Digital Forensics

steghide

steghide does steganography: it embeds a file inside an image or audio file so that the carrier looks and plays completely normally, with the hidden data protected by a passphrase. In forensics and CTFs it cuts both ways — you use it to recover data someone concealed in an innocent-looking JPEG, and to demonstrate how easily information can be smuggled past inspection. It embeds into JPEG, BMP, WAV, and AU files and can compress and encrypt the payload on the way in.

Official-repo package; Security → Digital Forensics → steghide.

The help it prints

steghide version 0.5.1

the first argument must be one of the following:
 embed, --embed          embed data
 extract, --extract      extract data
 info, --info            display information about a cover- or stego-file
   info <filename>       display information about <filename>
 encinfo, --encinfo      display a list of supported encryption algorithms
 version, --version      display version information
 license, --license      display steghide's license
 help, --help            display this usage information

embedding options:
 -ef, --embedfile        select file to be embedded
   -ef <filename>        embed the file <filename>
 -cf, --coverfile        select cover-file
   -cf <filename>        embed into the file <filename>
 -p, --passphrase        specify passphrase
   -p <passphrase>       use <passphrase> to embed data
 -sf, --stegofile        select stego file
   -sf <filename>        write result to <filename> instead of cover-file
 -e, --encryption        select encryption parameters
   -e <a>[<m>]|<m>[<a>]  specify an encryption algorithm and/or mode
   -e none               do not encrypt data before embedding
 -z, --compress          compress data before embedding (default)
   -z <l>                 using level <l> (1 best speed...9 best compression)
 -Z, --dontcompress      do not compress data before embedding
 -K, --nochecksum        do not embed crc32 checksum of embedded data
 -N, --dontembedname     do not embed the name of the original file
 -f, --force             overwrite existing files
 -q, --quiet             suppress information messages
 -v, --verbose           display detailed information

extracting options:
 -sf, --stegofile        select stego file
   -sf <filename>        extract data from <filename>
 -p, --passphrase        specify passphrase
   -p <passphrase>       use <passphrase> to extract data
 -xf, --extractfile      select file name for extracted data
   -xf <filename>        write the extracted data to <filename>
 -f, --force             overwrite existing files
 -q, --quiet             suppress information messages
 -v, --verbose           display detailed information

options for the info command:
 -p, --passphrase        specify passphrase
   -p <passphrase>       use <passphrase> to get info about embedded data

To embed emb.txt in cvr.jpg: steghide embed -cf cvr.jpg -ef emb.txt
To extract embedded data from stg.jpg: steghide extract -sf stg.jpg

Examples

# Hide a file inside an image
steghide embed -cf photo.jpg -ef secret.txt

# Extract hidden data from a file (prompts for the passphrase)
steghide extract -sf photo.jpg

# Show info about a carrier — including whether it holds embedded data
steghide info photo.jpg

# Embed without a passphrase (empty), scriptable
steghide embed -cf photo.jpg -ef secret.txt -p ""

When you suspect a file hides something but don’t have the passphrase, steghide info confirms whether there’s an embedded payload at all — a common first step in a forensics or CTF challenge.