competition-pcap-protocol

Installation
SKILL.md

Competition PCAP Protocol

Use this skill only as a downstream specialization after $ctf-sandbox-orchestrator is already active and has established sandbox assumptions, node ownership, and evidence priorities. If that has not happened yet, return to $ctf-sandbox-orchestrator first.

Use this skill when the decisive evidence sits inside packet order, protocol framing, or stream reconstruction rather than a single IOC or host log.

Reply in Simplified Chinese unless the user explicitly requests English.

Quick Start

  1. Establish the capture boundaries first: hosts, time span, interfaces, missing packets, retransmits, and stream count.
  2. Group traffic into sessions before decoding payload semantics.
  3. Record protocol framing, sequence, timing, and transferred artifacts together instead of as isolated packets.
  4. Correlate packet evidence with host, malware, or app behavior only after the session is reconstructed.
  5. Reproduce the smallest decoded stream or transferred artifact that proves the challenge path.

Workflow

1. Build The Session Map

Related skills

More from galiais/ctf-sandbox-orchestrator

Installs
8
GitHub Stars
92
First Seen
Mar 31, 2026