Zsteg
Zsteg is a Ruby-based steganography detection tool that automatically analyzes PNG and BMP images for hidden data using various extraction techniques.
Installation
Linux/Ubuntu
# Install Ruby 2.4+
sudo apt install ruby ruby-dev
# Install zsteg gem
sudo gem install zsteg
# Or from source
git clone https://github.com/zardus/ctf-tools.git
cd ctf-tools
./install zsteg
Verify Installation
zsteg -v
zsteg --help
Basic Commands
| Command | Description |
|---|---|
zsteg image.png | Analyze image for steganography |
zsteg image.png -a | All techniques (comprehensive scan) |
zsteg image.png -b 1,2 | Check bit planes 1 and 2 |
zsteg image.png -E | Extract LSB data directly |
zsteg image.png -o output.txt | Save output to file |
Analysis Techniques
Automatic Analysis
# Scan all known techniques (SLOW)
zsteg image.png -a
# Output matches and confidence scores
# Shows: detected patterns, text, data size, method used
Bit Plane Analysis
# Analyze specific bit planes
zsteg image.png -b 1 # Bit plane 1 only
zsteg image.png -b 0,1,2 # Multiple planes
# LSB extraction
zsteg image.png -b 0 # Least significant bit (common)
# Check all 8 planes
for i in {0..7}; do zsteg image.png -b $i; done
Extraction Methods
# Extract LSB data directly
zsteg image.png -E
# Extract with order specification
zsteg image.png -E xy # XY extraction order
zsteg image.png -E yx # YX extraction order (transpose)
# Extract and save output
zsteg image.png -E -o data.bin
# Verbose extraction with progress
zsteg image.png -E -v
Specific Parameter Extraction
# ZLIB compression detection
zsteg image.png -z # Look for compressed data
# Prime analysis
zsteg image.png -p # Prime structure detection
# Various filters
zsteg image.png --all-filters # Test all PNG filters
Security Features
Authentication
# Login with username/password
zsteg login --user <username>
# Login with API key
zsteg login --api-key <key>
# Login with certificate
zsteg login --cert <cert_file>
# Logout current session
zsteg logout
# Change password
zsteg passwd
# Generate new API key
zsteg generate-key --name <key_name>
# List active sessions
zsteg sessions
# Revoke session
zsteg revoke --session <session_id>
Encryption
# Encrypt file
zsteg encrypt --input <file> --output <encrypted_file>
# Decrypt file
zsteg decrypt --input <encrypted_file> --output <file>
# Generate encryption key
zsteg keygen --type <type> --size <size>
# Sign file
zsteg sign --input <file> --key <private_key>
# Verify signature
zsteg verify --input <file> --signature <sig_file>
# Hash file
zsteg hash --algorithm <algo> --input <file>
# Generate certificate
zsteg cert generate --name <name> --days <days>
# Verify certificate
zsteg cert verify --cert <cert_file>
Monitoring and Logging
System Monitoring
# Monitor system resources
zsteg monitor --system
# Monitor specific process
zsteg monitor --pid <pid>
# Monitor network activity
zsteg monitor --network
# Monitor file changes
zsteg monitor --files <directory>
# Real-time monitoring
zsteg monitor --real-time --interval 1
# Generate monitoring report
zsteg report --type monitoring --output <file>
# Set monitoring alerts
zsteg alert --threshold <value> --action <action>
# View monitoring history
zsteg history --type monitoring
Logging
# View logs
zsteg logs
# View logs with filter
zsteg logs --filter <pattern>
# Follow logs in real-time
zsteg logs --follow
# Set log level
zsteg logs --level <level>
# Rotate logs
zsteg logs --rotate
# Export logs
zsteg logs --export <file>
# Clear logs
zsteg logs --clear
# Archive logs
zsteg logs --archive <archive_file>
Troubleshooting
Common Issues
Issue: Command not found
# Check if zsteg is installed
which zsteg
zsteg --version
# Check PATH variable
echo $PATH
# Reinstall if necessary
sudo apt reinstall zsteg
# or
brew reinstall zsteg
Issue: Permission denied
# Run with elevated privileges
sudo zsteg <command>
# Check file permissions
ls -la $(which zsteg)
# Fix permissions
chmod +x /usr/local/bin/zsteg
# Check ownership
sudo chown $USER:$USER /usr/local/bin/zsteg
Issue: Configuration errors
# Validate configuration
zsteg config validate
# Reset to default configuration
zsteg config reset
# Check configuration file location
zsteg config show --file
# Backup current configuration
zsteg config export > backup.conf
# Restore from backup
zsteg config import backup.conf
Issue: Service not starting
# Check service status
zsteg status --detailed
# Check system logs
journalctl -u zsteg
# Start in debug mode
zsteg start --debug
# Check port availability
netstat -tulpn|grep <port>
# Kill conflicting processes
zsteg killall --force
Debug Commands
| Command | Description |
|---|---|
zsteg --debug | Enable debug output |
zsteg --verbose | Enable verbose logging |
zsteg --trace | Enable trace logging |
zsteg test | Run built-in tests |
zsteg doctor | Run system health check |
zsteg diagnose | Generate diagnostic report |
zsteg benchmark | Run performance benchmarks |
zsteg validate | Validate installation and configuration |
Performance Optimization
Resource Management
# Set memory limit
zsteg --max-memory 1G <command>
# Set CPU limit
zsteg --max-cpu 2 <command>
# Enable caching
zsteg --cache-enabled <command>
# Set cache size
zsteg --cache-size 100M <command>
# Clear cache
zsteg cache clear
# Show cache statistics
zsteg cache stats
# Optimize performance
zsteg optimize --profile <profile>
# Show performance metrics
zsteg metrics
Parallel Processing
# Enable parallel processing
zsteg --parallel <command>
# Set number of workers
zsteg --workers 4 <command>
# Process in batches
zsteg --batch-size 100 <command>
# Queue management
zsteg queue add <item>
zsteg queue process
zsteg queue status
zsteg queue clear
Integration
Scripting
#!/bin/bash
# Example script using zsteg
set -euo pipefail
# Configuration
CONFIG_FILE="config.yaml"
LOG_FILE="zsteg.log"
# Check if zsteg is available
if ! command -v zsteg &> /dev/null; then
echo "Error: zsteg is not installed" >&2
exit 1
fi
# Function to log messages
log() \\\\{
echo "$(date '+%Y-%m-%d %H:%M:%S') - $1"|tee -a "$LOG_FILE"
\\\\}
# Main operation
main() \\\\{
log "Starting zsteg operation"
if zsteg --config "$CONFIG_FILE" run; then
log "Operation completed successfully"
exit 0
else
log "Operation failed with exit code $?"
exit 1
fi
\\\\}
# Cleanup function
cleanup() \\\\{
log "Cleaning up"
zsteg cleanup
\\\\}
# Set trap for cleanup
trap cleanup EXIT
# Run main function
main "$@"
API Integration
Environment Variables
| Variable | Description | Default |
|---|---|---|
ZSTEG_CONFIG | Configuration file path | ~/.zsteg/config.yaml |
ZSTEG_HOME | Home directory | ~/.zsteg |
ZSTEG_LOG_LEVEL | Logging level | INFO |
ZSTEG_LOG_FILE | Log file path | ~/.zsteg/logs/zsteg.log |
ZSTEG_CACHE_DIR | Cache directory | ~/.zsteg/cache |
ZSTEG_DATA_DIR | Data directory | ~/.zsteg/data |
ZSTEG_TIMEOUT | Default timeout | 30s |
ZSTEG_MAX_WORKERS | Maximum workers | 4 |
Configuration File
# ~/.zsteg/config.yaml
version: "1.0"
# General settings
settings:
debug: false
verbose: false
log_level: "INFO"
log_file: "~/.zsteg/logs/zsteg.log"
timeout: 30
max_workers: 4
# Network configuration
network:
host: "localhost"
port: 8080
ssl: true
timeout: 30
retries: 3
# Security settings
security:
auth_required: true
api_key: ""
encryption: "AES256"
verify_ssl: true
# Performance settings
performance:
cache_enabled: true
cache_size: "100M"
cache_dir: "~/.zsteg/cache"
max_memory: "1G"
# Monitoring settings
monitoring:
enabled: true
interval: 60
metrics_enabled: true
alerts_enabled: true
Examples
Basic Workflow
# 1. Initialize zsteg
zsteg init
# 2. Configure basic settings
zsteg config set port 8080
# 3. Start service
zsteg start
# 4. Check status
zsteg status
# 5. Perform operations
zsteg run --target example.com
# 6. View results
zsteg results
# 7. Stop service
zsteg stop
Advanced Workflow
# Comprehensive operation with monitoring
zsteg run \
--config production.yaml \
--parallel \
--workers 8 \
--verbose \
--timeout 300 \
--output json \
--log-file operation.log
# Monitor in real-time
zsteg monitor --real-time --interval 5
# Generate report
zsteg report --type comprehensive --output report.html
Automation Example
#!/bin/bash
# Automated zsteg workflow
# Configuration
TARGETS_FILE="targets.txt"
RESULTS_DIR="results/$(date +%Y-%m-%d)"
CONFIG_FILE="automation.yaml"
# Create results directory
mkdir -p "$RESULTS_DIR"
# Process each target
while IFS= read -r target; do
echo "Processing $target..."
zsteg \
--config "$CONFIG_FILE" \
--output json \
--output-file "$RESULTS_DIR/$\\\\{target\\\\}.json" \
run "$target"
done < "$TARGETS_FILE"
# Generate summary report
zsteg report summary \
--input "$RESULTS_DIR/*.json" \
--output "$RESULTS_DIR/summary.html"
Best Practices
Security
- Always verify checksums when downloading binaries
- Use strong authentication methods (API keys, certificates)
- Regularly update to the latest version
- Follow principle of least privilege
- Enable audit logging for compliance
- Use encrypted connections when possible
- Validate all inputs and configurations
- Implement proper access controls
Performance
- Use appropriate resource limits for your environment
- Monitor system performance regularly
- Optimize configuration for your use case
- Use parallel processing when beneficial
- Implement proper caching strategies
- Regular maintenance and cleanup
- Profile performance bottlenecks
- Use efficient algorithms and data structures
Operational
- Maintain comprehensive documentation
- Implement proper backup strategies
- Use version control for configurations
- Monitor and alert on critical metrics
- Implement proper error handling
- Use automation for repetitive tasks
- Regular security audits and updates
- Plan for disaster recovery
Development
- Follow coding standards and conventions
- Write comprehensive tests
- Use continuous integration/deployment
- Implement proper logging and monitoring
- Document APIs and interfaces
- Use version control effectively
- Review code regularly
- Maintain backward compatibility
Resources
Official Documentation
Community Resources
Learning Resources
- Getting Started Guide
- Tutorial Series
- Best Practices Guide
- Video Tutorials
- Training Courses
- Certification Program
Related Tools
- Git - Complementary functionality
- Docker - Alternative solution
- Kubernetes - Integration partner
Last updated: 2025-07-06|Edit on GitHub