Cybersecurity CTF challenges
Choose a domain and difficulty, inspect the evidence, and verify each conclusion in a safe environment.
ProgrammingLevel 3Programming - Packet Log Analysis
capture.txt is generated from the FLAG injected at startup. Select flow=exfil payload_hex and XOR-decrypt with 0x5A to…
ProgrammingLevel 3Programming - Multithreaded Result Reassembly
worker-results.jsonl is generated from the FLAG injected at startup. Base64-decode results, XOR with worker SHA-1, and…
ProgrammingLevel 3Programming - Memory Dump Analysis
memory.img is generated from the FLAG injected at startup. Extract the ALLOC:0x4040 little-endian region and…
ProgrammingLevel 3Programming - Known-Plaintext Attack
known.txt and ciphertext.b64 are generated from the FLAG injected at startup. Derive the repeating XOR keystream from…
ProgrammingLevel 3Programming - Custom Protocol Parsing
protocol.bin is generated from the FLAG injected at startup. Walk length-prefixed KINO frames and XOR-decrypt type=3…
ProgrammingLevel 3Programming - Image Steganography
image.pgm is generated from the FLAG injected at startup. Read pixel LSBs in 8-bit groups until NUL to recover the flag.
ForensicsLevel 3Find Suspicious Network Connections in Memory
Analyze the network-connection record `netstat_dump.txt` to identify the suspicious C&C connection. The single…
ForensicsLevel 3Recover Executed Commands from Memory
Analyze the memory-string record `memdump.txt` to recover the executed command history. Decode the Base64 strings and…
ForensicsLevel 3Recover Deleted SQLite Records
Recover the deleted record from the SQLite database `app.db` to obtain the flag. Deleted rows persist in the freelist,…
ForensicsLevel 3Decompress Multi-Layer Archive
Decompress a file that has been compressed multiple times with different formats (zip, tar, gzip, bzip2). Learn to…
ForensicsLevel 3Decrypt Encrypted Disk
`secret_disk.img` is a genuine LUKS2 container. Brute-force `wordlist.txt` to find the weak passphrase, then decrypt…
General SkillsLevel 3Regex Expert - Data Validation
/app/data.txt contains various data formats. Extract lines that satisfy ALL conditions: 1. Contains email format…
ForensicsLevel 3Data Hidden in Audio File
`hidden.wav` hides a message encoded with on-off keying (OOK). Turn the tone on/off slots into bits and decode them to…
General SkillsLevel 3Advanced Automation - Directory Monitor
`/challenge/logs/` holds a large set of access logs. Aggregate status-404 requests per source IP and identify the…
General SkillsLevel 4AWS CLI - S3 Bucket Investigation
Analyze the S3 configuration audit under `/challenge/s3_audit/`. Inspect each bucket's `*_acl.json`, `*_policy.json`,…
ForensicsLevel 4Extract Secret Key from Android App
Extract a safe ZIP-formatted APK fixture and analyze the API secret recorded in its Android resources. No real device…
General SkillsLevel 4Ansible Automation - Server Configuration Management
Analyze a generated vault export without running Ansible or touching a server. Recover the encoded payload recorded…
General SkillsLevel 4CI/CD Security - GitHub Actions Vulnerability
Investigate the GitHub Actions workflows under `/challenge/repo/.github/workflows/` and the run logs under…
ForensicsLevel 4Detect Unauthorized Access in CloudTrail Logs
Analyze AWS CloudTrail logs to detect unauthorized IAM access and data exfiltration. Learn cloud forensics. Provided…
ForensicsLevel 4Extract Secrets from Docker Image Layers
The startup-generated `image/` directory is a `docker save`-style image layer layout. Analyze its `layer.tar` files…
General SkillsLevel 4Infrastructure as Code - Terraform Security
Analyze a generated tfstate artifact without initializing a Terraform provider. Recover the flag from the audit_only…
General SkillsLevel 4Kubernetes Basics - Cluster Investigation
Investigate a Pod snapshot artifact without connecting to a Kubernetes cluster. Recover the encoded value in the…
LinuxLevel 4Linux-Kernel Module. Gaining Root via a Vulnerable Driver
This challenge analyzes a vulnerable kernel module with a /proc interface as a safe user-space simulation. Find the…
LinuxLevel 4Linux-Buffer Overflow. Exploiting a gets() Vulnerability
A vulnerable SUID C binary with protections disabled is provided. Exploit its buffer overflow to redirect control flow…