Digital Forensics
steghide
steghide does steganography: it embeds a file inside an image or audio file so
that the carrier looks and plays completely normally, with the hidden data
protected by a passphrase. In forensics and CTFs it cuts both ways — you use it to
recover data someone concealed in an innocent-looking JPEG, and to demonstrate how
easily information can be smuggled past inspection. It embeds into JPEG, BMP, WAV,
and AU files and can compress and encrypt the payload on the way in.
Official-repo package; Security → Digital Forensics → steghide.
The help it prints
steghide version 0.5.1
the first argument must be one of the following:
embed, --embed embed data
extract, --extract extract data
info, --info display information about a cover- or stego-file
info <filename> display information about <filename>
encinfo, --encinfo display a list of supported encryption algorithms
version, --version display version information
license, --license display steghide's license
help, --help display this usage information
embedding options:
-ef, --embedfile select file to be embedded
-ef <filename> embed the file <filename>
-cf, --coverfile select cover-file
-cf <filename> embed into the file <filename>
-p, --passphrase specify passphrase
-p <passphrase> use <passphrase> to embed data
-sf, --stegofile select stego file
-sf <filename> write result to <filename> instead of cover-file
-e, --encryption select encryption parameters
-e <a>[<m>]|<m>[<a>] specify an encryption algorithm and/or mode
-e none do not encrypt data before embedding
-z, --compress compress data before embedding (default)
-z <l> using level <l> (1 best speed...9 best compression)
-Z, --dontcompress do not compress data before embedding
-K, --nochecksum do not embed crc32 checksum of embedded data
-N, --dontembedname do not embed the name of the original file
-f, --force overwrite existing files
-q, --quiet suppress information messages
-v, --verbose display detailed information
extracting options:
-sf, --stegofile select stego file
-sf <filename> extract data from <filename>
-p, --passphrase specify passphrase
-p <passphrase> use <passphrase> to extract data
-xf, --extractfile select file name for extracted data
-xf <filename> write the extracted data to <filename>
-f, --force overwrite existing files
-q, --quiet suppress information messages
-v, --verbose display detailed information
options for the info command:
-p, --passphrase specify passphrase
-p <passphrase> use <passphrase> to get info about embedded data
To embed emb.txt in cvr.jpg: steghide embed -cf cvr.jpg -ef emb.txt
To extract embedded data from stg.jpg: steghide extract -sf stg.jpg
Examples
# Hide a file inside an image
steghide embed -cf photo.jpg -ef secret.txt
# Extract hidden data from a file (prompts for the passphrase)
steghide extract -sf photo.jpg
# Show info about a carrier — including whether it holds embedded data
steghide info photo.jpg
# Embed without a passphrase (empty), scriptable
steghide embed -cf photo.jpg -ef secret.txt -p ""
When you suspect a file hides something but don’t have the passphrase, steghide info confirms whether there’s an embedded payload at all — a common first step in
a forensics or CTF challenge.