Walkthroughs for 41 challenges from Friendly Securinets CTF 2026: 39 forensics tasks
across three waves, one reverse-engineering challenge, and one web-exploitation challenge.
They run from file-format analysis up to full incident reconstruction, memory forensics, cryptanalysis, and debugger-driven reversing.
Friendly Securinets CTF 2026
Writeups in this collection
- 01 Forensics Wave 1 Seven easy-to-medium forensics challenges: header repair, layered encodings, nested archives, a disguised shell archive, low-contrast stego, Morse audio, and a PNG/PDF polyglot.
- 02 Forensics Wave 2 Eighteen intermediate forensics tasks covering Git history, browser artifacts, DNS, maldocs, packet analysis, steganography, and reverse engineering.
- 03 Forensics Wave 3 Fourteen advanced forensics challenges spanning memory analysis, DFIR, TLS recovery, cloud logs, mobile artifacts, network cryptanalysis, and hardware signals.
- 04 Twofold A Windows reverse-engineering challenge that requires recovering a license key statically, then manipulating execution in a debugger to reveal a runtime-only unlock token.
- 05 Reset Vault A web exploitation challenge built around predictable MongoDB ObjectIds, deterministic token generation, and AES keys derived from attacker-guessable identifiers.
Where to start
| If you are… | Start with |
|---|---|
| New to forensics | Forensics — Wave 1: one artifact, one technique per challenge |
Comfortable with Wireshark, sqlite3 and Git |
Forensics — Wave 2: Cookie Jar, Force Push and the Chilla Box incident |
| Looking for DFIR depth | Forensics — Wave 3: Key Recovery, Timestomped, Trailhead and Nitro |
| Into reversing or web | Twofold or Reset Vault |
How the waves progress
- Wave 1: recognition. File signatures, archive structure, common encodings, and
hidden data in images and audio. - Wave 2: investigation. Choosing the right tool, filtering noisy data, recovering
deleted state, and correlating evidence across several formats. - Wave 3: reconstruction. Timelines, volatile evidence, encrypted traffic, protocol
behaviour, and implementation flaws, with no exposed flag string to search for. - Twofold and Reset Vault apply the same evidence-first approach to debugger state and
application logic.
What the set covers
- Network forensics across HTTP, DNS, TLS, C2 beaconing, and encrypted exfiltration
- Windows, browser, memory, disk, mobile, cloud, Git, document, and Linux artifact analysis
- File repair, steganography, archive attacks, audio analysis, hardware signals, and packet reconstruction
- Static and dynamic reverse engineering, cryptographic implementation flaws, and web logic vulnerabilities
How to read the writeups
Each challenge starts with its points, files and description, followed by:
- Hints: collapsed and progressive, so you can try the challenge first.
- What it targets: the skills involved and why they matter outside a CTF.
- Walkthrough: the commands, their output, and the reasoning that connects them.
- Pitfalls, red herrings and alternative paths, where relevant.
- Flag: collapsed at the end of the section.
Each wave page also lists the tools used, with install commands.