Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
stego-toolkit — Collection of steganography tools - helps with CTF challenges | Kitploit
Tools/GitHubGitHub/dominicbreuker/stego-toolkit
ForensicsSteganographyCTFLearning & EducationLabs & Practice
GitHubdominicbreuker/stego-toolkit

stego-toolkit

Collection of steganography tools - helps with CTF challenges

View Repository
2.7k340216 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Steganography Toolkit

This project is a Docker image useful for solving Steganography challenges as those you can find at CTF platforms like hackthebox.eu. The image comes pre-installed with many popular tools (see list below) and several screening scripts you can use check simple things (for instance, run check_jpg.sh image.jpg to get a report for a JPG file).

Docker build status

Hack The Box

Usage

First make sure you have Docker installed (how to). Then you can use the shell scripts bin/build.sh and bin/run.sh in this repo to build the image and run the container. You will be dropped into a bash shell inside the container. It will have the data folder mounted, into which you can put the files to analyze.

If you don't use the scripts, follow these steps:

  1. Build image (docker build -t <image_name> .) or pull from Docker hub (docker pull dominicbreuker/stego-toolkit)
  2. Start a container with your files mounted to the folder /data (docker run -it <image_name> -v /local/folder/with/data:/data /bin/bash)
  3. Use CLI tools and screening scripts on your files: e.g., run check_jpg.sh image.jpg to create a quick report, or run brute_jpg.sh image.jpg wordlist.txt to try extracting hidden data with various tools and passwords
  4. If you want to run GUI tools use one of these two ways:
  • Run start_ssh.sh and connect to your container with X11 forwarding
  • Run start_vnc.sh and connect to the container's Desktop through your browser

Check out the following sections for more information:

  • What tools are installed? Go here
  • What scripts can I run to quickly screen files automatically or brute force them? Go here
  • How can I play with different Steganography examples to see if I can break them? Go here
  • How can I run GUI tools inside the container? go here

Demo

Start with docker run -it --rm -v $(pwd)/data:/data dominicbreuker/stego-toolkit /bin/bash. You will be dropped into a container shell in work dir /data. Your host folder $(pwd)/data will be mounted and the images inside will be accessible.

animated demo gif

Tools

Many different Linux and Windows tools are installed. Windows tools are supported with Wine. Some tools can be used on the command line while others require GUI support!

Command line interface tools

These tools can be used on the command line. All you have to do is start a container and mount the steganography files you want to check.

General screening tools

Tools to run in the beginning. Allow you to get a broad idea of what you are dealing with.

ToolDescriptionHow to use
fileCheck out what kind of file you havefile stego.jpg
exiftoolCheck out metadata of media filesexiftool stego.jpg
binwalkCheck out if other files are embedded/appendedbinwalk stego.jpg
stringsCheck out if there are interesting readable characters in the filestrings stego.jpg
foremostCarve out embedded/appended filesforemost stego.jpg
pngcheckGet details on a PNG file (or find out is is actually something else)pngcheck stego.png
identifyGraphicMagick tool to check what kind of image a file is. Checks also if image is corrupted.identify -verbose stego.jpg
ffmpegffmpeg can be used to check integrity of audio files and let it report infos and errorsffmpeg -v info -i stego.mp3 -f null - to recode the file and throw away the result

Tools detecting steganography

Tools designed to detect steganography in files. Mostly perform statistical tests. They will reveal hidden messages only in simple cases. However, they may provide hints what to look for if they find interesting irregularities.

ToolFile typesDescriptionHow to use
stegoVeritasImages (JPG, PNG, GIF, TIFF, BMP)A wide variety of simple and advanced checks. Check out stegoveritas.py -h. Checks metadata, creates many transformed images and saves them to a directory, Brute forces LSB, ...stegoveritas.py stego.jpg to run all checks
zstegImages (PNG, BMP)Detects various LSB stego, also openstego and the Camouflage toolzsteg -a stego.jpg to run all checks
stegdetectImages (JPG)Performs statistical tests to find if a stego tool was used (jsteg, outguess, jphide, ...). Check out man stegdetect for details.stegdetect stego.jpg
stegbreakImages (JPG)Brute force cracker for JPG images. Claims it can crack outguess, jphide and jsteg.stegbreak -t o -f wordlist.txt stego.jpg, use -t o for outguess, -t p for jphide or -t j for jsteg

Tools actually doing steganography

Tools you can use to hide messages and reveal them afterwards. Some encrypt the messages before hiding them. If they do, they require a password. If you have a hint what kind of tool was used or what password might be right, try these tools. Some tools are supported by the brute force scripts available in this Docker image.

Download Tool