Dear Sir, Please find in attachment my analysis and my answers to the Network Forensics Puzzle Contest. This archives contains: analysis.txt : detailled analysis oft-tsk.lua: OFT protocol lua dissector recipe.docx: docx file extracted from evidence.pcap recipe.docx.md5: md5sum of recipe.docx file. I've mostly used Tshark, an OFT dissector written (in Lua) for the challenge, some bash command: sort,uniq, awk and the tcpflow tool. I've tried to give the maximum details of all the steps i've taken. Regards, Franck GUENICHOT