Challenge Category

Digital Forensics CTF Challenges

Disk, memory, disk image & timeline triage.

Round duration

12 hours

Format

Jeopardy-style CTF

Team size

1–3 members

Digital forensics is the one category where you are not attacking a system — you are reconstructing one after the fact. A disk image, a memory dump or a packet capture lands in front of you, and your job is to work out what happened, who did it and when, then prove it with the artefact that proves it.

The core discipline is triage under time pressure. Real forensic work is about deciding what to look at first: timestamps that do not agree, a file with a suspiciously empty metadata block, an executable nobody remembers installing. The competitors who score fastest are the ones who build a reliable routine and refuse to abandon it under pressure.

Tools do a lot of the heavy lifting here. Autopsy, Sleuth Kit, Volatility, Wireshark, binwalk and foremost will surface most of what you need. The skill that matters is knowing which one to reach for, and reading its output critically enough to know when it has found nothing.

What you’ll actually face

Challenge types modelled on the work real security teams do, weighted toward the mid and upper difficulty bands.

Disk & filesystem

Partition tables, deleted file recovery, unallocated space, alternate data streams, journal artefacts and files that were renamed rather than deleted.

Memory forensics

Process and network state recovered from a RAM dump: running processes, injected code, open handles, credentials and injected shellcode in memory.

Network analysis

PCAP files reassembled into sessions — reconstructing a web request, spotting data exfiltration over DNS, or identifying a command-and-control channel.

Timeline reconstruction

Correlating timestamps across artefacts to answer "when did this happen", where file times, log entries and registry keys disagree with one another.

Embedded & hidden data

Data appended after the end of a file, buried in slack space, hidden in image metadata or packed inside another container that the header does not describe.

Log & registry analysis

Windows event logs, browser history and caches, and registry keys that record user actions no other artefact captured.

Tools you’ll reach for

  • Autopsy / The Sleuth Kit
  • Volatility 3
  • Wireshark & tshark
  • binwalk
  • foremost
  • ExifTool
  • FTK Imager
  • strings / xxd

How to prepare

None of this is required to enter — it is simply the shortest path to scoring points in this discipline.

  1. Build a Volidity 3 workflow end to end on a practice image: plugins list, process listing, network scan, file dump. Speed beats novelty in this category.

  2. Learn to read a hex dump by hand for the first few bytes. File signatures are the fastest way to identify a carved artefact.

  3. Practise timeline questions specifically — most challenges ultimately ask "when" or "in what order".

  4. Get comfortable with `tshark` field filters so you can isolate a conversation instead of scrolling through thousands of packets.

  5. Do at least one full forensic writeup end to end. It forces you to record what you examined, which is exactly the discipline the category rewards.

Quick facts

Everything about Ghost Protocol CTF 2.0 at a glance.

Online qualifier
17 October 2026 · 12 hours · remote
Grand finale
24 October 2026 · 12 hours · on-ground
Format
Jeopardy-style CTF
Team size
1–3 members (solo entry allowed)
Registration fee
Free per team
Prize pool
Up to ₹51,000
Challenge categories
10 disciplines
Eligibility
Any student in an undergraduate or postgraduate programme, any stream
Venue
NIET Greater Noida
Organised by
Cyber Invaders · NIET Greater Noida

Ready to prove it on the scoreboard?

Digital Forensics is one of 10 disciplines in Ghost Protocol CTF 2.0. Entry is free and teams of 1–3 are welcome.