Challenge Category

Steganography CTF Challenges

Hidden data extraction from files & media.

Round duration

12 hours

Format

Jeopardy-style CTF

Team size

1–3 members

Steganography is the art of hiding data inside something that appears to be something else — a photograph, an audio file, a disk image, a piece of source code. The data is genuinely there, and often it is not hidden with great sophistication. The real skill is refusing to accept that the file you were given is only what it appears to be.

Most solves follow the same arc: notice an anomaly (a file much larger than its visible content warrants, a colour channel that is not what it should be, an ID3 tag with unusual padding), then escalate through a short list of standard tools until something falls out. The escalation order is the thing to memorise, because time pressure means you cannot try things at random.

It is a fast-scoring category. The techniques are finite, the tools are cheap, and a solver who knows the ladder can extract a flag in under two minutes. If you want points early in a competition, this is where they are.

What you’ll actually face

Challenge types modelled on the work real security teams do, weighted toward the mid and upper difficulty bands.

Concatenated files

A second file appended after the end of the first, or embedded after the image EOF marker. Recoverable with `binwalk` or a simple carve.

LSB encoding

Data written into the least significant bits of pixel values, recoverable with `zsteg`, `stegsolve` or a few lines of Python and Pillow.

Spectrogram and audio

Text or shapes encoded in the frequency domain of an audio file, visible in a spectrogram but completely inaudible on playback.

Tool-specific carriers

Data hidden using `steghide` in JPEGs or WAV, `outguess` in JPEGs, or OpenStego — each requiring its matching extraction tool.

Container manipulation

Hidden data in PNG ancillary chunks, JPEG comments, PDF metadata or font tables — legitimate container features used off-purpose.

Encoding layers

A flag that is itself base64 or hex encoded, sitting inside something already extracted. Layers are common and cheap to check.

Tools you’ll reach for

  • binwalk
  • zsteg
  • stegsolve
  • steghide
  • exiftool
  • Audacity (spectrogram)
  • CyberChef
  • Pillow (Python)

How to prepare

None of this is required to enter — it is simply the shortest path to scoring points in this discipline.

  1. Memorise the escalation ladder: `file` → `strings` → `binwalk` → `exiftool` → `zsteg` → `steghide`. Trying them in order beats guessing.

  2. Learn to read `binwalk` output properly, including how to carve a specific offset rather than extracting everything.

  3. Get comfortable with `zsteg` bit-plane syntax — knowing what `-b 2,8,lsb,xy` selects is worth several solves on its own.

  4. Keep Audacity installed and know how to switch to spectrogram view. Audio challenges are fast once you can see them.

  5. Always run a hex dump on anything that feels wrong. `xxd | head` catches more than you would expect.

Quick facts

Everything about Ghost Protocol CTF 2.0 at a glance.

Online qualifier
17 October 2026 · 12 hours · remote
Grand finale
24 October 2026 · 12 hours · on-ground
Format
Jeopardy-style CTF
Team size
1–3 members (solo entry allowed)
Registration fee
Free per team
Prize pool
Up to ₹51,000
Challenge categories
10 disciplines
Eligibility
Any student in an undergraduate or postgraduate programme, any stream
Venue
NIET Greater Noida
Organised by
Cyber Invaders · NIET Greater Noida

Ready to prove it on the scoreboard?

Steganography is one of 10 disciplines in Ghost Protocol CTF 2.0. Entry is free and teams of 1–3 are welcome.