Browse CTFs New CTF Sign in
Back to Learning Paths
OSINT & Cyber Threat Intelligence
Specialist Wave 1

OSINT & Cyber Threat Intelligence

30.0h estimated 3 Courses

Specialist certification in OSINT collection and cyber threat intelligence. Covers collection, pivoting, infrastructure analysis, and TTP mapping.

Sign in to enroll

OSINT Collection, Pivoting and Validation

15 cards

AWS Cognito Unauthenticated Identity Pool Exploitation: Anonymous Credential Escalation

osint_collection Difficulty 1–5 30 min

Terraform State Manipulation: Injecting Malicious Resource Definitions via Backend Write Access

osint_collection Difficulty 1–5 30 min

AWS CloudFormation Credential Exposure: Extracting Secrets from Stack Templates

osint_collection Difficulty 1–5 30 min

AWS Lambda Execution Role Privilege Escalation: Function Invocation for IAM Abuse

osint_collection Difficulty 1–5 30 min

AWS Secrets Manager Access Control Weaknesses: Scoping IAM Policies for GetSecretValue

osint_collection Difficulty 1–5 30 min

AWS Confused Deputy Attack: Cross-Account Role Assumption Without External ID Enforcement

osint_collection Difficulty 1–5 30 min

Reconstructing SMTP Email Sessions and Extracting Attachments from Network Traffic Captures

osint_collection Difficulty 1–5 30 min

Parsing FTP Command and Response Traffic with Passive Mode Data Channel Reconstruction

osint_collection Difficulty 1–5 30 min

Parsing Telnet IAC Command Sequences and Reconstructing Plaintext Sessions from PCAP

osint_collection Difficulty 1–5 30 min

Reconstructing IRC Sessions via Protocol PCAP Analysis and Channel Message Content Recovery

osint_collection Difficulty 1–5 30 min

Reconstructing LDAP Directory Queries via PCAP Analysis and Enumeration Pattern Detection

osint_collection Difficulty 1–5 30 min

Analyzing WebSocket PCAP Captures via HTTP Upgrade Detection and Frame Payload Extraction

osint_collection Difficulty 1–5 30 min

Reconstructing SIP Call Dialogs and Extracting RTP Stream Parameters for VoIP Forensics

osint_collection Difficulty 1–5 30 min

Enumerating Local Services via mDNS PCAP Multicast Record Analysis and Host Fingerprinting

osint_collection Difficulty 1–5 30 min

Interpreting Modbus/TCP Function Codes and Extracting PLC Register Values from PCAP

osint_collection Difficulty 1–5 30 min

Threat Infrastructure and Adversary TTPs

70 cards

Detecting Advanced DNS Tunneling Evasion via Slow-Rate Exfiltration and Multi-Domain Correlation

network_forensics_pcap Difficulty 1–5 30 min

Reconstructing HTTP Sessions via Multi-Request Correlation, Credential and Object Recovery

network_forensics_pcap Difficulty 1–5 30 min

Detecting TLS Fingerprint Anomalies via JA3/JA3S Computation and Malware Client Identification

network_forensics_pcap Difficulty 1–5 30 min

Detecting ICMP Covert Channels via Payload Anomaly Identification and Hidden Data Extraction

network_forensics_pcap Difficulty 1–5 30 min

Reconstructing FTP Data Exfiltration via Passive Mode Analysis and TCP Stream Extraction

network_forensics_pcap Difficulty 1–5 30 min

Analyzing Advanced SMTP Exfiltration via MIME Multipart Parsing and Encoded Attachment Recovery

network_forensics_pcap Difficulty 1–5 30 min

Identifying IRC Botnet C2 via PRIVMSG Command Pattern Analysis and Bot Fingerprinting

network_forensics_pcap Difficulty 1–5 30 min

Detecting Kerberoasting and AS-REP Roasting via TGS-REQ Analysis and Ticket Extraction

network_forensics_pcap Difficulty 1–5 30 min

Analyzing WebSocket Data Exfiltration via Frame Demasking, Payload Extraction and Protocol Reconstruction

network_forensics_pcap Difficulty 1–5 30 min

Extracting Modbus Register Data via ICS/OT Protocol Forensics and Unauthorized Read Detection

network_forensics_pcap Difficulty 1–5 30 min

Recovering Corrupted PCAP Files via Magic Byte Forensics and Partial Capture Reconstruction

network_forensics_pcap Difficulty 1–5 30 min

Volatility 3 Advanced Analysis: Symbol Tables, Namespaced Plugins and Cross-Layer Memory Correlation

network_forensics_pcap Difficulty 1–5 30 min

Correlating Multi-Host Authentication Anomalies to Detect Lateral Movement

log_analysis_siem Difficulty 1–5 30 min

Correlating Audit Events Across Linux and Windows Privilege Escalation Transitions

log_analysis_siem Difficulty 1–5 30 min

QR code decode

log_analysis_siem Difficulty 1–5 30 min

Vigenère Cipher Cryptanalysis: Kasiski Examination and Index of Coincidence Attack

cloud_container_security Difficulty 1–5 30 min

Cracking Columnar Transposition Ciphers: Key-Length Detection and Column Reordering

cloud_container_security Difficulty 1–5 30 min

AES-ECB Block Alignment Attack: Exploiting Deterministic Encryption for Oracle Leakage

cloud_container_security Difficulty 1–5 30 min

CBC Padding Oracle Attack: Byte-by-Byte Plaintext Recovery via PKCS#7 Error Responses

cloud_container_security Difficulty 1–5 30 min

AES-CTR Nonce Reuse Attack: XOR-Based Keystream Recovery and Plaintext Decryption

cloud_container_security Difficulty 1–5 30 min

Exploiting Symmetric Key Reuse Across Users: Cross-Account Ciphertext Oracle Attacks

cloud_container_security Difficulty 1–5 30 min

Extracting Hardcoded Symmetric Keys from Binaries via Static Reverse Engineering

cloud_container_security Difficulty 1–5 30 min

Attacking Weak Key Derivation Functions: Dictionary Attacks on Under-Iterated Password Hashing

cloud_container_security Difficulty 1–5 30 min

XOR Keystream Reuse Attack: Many-Time Pad Cryptanalysis and Statistical Key Recovery

cloud_container_security Difficulty 1–5 30 min

Cracking RSA Small Public Exponents: Cube-Root Recovery and Low-Exponent Bias

cloud_container_security Difficulty 1–5 30 min

RSA Broadcast Attack: CRT-Based Plaintext Recovery Across Multiple Recipients

cloud_container_security Difficulty 1–5 30 min

Factoring Weak RSA Primes via Fermat Factorisation and Pollard p-1 Method

cloud_container_security Difficulty 1–5 30 min

Sigreturn-Oriented Programming: Signal Frame Hijacking for Full CPU Register Control with Minimal Gadgets

log_analysis_siem Difficulty 1–5 30 min

Morse Code Decoding: Timing Analysis, Delimiter Identification and Transcription Methodology

log_analysis_siem Difficulty 1–5 30 min

Bacon cipher

log_analysis_siem Difficulty 1–5 30 min

Zero-width steganography

log_analysis_siem Difficulty 1–5 30 min

Brainfuck encoding

log_analysis_siem Difficulty 1–5 30 min

NATO phonetic alphabet

log_analysis_siem Difficulty 1–5 30 min

Multi-layer encoding chain

log_analysis_siem Difficulty 1–5 30 min

QR Code Forensics: Error Correction Analysis and Partially Damaged Payload Reconstruction

log_analysis_siem Difficulty 1–5 30 min

Baudot encoding

log_analysis_siem Difficulty 1–5 30 min

Leetspeak obfuscation

log_analysis_siem Difficulty 1–5 30 min

Azure RBAC Misconfiguration: Subscription-Scope Role Assignments and Service Principal Abuse

log_analysis_siem Difficulty 1–5 30 min

AWS Service Control Policy Misconfiguration: Cross-Account Permission Escalation

log_analysis_siem Difficulty 1–5 30 min

S3 Bucket Policy Misconfiguration: Public Access, Cross-Account Grants and Transport Gaps

log_analysis_siem Difficulty 1–5 30 min

WAV spectrogram stego

cloud_container_security Difficulty 1–5 30 min

WAV echo stego

cloud_container_security Difficulty 1–5 30 min

LSB RGB stego

cloud_container_security Difficulty 1–5 30 min

Bit plane image stego

cloud_container_security Difficulty 1–5 30 min

Alpha channel LSB stego

cloud_container_security Difficulty 1–5 30 min

XOR two-image stego

cloud_container_security Difficulty 1–5 30 min

DCT block image stego

cloud_container_security Difficulty 1–5 30 min

Recovering Wide Strings (UTF-16LE) from Memory: C2 URL and Credential Extraction via Volatility

cloud_container_security Difficulty 1–5 30 min

Detecting XOR-Encoded Payloads in Memory Dumps: Entropy Analysis and Brute-Force Key Recovery

cloud_container_security Difficulty 1–5 30 min

DOCX core metadata forensics

network_forensics_pcap Difficulty 1–5 30 min

DOCX hidden text forensics

network_forensics_pcap Difficulty 1–5 30 min

DOCX revision comment forensics

network_forensics_pcap Difficulty 1–5 30 min

DOCX acrostic steganography

network_forensics_pcap Difficulty 1–5 30 min

DOCX revision history (track changes)

network_forensics_pcap Difficulty 1–5 30 min

DOCX extended app properties forensics

network_forensics_pcap Difficulty 1–5 30 min

XLSX core metadata forensics

network_forensics_pcap Difficulty 1–5 30 min

XLSX hidden cell forensics (white-on-white)

network_forensics_pcap Difficulty 1–5 30 min

XLSX named range forensics

network_forensics_pcap Difficulty 1–5 30 min

XLSX cell comment forensics

network_forensics_pcap Difficulty 1–5 30 min

XLSX hidden worksheet forensics

network_forensics_pcap Difficulty 1–5 30 min

XLSX very-hidden worksheet forensics

network_forensics_pcap Difficulty 1–5 30 min

Shellcode Injection and Execution: NX-Free Environment Exploitation and NOP Sled Delivery

network_forensics_pcap Difficulty 1–5 30 min

Kubernetes RBAC to S3 Pivot: Pod Service Account Lateral Movement to Cloud Storage

network_forensics_pcap Difficulty 1–5 30 min

IAM Privilege Escalation Chain: AssumeRole, PassRole and CreatePolicyVersion Abuse Paths

network_forensics_pcap Difficulty 1–5 30 min

Reconstructing Ransomware Infection Vectors from Multi-Source Log Evidence

network_forensics_pcap Difficulty 1–5 30 min

C2 Beaconing Detection via Log Interval Analysis and Temporal Correlation

network_forensics_pcap Difficulty 1–5 30 min

Correlating SQLi, XSS, LFI and RCE Attack Patterns Across Web Server Access Logs

network_forensics_pcap Difficulty 1–5 30 min

Detecting Malicious Service Persistence via Windows Event 7045 and Systemd Unit Forensics

network_forensics_pcap Difficulty 1–5 30 min

Detecting DNS Exfiltration Through Entropy-Based Subdomain Anomaly Analysis

network_forensics_pcap Difficulty 1–5 30 min

Instagram-to-Twitter Persona Pivot: Cross-Platform Handle Correlation and Profile Reconstruction

network_forensics_pcap Difficulty 1–5 30 min

CTI Reporting, IoCs and Intelligence Requirements [Non-CTF]

0 cards

No cards in this course yet.

🏅

CTFFactory OSINT & Cyber Threat Intelligence — Specialist

Specialist credential — awarded upon completion