Challenges

Capture the flag, defensively

Puzzles built on sandboxed artifacts and fictional systems. Every solution ends in an explanation you could hand to an engineering team.

Challenges never target real-world systems. Do not apply these techniques without explicit authorization.

Solved

3/12

Points earned

250

Categories

7

Beginner

WebBeginner

Cookie Crumbs

Inspect a demo session cookie and explain why it is not tamper-proof.

50 pts Solved
CryptoBeginner

Base of Operations

Decode layered encodings in a sample artifact.

50 pts Solved
ForensicsBeginner

Metadata Trail

Recover a workflow timeline from demo file metadata.

75 ptsUnsolved
OSINTBeginner

Public Footprint

Map a fictional company's public surface from provided documents.

75 ptsUnsolved

Intermediate

LinuxIntermediate

Permission Denied

Explain a misconfigured permission set in a sandbox filesystem.

150 pts Solved
WebIntermediate

Header Games

Diagnose a broken CSP in an isolated demo app.

150 ptsUnsolved
NetworkingIntermediate

Packet Puzzle

Reconstruct a session from a supplied sample capture.

175 ptsUnsolved
CryptoIntermediate

Nonce Sense

Explain why nonce reuse breaks a demo cipher mode.

200 ptsUnsolved

Advanced

Secure CodingAdvanced

Review Board

Find and fix three authorization flaws in a provided snippet.

300 ptsUnsolved
ForensicsAdvanced

Chain of Custody

Build a defensible incident timeline from demo evidence.

325 ptsUnsolved
NetworkingAdvanced

Segmentation Fault Line

Design segmentation for a sample flat network.

350 ptsUnsolved
Secure CodingAdvanced

Zero Trust Blueprint

Propose a zero-trust redesign for a demo architecture.

400 ptsUnsolved