deciding what to look at first: timestamps that do not agree, a file with a suspiciously empty metadata block, an executable nobody remembers installing. The competitors who score fastest are the ones who build a reliable routine and refuse to abandon it under pressure.
Tools do a lot of the heavy lifting here. Autopsy, Sleuth Kit, Volatility, Wireshark, binwalk and foremost will surface most of what you need. The skill that matters is knowing which one to reach for, and reading its output critically enough to know when it has found nothing.
What you’ll actually face
Challenge types modelled on the work real security teams do, weighted toward the mid and upper difficulty bands.
Disk & filesystem
Partition tables, deleted file recovery, unallocated space, alternate data streams, journal artefacts and files that were renamed rather than deleted.
Memory forensics
Process and network state recovered from a RAM dump: running processes, injected code, open handles, credentials and injected shellcode in memory.
Network analysis
PCAP files reassembled into sessions — reconstructing a web request, spotting data exfiltration over DNS, or identifying a command-and-control channel.
Timeline reconstruction
Correlating timestamps across artefacts to answer "when did this happen", where file times, log entries and registry keys disagree with one another.
Embedded & hidden data
Data appended after the end of a file, buried in slack space, hidden in image metadata or packed inside another container that the header does not describe.
Log & registry analysis
Windows event logs, browser history and caches, and registry keys that record user actions no other artefact captured.
Tools you’ll reach for
- Autopsy / The Sleuth Kit
- Volatility 3
- Wireshark & tshark
- binwalk
- foremost
- ExifTool
- FTK Imager
- strings / xxd
How to prepare
None of this is required to enter — it is simply the shortest path to scoring points in this discipline.
Build a Volidity 3 workflow end to end on a practice image: plugins list, process listing, network scan, file dump. Speed beats novelty in this category.
Learn to read a hex dump by hand for the first few bytes. File signatures are the fastest way to identify a carved artefact.
Practise timeline questions specifically — most challenges ultimately ask "when" or "in what order".
Get comfortable with `tshark` field filters so you can isolate a conversation instead of scrolling through thousands of packets.
Do at least one full forensic writeup end to end. It forces you to record what you examined, which is exactly the discipline the category rewards.
Quick facts
Everything about Ghost Protocol CTF 2.0 at a glance.
- Online qualifier
- 17 October 2026 · 12 hours · remote
- Grand finale
- 24 October 2026 · 12 hours · on-ground
- Format
- Jeopardy-style CTF
- Team size
- 1–3 members (solo entry allowed)
- Registration fee
- Free per team
- Prize pool
- Up to ₹51,000
- Challenge categories
- 10 disciplines
- Eligibility
- Any student in an undergraduate or postgraduate programme, any stream
- Venue
- NIET Greater Noida
- Organised by
- Cyber Invaders · NIET Greater Noida
Adjacent disciplines
Competitors in CTF teams tend to specialise — here is where the skills overlap.
Ready to prove it on the scoreboard?
Digital Forensics is one of 10 disciplines in Ghost Protocol CTF 2.0. Entry is free and teams of 1–3 are welcome.