Turn CTF artifacts into interactive investigations.
Detect real file types, inspect metadata and archives, carve trailing data,
decode multi-stage clues, preserve provenance, and verify flags without
confusing a discovered candidate with the correct answer.
Browser sandbox
No artifact upload. No binary execution.
⇧
Drop an artifact to begin
Images, archives, executables, documents, captures, audio, and text up to 50 MB.
Use only authorized CTF or educational artifacts.
Practice modeNo challenge manifest loaded
Candidates can be collected, but only a manifest can verify the final flag.
Detected format—
—
File size—
—
Entropy—
Waiting for analysis
Evidence0
No evidence recorded
Progress0 / 4
Investigation not started
ARTIFACT ANALYSIS
No artifact selected
UnknownRead-only
Filename—
Browser MIME—
Detected format—
File size—
Printable ratio—
Artifact rolePrimary artifact
SHA-256
—
INITIAL ASSESSMENT
Upload an artifact to begin analysis.
Challenge artifact mismatch
The loaded artifact SHA-256 does not match the manifest. Verification is disabled.
No metadata has been extracted yet.
No strings extracted yet.
No hex preview available.
No archive region has been detected.
No findings yet.
No evidence recorded yet.
DECODER WORKBENCH
Transform suspicious data
Decoded output will appear here.
No decoder steps recorded.
FLAG VERIFICATION
Submit recovered flag
Unverified practice
A candidate is not considered correct until a challenge manifest verifies its SHA-256.
Discovered candidates0
No flag candidates discovered yet.
COMMAND GUIDE
Understand the terminal
Select a command to see what it does, why it helps, and its risk level.