What you will learn
- Parse and transform evidence
- Break investigations into testable steps
- Automate repetitive security analysis
Write small programs to transform data, automate investigation, and solve security tasks that do not scale by hand.
47 challenges available.
ProgrammingLevel 1In security work, programming is essential for processing large amounts of data. In this challenge, you'll use Python…
ProgrammingLevel 2Start the stock API on localhost:9102, find the transaction with the largest sell_price - buy_price across all…
ProgrammingLevel 2data.txt contains 100+ Base64 strings. Exactly one decodes to the FLAG injected at startup; decode every line to find…
ProgrammingLevel 2Runtime-generated data.txt is a sales CSV. The notes of the one row with amount >= 10000, status completed, and a SEC-…
ProgrammingLevel 2In runtime-generated JSON data.txt, find the only user whose role is admin, active is true, and email contains…
ProgrammingLevel 2Runtime-generated data.txt is a 1200-line access log. Filter for 192.168.1.100 and find the FLAG among those lines.
ProgrammingLevel 2data.txt holds 100+ base64-encoded strings, one per line. Decode them all and find the flag (the line starting with…
ProgrammingLevel 2data.txt is a sales CSV (transaction_id,date,product_id,amount,status,notes). Find the single transaction with amount…
ProgrammingLevel 2data.txt is JSON containing many users. Find the single user whose role is admin, active is true, and email contains…
ProgrammingLevel 2data.txt is an access log of 1000+ lines. Extract the lines from IP 192.168.1.100 and find the flag (FLAG{...}) among…
ProgrammingLevel 2data.txt holds many sha256 hashes. The flag was split into ordered chunks; each chunk is hashed as…
ProgrammingLevel 2jobs.log is generated from the FLAG injected at startup. Filter successful archive jobs, order parts, reverse values,…
ProgrammingLevel 2vault.json is generated from the FLAG injected at startup. Brute-force the 0000–9999 PIN SHA-256 and XOR-decrypt with…
ProgrammingLevel 2artifact-manifest.json is generated from the FLAG injected at startup. Verify each data SHA-256, XOR-decrypt with…
ProgrammingLevel 2capture.bin is generated from the FLAG injected at startup. Parse KBIN TLV records and XOR-decode type 0x42 with 0x5A…
ProgrammingLevel 2Extract every KINO-four-digits-four-uppercase glyph from data.txt, identify the one occurring once, and submit it to…
ProgrammingLevel 3data.db is a business SQLite database (users / orders / audit_log). The flag hides in the security_note of the single…
ProgrammingLevel 3cipher.txt holds the flag encrypted with a custom cipher (hex). Encryption applies per byte: add (key), xor…
ProgrammingLevel 3secret.zip is a ZIP encrypted with a weak password and contains flag.txt. Use the shipped wordlist.txt and Python's…
ProgrammingLevel 3Use BFS to find the shortest path from S to E in data.txt, then submit the UDLR move sequence to challenge.py. A…
ProgrammingLevel 3evidence.db is generated from the FLAG injected at startup. JOIN users/access_log and Base64-decode the top…
ProgrammingLevel 3site.json is generated from the FLAG injected at startup. Follow ordered link-graph comments and join Base64 fragments…
ProgrammingLevel 3archive.json is generated from the FLAG injected at startup. Find the wordlist password matching password_sha256 and…
ProgrammingLevel 3capture.txt is generated from the FLAG injected at startup. Select flow=exfil payload_hex and XOR-decrypt with 0x5A to…