// the find
elder-plinius/ST3GG
All-in-one steganography suite
ST3GG is a Python/browser toolkit that both hides data using 100+ steganography techniques (images, audio, text/Unicode, network protocols, documents, code) and detects it via a companion analysis suite. It's aimed at CTF players, red/blue teams, and forensics folks who want one dependency instead of a dozen format-specific stego scripts.
Genuinely broad format coverage in a single library — PNG/JPEG/WebP/GIF/BMP/TIFF, WAV/AIFF/AU/MIDI, Unicode text tricks, DNS/ICMP/TCP/HTTP covert channels, and document/archive formats, all in one codebase instead of scattered single-purpose tools. Ships in three real forms: a Python library (steg_core.py), an interactive CLI, and a subprocess-friendly stegg-cli with JSON output built specifically for scripting into agent pipelines. F5 mode implements actual JPEG DCT-coefficient matrix encoding, which is a legitimate technique for surviving recompression, not just LSB dressed up. There's a real example-generation and test setup (test_examples.py, test_comprehensive.py) so techniques have runnable round-trip verification rather than just being claimed in the README.
The README's marketing framing (comparison tables, ASCII banners, roadmap emoji) makes it hard to judge engineering rigor from outside — there's no CI badge, no CONTRIBUTING guide, and no visible review process for a tool where subtle bugs in crypto or encoding code matter. Novel-sounding features like SPECTER 'channel hopping' and Ghost Mode noise decoys are homegrown obfuscation, not peer-reviewed steganography — the README lists actual academic techniques (HUGO, WOW, S-UNIWARD) as future roadmap items, so the 'academic-grade' positioning oversells what's implemented today. AGPL-3.0 licensing with a 'contact us for commercial license' clause means any team wanting to fold this into a proprietary DLP or forensics product needs a licensing conversation before they can ship. The README itself embeds hidden zero-width Unicode and HTML-comment payloads as a demo — cute for a steg tool, but a real footgun if anyone copies text out of it into another document without checking for invisible characters first.