Jump to content

Capture the flag (cybersecurity)

From Wikipedia, the free encyclopedia
A team competing in the CTF competition at DEF CON 17

In computer security, Capture the Flag (CTF) is an exercise in which participants attempt to find text strings, called "flags", hidden in intentionally vulnerable programs, websites, devices, or other systems. CTFs are used for competitive and educational purposes. In the two most common formats, participants either solve stand-alone challenges provided by the organizers (jeopardy-style CTFs) or defend their own systems while attempting to steal flags from other participants (attack-defense CTFs). Mixed competitions combine elements of both formats.[1] Competitions may be held online or in person, may include hardware and physical-security tasks, and may be designed for beginners or experienced participants. The name is derived from the outdoor game of the same name. CTFs are widely used to develop, practice, and assess cybersecurity skills in academic, professional, and recreational settings.[2]

Overview

[edit]

The first widely recognized cybersecurity CTF was held at DEF CON in 1996. Early DEF CON competitions used custom vulnerable services on a shared system and primarily tested offensive security skills; later attack-defense competitions required teams to protect their own services while attacking identical services operated by other teams.[3][4]

The two most common formats are jeopardy and attack-defense.[2] In a jeopardy CTF, teams solve independent challenges worth a fixed or dynamically adjusted number of points. Common categories include cryptography, digital forensics, web exploitation, binary exploitation, and reverse engineering.[2][5] Solving a challenge reveals a flag that is submitted to a scoring system. In an attack-defense CTF, teams are given equivalent vulnerable services and must keep their own services available, patch vulnerabilities, and repeatedly exploit opposing teams to obtain flags.[2] Mixed competitions combine jeopardy challenges with attack-defense targets.

CTFs can cover a broad range of technical skills, including software exploitation, password cracking, network analysis, programming, and incident response. A study of 15,963 published CTF solutions found that challenges emphasized technical topics, particularly cryptography and network security, while human-centered subjects such as social engineering and cybersecurity awareness were comparatively underrepresented.[6]

Educational applications

[edit]
Presenter walks through the solution of a CTF challenge

CTFs are commonly used in cybersecurity education because they combine hands-on exercises with competition and gamification. Reviews of cybersecurity competitions have found that well-designed CTF activities can increase engagement and provide opportunities to practice technical problem-solving, although their educational value depends on factors such as challenge design, learner preparation, guidance, and feedback.[7][8]

Educational CTF platforms target a range of audiences. PicoCTF, organized by Carnegie Mellon CyLab, was created to introduce middle- and high-school students to computer security.[9] Pwn.college, maintained by a team at Arizona State University, provides free challenge-based material and supports parts of the university's cybersecurity curriculum.[10]

CTF-style exercises have also been integrated into university courses.[11][12] One documented example used jeopardy-style CTF assignments in an introductory information-security course at the National University of Singapore.[13]

CTF and related cyber-range exercises are also used by military academies and government training programs. The National Security Agency's NSA Cyber Exercise is a year-round education and training program that culminates in a competition for students from United States service academies and military colleges.[14]

Competitions

[edit]

Many organizers register competitions with the CTFtime platform, which maintains an event calendar, archives challenges and write-ups, and calculates seasonal ratings for teams and events.[15][16]

Community competitions

[edit]
LakeCTF Finals 2026 event @ EPFL

CTFs are organized by security conferences, universities, companies, and independent community teams. Conference-associated events include the DEF CON CTF, HITCON CTF, competitions held at Security BSides events, and SANS Institute NetWars tournaments.[2][17]

The DEF CON CTF is one of the longest-running major CTF competitions. It has been described by media outlets as the "World Series of hacking"[18] and the "Olympics of hacking".[19] Teams generally qualify through a separate qualification event before competing in the in-person finals. In 2026, DEF CON selected the Benevolent Bureau of Birds to organize the competition for a four-year term. The group brings together members of Carnegie Mellon University's Plaid Parliament of Pwning, the University of British Columbia's Maple Bacon, and The Duck, a team associated with the cybersecurity company Theori.[20] Before becoming organizers, the three groups competed together as Maple Mallard Magistrates and won four consecutive DEF CON CTF titles from 2022 through 2025.[21] Plaid Parliament of Pwning had participated in nine winning DEF CON CTF teams overall by 2025, the most in the competition's history.[22]

The New York University Tandon School of Engineering hosts Cybersecurity Awareness Worldwide (CSAW), a student-run cybersecurity event whose competitions include a jeopardy-style CTF. The 2021 qualification round recorded more than 1,200 teams with at least one point.[23][24]

Many community teams are associated with universities and organize their own events. Examples include Carnegie Mellon University's Plaid Parliament of Pwning and the University of California, Santa Barbara team Shellphish, which has organized the International Capture The Flag competition.[25][26]

Some community events are online and open to a broad audience. Examples include the SANS Holiday Hack Challenge, which combines guided cybersecurity exercises with a CTF track, and TryHackMe's beginner-oriented Advent of Cyber challenge series.[27][28]

Government-supported competitions

[edit]

Government-supported competitions include the DARPA Cyber Grand Challenge, in which autonomous systems played a machine-only CTF in 2016, and the ENISA-supported European Cybersecurity Challenge.[29][30]

In 2023, the United States Space Force-sponsored Hack-A-Sat 4 finals used Moonlighter, an operational satellite in low Earth orbit. Space Systems Command described it as the first CTF hacking competition conducted on an operational satellite.[31]

Corporate-supported competitions

[edit]

Corporations and other organizations use CTFs for workforce training, recruitment, and skills evaluation, as well as sponsor public competitions.[32] Google, for example, operates a public online jeopardy competition and related experimental events.[33]

Artificial intelligence and the decline of traditional CTFs

[edit]

The increasing ability of large language model-based systems to solve cybersecurity challenges has prompted debate over the future of capture-the-flag competitions, particularly the jeopardy format. AI agents can analyze challenge files, invoke security tools, generate and test exploits, retrieve flags, and produce written explanations with limited human involvement. In a 2026 study of 41 participants in a live, on-site CTF, competitors delegated increasingly large subtasks to an AI assistant as the event progressed; when four autonomous agents were separately evaluated on the same previously unreleased challenges, the best-performing agent placed second overall and outperformed most participating human teams.[34]

Competitive teams have also developed specialized CTF-solving systems. Squid Proxy Lovers, one of the first to develop an agent, reported that its Squid Agent framework solved 46 of 50 challenges in the CTFTiny benchmark, while remaining less reliable on novel, large, or long-context challenges.[35]

The adoption of these systems has raised questions about what conventional leaderboards measure. Participants may obtain flags or complete solutions without understanding the underlying vulnerability, and differences in access to models, computing resources, or inference budgets may influence results. Researchers studying AI-assisted cybersecurity competitions have proposed measures such as separate autonomy levels, traceable submissions containing agent logs or code, and scoring criteria designed for human & AI collaboration.[36]

Competition organizers have responded through restrictions and disclosure requirements. The rules for the 2026 DEF CON CTF Qualifier prohibited fully or primarily autonomous teams but allowed human competitors to use large language model-based tools when humans remained meaningfully involved in directing the work.[37] Teams classified their AI use as No AI, Low AI, or Human-Led AI, with those classifications displayed on the public scoreboard.[37][38]

Alongside conventional jeopardy challenges, the qualifier included King of the Hill (KoTH) and LiveCTF challenges. These formats repeatedly evaluated submitted programs or strategies instead of awarding points only when a team retrieved a single static flag.[39]

In July 2026, OtterSec, a blockchain security auditing company, announced the Save CTFs Fund, a US$100,000 initiative supporting experiments with competition formats intended to remain meaningful as AI capabilities increase.[40][41] The company argued that conventional jeopardy scoring could increasingly reflect available inference budgets and advocated formats that compare the performance of exploits, defensive patches, bots, or strategies over multiple rounds.[41]

OtterSec described the resulting community discussion as including declarations of the "death of CTFs".[41] The debate more specifically concerns whether traditional human-focused jeopardy scoring remains an effective measure of cybersecurity skill. AI-use disclosures, restrictions on autonomous teams, and continuously evaluated formats indicate that some organizers are adapting CTFs rather than abandoning them.

[edit]
  • In Mr. Robot, a CTF tournament is depicted in the third-season premiere, "eps3.0_power-saver-mode.h". The technical advisers for the series said the scene was based on real-world CTF events and used a challenge adapted from a previous security competition.[42]
  • In The Undeclared War, a CTF is depicted in the opening scene as a recruitment exercise used by GCHQ.[43]
  • Go Go Squid!, a Chinese television series, centers partly on characters training for and competing in fictionalized international cybersecurity competitions.[44]

See also

[edit]

References

[edit]
  1. "What is Capture The Flag?". CTFtime. Retrieved 16 July 2026.
  2. 1 2 3 4 5 European Union Agency for Cybersecurity (10 May 2021). Contemporary Practices and State-of-the-Art in Capture-the-Flag Competitions (PDF) (Report). ENISA. ISBN 978-92-9204-501-2. Retrieved 16 July 2026.
  3. Trickel, Erik; Disperati, Francesco; Gustafson, Eric; Kalantari, Faezeh; Mabey, Mike; Tiwari, Naveen; Safaei, Yeganeh; Doupé, Adam; Vigna, Giovanni (2017). Shell We Play A Game? CTF-as-a-service for Security Education (PDF). 2017 USENIX Workshop on Advances in Security Education (ASE 17). USENIX Association. Retrieved 16 July 2026.
  4. Cowan, Crispin; Arnold, Seth; Beattie, Steve; Wright, Chris; Viega, John (April 2003). Defcon Capture the Flag: Defending vulnerable code from intense attack. Proceedings DARPA Information Survivability Conference and Exposition. Vol. 1. pp. 120–129. doi:10.1109/DISCEX.2003.1194878. ISBN 0-7695-1897-4. S2CID 18161204.
  5. Chung, Kevin; Cohen, Julian (2014). Learning Obstacles in the Capture The Flag Model. 3GSE '14: 2014 USENIX Summit on Gaming, Games, and Gamification in Security Education. USENIX Association. Retrieved 16 July 2026.
  6. Švábenský, Valdemar; Čeleda, Pavel; Vykopal, Jan; Brišáková, Silvia (March 2021). "Cybersecurity knowledge and skills taught in capture the flag challenges". Computers & Security. 102 102154. arXiv:2101.01421. doi:10.1016/j.cose.2020.102154. Retrieved 16 July 2026.
  7. Balon, Tyler; Baggili, Ibrahim (24 February 2023). "Cybercompetitions: A survey of competitions, tools, and systems to support cybersecurity education". Education and Information Technologies. 28 (9): 11759–11791. doi:10.1007/s10639-022-11451-4. ISSN 1573-7608. PMC 9950699. PMID 36855694.
  8. Vykopal, Jan; Švábenský, Valdemar; Chang, Ee-Chien (26 February 2020). Benefits and Pitfalls of Using Capture the Flag Games in University Courses. Proceedings of the 51st ACM Technical Symposium on Computer Science Education. pp. 752–758. arXiv:2004.11556. doi:10.1145/3328778.3366893. ISBN 9781450367936. S2CID 211519195.
  9. "picoCTF aims to close the cybersecurity talent gap". Carnegie Mellon CyLab. Retrieved 16 July 2026.
  10. "pwn.college". pwn.college. Retrieved 16 July 2026.
  11. McDaniel, Lucas; Talvi, Erik; Hay, Brian (January 2016). Capture the Flag as Cyber Security Introduction. 2016 49th Hawaii International Conference on System Sciences. pp. 5479–5486. doi:10.1109/HICSS.2016.677. ISBN 978-0-7695-5670-3. S2CID 35062822.
  12. Leune, Kees; Petrilli, Salvatore J. (27 September 2017). Using Capture-the-Flag to Enhance the Effectiveness of Cybersecurity Education. Proceedings of the 18th Annual Conference on Information Technology Education. Association for Computing Machinery. pp. 47–52. doi:10.1145/3125659.3125686. ISBN 978-1-4503-5100-3. S2CID 46465063.
  13. Vykopal, Jan; Švábenský, Valdemar; Chang, Ee-Chien (26 February 2020). Benefits and Pitfalls of Using Capture the Flag Games in University Courses. Proceedings of the 51st ACM Technical Symposium on Computer Science Education. pp. 752–758. arXiv:2004.11556. doi:10.1145/3328778.3366893. ISBN 9781450367936. S2CID 211519195.
  14. "NSA Cyber Exercise (NCX)". National Security Agency. Retrieved 16 July 2026.
  15. "CTFtime". CTFtime. Retrieved 16 July 2026.
  16. "CTFtime FAQ". CTFtime. Retrieved 16 July 2026.
  17. "SANS Cyber Ranges". SANS Institute. Retrieved 16 July 2026.
  18. Korber, Sabrina (8 November 2013). "Cyberteams duke it out in the World Series of hacking". CNBC. Retrieved 16 July 2026.
  19. Siddiqui, Zeba (17 August 2022). "Hacker tournament brings together world's best in Las Vegas". Reuters. Retrieved 16 July 2026.
  20. "UBC competitive hacking team to organize this year's top-tier cybersecurity competition". University of British Columbia Department of Computer Science. 31 March 2026. Retrieved 16 July 2026.
  21. "UBC wins fourth consecutive time at world-renowned "Capture the Flag" hacking competition". University of British Columbia Department of Computer Science. 29 August 2025. Retrieved 16 July 2026.
  22. "Carnegie Mellon's Hacking Team Wins Fourth Straight, Record Ninth Overall DEF CON Capture-the-Flag Title". Carnegie Mellon University. 11 August 2025. Retrieved 16 July 2026.
  23. "CSAW". New York University. Retrieved 16 July 2026.
  24. "CSAW'22 Cybersecurity Games & Conference". New York University Abu Dhabi. Retrieved 16 July 2026.
  25. "Carnegie Mellon's Hacking Team Wins Fourth Straight, Record Ninth Overall DEF CON Capture the Flag". Carnegie Mellon University. 11 August 2025. Retrieved 16 July 2026.
  26. "iCTF: the International Capture The Flag Competition". University of California, Santa Barbara. Retrieved 16 July 2026.
  27. "Holiday Hack Cybersecurity Challenge 2025". SANS Institute. Retrieved 16 July 2026.
  28. "Advent of Cyber 2025". TryHackMe. Retrieved 16 July 2026.
  29. "Cyber Grand Challenge". Defense Advanced Research Projects Agency. Retrieved 16 July 2026.
  30. "European Cybersecurity Challenge". European Cybersecurity Challenge. Retrieved 16 July 2026.
  31. "Global teams of security researchers compete in first-ever capture-the-flag hacking competition in space" (PDF). Space Systems Command. 14 August 2023. Retrieved 16 July 2026.
  32. Cherinka, Robert (2018). "Using Cyber Competitions to Build a Cyber Security Talent Pipeline and Skilled Workforce". Advances in Intelligent Systems and Computing. Springer. pp. 280–289. doi:10.1007/978-3-030-01177-2_20.
  33. "Google CTF". Google. Retrieved 16 July 2026.
  34. Tang, Tingxuan; Janis, Nicolas; Montague, Kalyn Asher; Eykholt, Kevin; Kirat, Dhilung; Park, Youngja; Jang, Jiyong; Nadkarni, Adwait; Xiao, Yue (2026). "Understanding Human-AI Collaboration in Cybersecurity Competitions". arXiv:2602.20446 [cs.CR].
  35. "Squid Agent – A Multi-Agent CTF Auto Solver". Squid Proxy Lovers. 18 November 2025. Retrieved 16 July 2026.
  36. Xi, Haoran; Shao, Minghao; Milner, Kimberly; Putrevu, Venkata Sai Charan; Rani, Nanda; Udeshi, Meet (2026). "AI In Cybersecurity Education—Scalable Agentic CTF Design Principles and Educational Outcomes". arXiv:2603.21551 [cs.CR].
  37. 1 2 "Birding Rules – DEF CON CTF Quals 2026". Benevolent Bureau of Birds. Retrieved 16 July 2026.
  38. "Scoreboard – DEF CON CTF Quals 2026". Benevolent Bureau of Birds. Retrieved 16 July 2026.
  39. Suehiro (5 June 2026). "DEF CON CTF Qualifier 2026 参加記" [Participation report for the DEF CON CTF Qualifier 2026]. NF Labs Engineering Blog (in Japanese). Retrieved 16 July 2026.
  40. "OtterSec". OtterSec. Retrieved 16 July 2026.
  41. 1 2 3 Debono, Michael (7 July 2026). "Announcing the Save CTFs Fund". OtterSec. Retrieved 16 July 2026.
  42. Kazanciyan, Ryan (30 September 2020). "Mr. Robot Disassembled: eps3.0_power-saver-mode.h". Medium. Retrieved 16 July 2026.
  43. Woodward, Alan (7 July 2022). "'Some staff work behind armoured glass': a cybersecurity expert on The Undeclared War". The Guardian. ISSN 0261-3077. Retrieved 16 July 2026.
  44. "Former child star follows 'destiny'". China Daily. 17 July 2019. Retrieved 16 July 2026.
[edit]
  • CTFtime – an archive and calendar of past, current, and upcoming CTF competitions.