Capture the Flag
Also known as:CTF
Capture the Flag: Competition format in which participants solve security challenges to recover hidden strings. CTFs are the most widespread training format in offensive securityOffensive SecurityAuthorized testing of systems using methods employed by real-world attackers..
How it works and where it fits
Each challenge contains a flag in a fixed format, submitted as proof of solution; points scale with difficulty. In the common jeopardy format, challenges are grouped into categories — web, crypto, reversing, pwn, forensics, OSINT, and increasingly OT and AI. In the attack–defense format, teams simultaneously operate their own vulnerable services, which they must defend while exploiting the opponents’.
Practical security relevance
The training value lies less in the individual challenges than in the method: reconnaissance before attacking, forming and discarding hypotheses, recognising dead ends, and budgeting time. At the same time there are clear differences from real security testing — no rules of engagement, no customer systems, no reporting obligations, and no assessment of real business risk. For organisations, CTFs are therefore primarily an instrument for skills development and talent acquisition.
Related concepts
- Offensive SecurityOffensive SecurityAuthorized testing of systems using methods employed by real-world attackers.: Authorized testing of systems using methods employed by real-world attackers.
- Penetration TestingPenetration TestingAuthorized, methodical testing of a system for exploitable weaknesses, to find them before real attackers do.: Authorized, methodical testing of a system for exploitable weaknesses, to find them before real attackers do.
- Security AwarenessSecurity AwarenessThe knowledge and behavior that help people recognize and reduce cyber risks.: The knowledge and behavior that help people recognize and reduce cyber risks.
- Binary ExploitationBinary ExploitationExploitation of memory or logic errors in compiled applications.: Exploitation of memory or logic errors in compiled applications.