Digital forensics and incident response (DFIR) writeups from Google CTF, DEF CON, picoCTF, and other global competitions. Organized by year and event.


2025 Challenges

Google CTF 2025

Google CTF 2025

PacketMonster

Easy

Category: Forensics · Points: 100 · Solves: 580

A network PCAP file containing suspicious port scanning and TCP streams. Locate the payload transmission stream and carve out the hidden files.

PCAPWiresharkTCP StreamFile Carving

HTB Cyber Apocalypse 2025

HTB Cyber Apocalypse 2025

MemDissect

Medium

Category: Forensics · Points: 260 · Solves: 140

Memory dump of a Windows Server compromised via LSASS dumping. Use Volatility 3 to locate the LSASS process and recover NT hashes.

Volatility 3Memory ForensicsLSASSCredential Dumping