KASPERSKY CTF 2026 • FORENSICS TRACK
Kaspersky CTF
Detailed walkthroughs for all 3 official forensics challenges from Kaspersky CTF 2026. Covering memory dumps, PoolParty process injection, Apple CoreStorage volume carving, and TLS covert channel cryptanalysis.
Forensics Track
3 WriteupsSolved Challenges (3/3)

Memory Forensics500 PTS
PoolParty & Havoc Demon Reversing
Ping Pong Show
Investigating a 4.5 GB Windows 10 RAM dump. Carving Outlook phishing attachments, reversing PoolParty ThreadPool injection into Acrobat, and decrypting Havoc Demon C2 traffic.
Volatility 3PoolPartyHavoc DemonAES-CTROutlook MPFS
⏱ 10 min readRead Guide →

macOS DFIR500 PTS
CoreStorage Fusion Drive & FileVault
Ryan Guzling
Reassembling an Apple CoreStorage Fusion Drive split across SSD and HDD images. Carving an HFS+ trash volume to recover the FileVault recovery key and unlock the volume.
CoreStorageFileVaultHFS+SleuthKithdiutil
⏱ 8 min readRead Guide →

Network Forensics500 PTS
TLS GREASE Covert Channel & DLL Sideloading
Time to Install Arch
Forensic analysis of a Windows Server 2016 VMDK and PCAP. Spotting GAC DLL sideloading, decoding a covert channel inside TLS GREASE 0x0a0a extensions, and ChaCha20 decryption.
WiresharkDLL SideloadingTLS GREASEChaCha20tshark
⏱ 9 min readRead Guide →