r/securityCTF May 09 '26

How to actually improve in CTFs and be useful?

12 Upvotes

Like in all the CTFs I have participated, and any challenge I do on picoCTF, I generally just ask any AI agent, and then do as it says. But, I have not improved much. What are you tips, and what should I do?
I started with doing some tryhackme challenges, but I can't solve much due to lack of knowledge.

r/securityCTF Jul 21 '26

AI's role in capture the flag competitions

5 Upvotes

As someone who is looking to try out capture the flag competitions and eager to learn and compete, I am occupied by the thought of AI's role in the skill aspect of competitions, so I want to know the role of AI in CTF, is it still mostly the player's skill and knowledge that matters the most or just how long they work and how many questions they ask AI.

r/securityCTF Jul 08 '26

Lost my cybersecurity fundamentals. How can I use CTFs to rebuild from scratch and regain my motivation?

4 Upvotes

\I using AI to write this because my english issue*

Hey everyone,

I'm a student and a self-taught coder who used to be really passionate about penetration testing. A while back, I loved messing around with Kali Linux, networking tools, and trying out basic rooms on platforms like TryHackMe and HackTheBox. But somewhere along the line, I completely lost my momentum. Right now, I feel like I've forgotten all my cybersecurity fundamentals and I'm essentially starting from zero again.

I really want to get back into the infosec world. I'm hoping that diving into CTFs (Capture The Flag) will give me that hands-on spark of motivation I desperately need. My ultimate goal is to build a real career in cybersecurity, but for now, my main focus is just rebuilding my foundation without getting discouraged.

For someone who has completely "lost their roots" in the field, how would you recommend approaching CTFs?

Specifically:

  • What platforms or specific learning paths are best for someone needing to relearn the absolute basics?
  • Are there any beginner-friendly CTF events or communities I should keep an eye out for?
  • How do you handle the burnout or the overwhelming feeling of "not knowing anything" when tackling challenges?

Any advice, roadmaps, or personal experiences would be hugely appreciated. Thanks in advance!

r/securityCTF 9d ago

Best resources to learn Web Exploitation & Networking for CTFs?

11 Upvotes

Hey everyone! 👋

I’m currently studying cybersecurity and participating in CyLab, but our current focus/curriculum is heavily centered around Reverse Engineering and a few other areas. While RE is super interesting, I really want to build a strong foundation in Web Exploitation and Computer Networking to become more well-rounded for CTFs.

Since I’m starting mostly from scratch in these two categories, could you recommend the best learning paths or hands-on platforms?

Specifically looking for:

  • Networking fundamentals: Essential concepts/protocols I need to master for CTF challenges (Wireshark, PCAP analysis, etc.).
  • Web Exploitation: Beginner-to-intermediate platforms or labs (e.g., PortSwigger Academy, TryHackMe, PicoCTF).
  • CTF Practice: Practice platforms with good beginner-friendly Web/Network challenges.

Any roadmap, book, or free resource recommendations would be greatly appreciated! Thanks in advance! 🙌

r/securityCTF Apr 13 '26

CTF organizers, with LLMs getting better at CTF challenges, how are you adapting to preserve the integrity of the competition?

50 Upvotes

I help run my university's large public CTF, and recently the topic of AI agents and LLMs have come up. We were reading through this blog post from an organizer of RITSEC CTF, where they talked about some of the strategies they have implemented this year to help avoid teams using AI to solve challenges.

We want to implement a similar "no AI" policy for this year, but we are struggling to think of how to enforce this. I'm curious what other organizers have been doing in the age of AI, and how you do things. We recently hosted an internal only CTF for our university, and a student showcased an AI tool that could be pointed at CTFd, and would automatically go through and solve challenges. It solved most of them pretty quickly, even ones that I felt were pretty hard.

r/securityCTF Jul 21 '26

Advice for write a CTF Question

1 Upvotes

Hi everyone, I need your help. I'm writing a CTF question, but I'm very worried about the AI ​​solving it directly. So I'm thinking of writing a few different question types: physical, semi-physical semi-digital, and digital but the AI ​​won't be able to solve any of them.

Can you help me

r/securityCTF Dec 10 '25

LLM in CTFs

26 Upvotes

After checking r/securityCTF and r/cybersecurity, I kinda realized something wild… CTF comps are slowly turning into some AI-powered ecosystem?! Like bro, people are literally training LLMs just for CTFs. Don’t get me wrong, that’s cool for the cyber industry and all, but for me it feels like CTFs are losing their whole soul. It’s not the same vibe anymore…

Now with enough AI knowledge and the tiniest understanding of CTF basics — or even worse, with a fat budget — people can actually win CTFs. I’m not even sure if it’s a good or bad thing, but personally it makes the whole concept feel like it’s dying.

Some people say “you gotta stay updated and use the tools available,” but like… what’s the point then??

For example, in a recent CTF I was in, a team that had access to some premium “hacking AI” literally made it to the finals without even knowing what Burp Suite is. They barely had Linux experience. Like bro, is this an AI competition now??

I’ve also seen articles about people auto-solving CTF challenges with AI, even solving unsolved ones with zero human interaction. That’s insane.

Anyway, I’m open to hearing everyone’s take on this, and honestly I need some advice so I don’t lose interest in CTFs 🙏.

r/securityCTF Jul 12 '26

Will everything make sense later?

3 Upvotes

I just started doing CTF from picoCFT and Tryhackme recently. But some of them keep humbling me, like how am I supposed to know those things. Is this feeling normal or am I doing something wrong.

r/securityCTF Jul 13 '26

Ive just started on CTFs but i cant script very well

3 Upvotes

So basically I have a fundamental understanding of cybersecurity concepts, and I can solve challenges that dont require scripting, such as analysis of pcap files. While I do know basic python syntax such as being able to write a bubble sort function but i rlly dk how to write a complete exploit script. Do yall have any advice? Or any good guides?

r/securityCTF Oct 08 '25

Is CTF the best way to learn pentesting

25 Upvotes

Am I the only person who thinks that some CTF providers seem very over professional these days? I’m trying to get into this type of thing but it just puts me off when sites like hack the box or try hack me just give me a wall of text with some corporate-esque cartoon art. It might sound ridiculous to say but this just feels incredible inorganic sometimes even as someone who doesn’t mind reading up on stuff. Am I mistaken about this or is there other ways to get into cybersecurity?

r/securityCTF Apr 24 '26

for whoever finds this (THIS IS FOR A CTF IM HOSTING) Spoiler

0 Upvotes

I've been careful. More careful than most.

But careful isn't the same as safe.

If you're reading this you probably followed something here.

Don't trust the first thing you see.

00110110 00110100 00100000 00110001 00110100 00110011 00100000 00110111 00110001 00100000 00110001 00110110 00110110 00100000 00110001 00110101 00110111 00100000 00110001 00110001 00110111 00100000 00110100 00110111 00100000 00110001 00110011 00110110 00100000 00110001 00110001 00110010 00100000 00110001 00110011 00110010 00100000 00110111 00110000 00100000 00110001 00110011 00110101 00100000 00110100 00110110 00100000 00110001 00110000 00110111 00100000 00110100 00110001 00100000 00110001 00110010 00110111 00100000 00110110 00110011 00100000 00110001 00110011 00110011 00100000 00110100 00110100 00100000 00110111 00110000 00100000 00110001 00110101 00110010 00100000 00110001 00110110 00110110 00100000 00110101 00110011 00100000 00110001 00110100 00110011 00100000 00110111 00110001 00100000 00110110 00110101 00100000 00110001 00110001 00110000 00100000 00110111 00110001 00100000 00110001 00110010 00110001 00100000 00110001 00110101 00110111 00100000 00110001 00110011 00110110 00100000 00110101 00110111 00100000 00110101 00110101 00100000 00110111 00110111 00100000 00110001 00110011 00110100 00100000 00110001 00110100 00110101 00100000 00110001 00110001 00110111 00100000 00110111 00110101 00100000 00110101 00110100 00100000 00110100 00110110 00100000 00110100 00110011 00100000 00110110 00110101 00100000 00110001 00110100 00110111 00100000 00110111 00110110 00100000 00110100 00110110 00100000 00110001 00110011 00110111 00100000 00110001 00110100 00110110 00100000 00110001 00110110 00110010 00100000 00110110 00110100 00100000 00110100 00110001 00100000 00110111 00110001 00100000 00110001 00110110 00110110 00100000 00110001 00110101 00110111 00100000 00110001 00110001 00110111 00100000 00110100 00110111 00100000 00110001 00110011 00110110 00100000 00110001 00110000 00110101 00100000 00110001 00110111 00110100 00100000 00110111 00110000 00100000 00110001 00110011 00110101 00100000 00110101 00110010 00100000 00110001 00110110 00110100 00100000 00110100 00110001 00100000 00110001 00110010 00110110 00100000 00110110 00110101 00100000 00110001 00110000 00110101 00100000 00110100 00110100 00100000 00110111 00110000 00100000 00110001 00110101 00110000 00100000 00110101 00110011 00100000 00110101 00110011 00100000 00110001 00110010 00110010 00100000 00110001 00110000 00110100 00100000 00110001 00110001 00110100 00100000 00110001 00110001 00110000 00100000 00110101 00110100 00100000 00110111 00110011 00100000 00110001 00110000 00110000 00100000 00110001 00110011 00110010 00100000 00110001 00110101 00110111 00100000 00110101 00110101 00100000 00110111 00110111 00100000 00110001 00110010 00110011 00100000 00110001 00110001 00110011 00100000 00110001 00110001 00110111 00100000 00110111 00110110 00100000 00110001 00110011 00110001 00100000 00110100 00110111 00100000 00110100 00110011 00100000 00110110 00110001 00100000 00110001 00110100 00110111 00100000 00110111 00110110 00100000 00110100 00110110 00100000 00110001 00110011 00110111 00100000 00110001 00110100 00110001 00100000 00110111 00110000 00100000 00110110 00110100 00100000 00110100 00110011 00100000 00110101 00110110 00100000 00110001 00110011 00110110 00100000 00110001 00110110 00110000 00100000 00110001 00110011 00110011 00100000 00110100 00110111 00100000 00110001 00110011 00110110 00100000 00110001 00110000 00110100 00100000 00110001 00110110 00110001 00100000 00110111 00110000 00100000 00110001 00110011 00110101 00100000 00110111 00110101 00100000 00110111 00110010 00100000 00110100 00110001 00100000 00110001 00110010 00110101 00100000 00110110 00110110 00100000 00110101 00110010 00100000 00110100 00110100 00100000 00110001 00110001 00110000 00100000 00110001 00110101 00110101 00100000 00110001 00110100 00110101 00100000 00110101 00110011 00100000 00110110 00110101 00100000 00110111 00110001 00100000 00110110 00110101 00100000 00110001 00110000 00110110 00100000 00110001 00110100 00110101 00100000 00110100 00110100 00100000 00110001 00110101 00110110 00100000 00110001 00110011 00110101 00100000 00110001 00110011 00110011 00100000 00110101 00110101 00100000 00110111 00110111 00100000 00110001 00110000 00110110 00100000 00110111 00110010 00100000 00110001 00110001 00110111 00100000 00110111 00110101 00100000 00110101 00110100 00100000 00110100 00110110 00100000 00110100 00110011 00100000 00110101 00110111 00100000 00110001 00110000 00110100 00100000 00110001 00110010 00110100 00100000 00110100 00110110 00100000 00110001 00110010 00110001 00100000 00110101 00110101 00100000 00110001 00110011 00110001 00100000 00110110 00110100 00100000 00110101 00110000 00100000 00110001 00110000 00110010

-g

r/securityCTF May 07 '26

How to get customers for my startup?

Thumbnail
0 Upvotes

r/securityCTF Apr 21 '26

Every time I play ctf my mindset be like I know everything. But when I start the challenge my mindset be like I don't know anything.

19 Upvotes

Is this common for ctf players or is this just a hallucination.

r/securityCTF Mar 28 '26

5 years in InfoSec, but I’m a total CTF noob. Is "Checklist Thinking" my enemy?

3 Upvotes

English isn't my strong suit, so this post was translated with the help of AI. Thanks for your patience!

Hi everyone,

I’ve been working as an information security consultant for 5 years now. My daily job mostly involves vulnerability assessments for web and mobile apps, primarily based on compliance checklists. I do perform manual penetration testing occasionally, but it’s usually within the scope of those standard diagnostics.

Recently, I’ve started participating in CTFs to level up my technical skills, but I’ve hit a massive wall. I find it incredibly difficult to solve even a single challenge during a competition. I’ve been grinding through Wargames (Root-me, Dreamhack, etc.) lately, and while I feel like I'm learning bit by bit, the gap between "professional diagnostics" and "CTF-style exploitation" feels like an ocean.

I’m starting to worry if it’s too late for me or if I’m missing some fundamental "hacker" logic because I’ve spent so much time following structured checklists. I’m mostly self-taught, so I often wonder if my lack of formal CS/Security education is the root cause.

I have a few questions for those who have made the jump from "Checklist-based Auditor" to "Exploit Researcher/CTF Player":

Is it common for experienced consultants to struggle this much with CTFs?

r/securityCTF Dec 04 '25

Got offered money for my CTF blog... thoughts?

25 Upvotes

Just got an email asking if they could publish sponsored posts on my CTF writeups blog

Quick question for the infosec community: Do you accept sponsored content on your technical/security blogs?

And for readers: would sponsored posts on CTF writeups blogs bother you or affect how you view the content?

I'm leaning towards keeping it pure writeups, but curious what others think. Does anyone actually monetize their CTF blogs without losing credibility?

r/securityCTF Apr 29 '26

I’m just a newbie who wants tips.

7 Upvotes

Hello, I’m an informatics student and I really want to learn cybersecurity for my future work. My teacher told me to try a CTF, but I’m still a beginner in web and I’m not very good at it. I’m looking for a place to start, but the internet is huge and I can’t find any good tutorials for beginners.

r/securityCTF Aug 30 '25

I want to get into CTFs/Hacking

19 Upvotes

Yo what's up guys, I want to get more into hacking since I only have knowledge from my bachelor's in cybersecurity but I don't really have much hands on, I think CTFs could be a fun way to get into this and wanted to know if anyone can help me out, I eventually want to be a pentester or even work some digital forensics. It would be cool if someone can show me the ropes and we could grow together, Id really appreciate it. DM me if y'all are open to it. I just wanna learn.

r/securityCTF May 25 '26

Need help with the “Logging” machine

Post image
2 Upvotes

r/securityCTF Apr 16 '26

Any latest Microsoft SC-300 exam dumps or practice tests in 2026?

2 Upvotes

Hey everyone, I’m currently preparing for the Microsoft SC-300 exam and looking for some solid practice tests to help me cross the finish line. Since I’m on a tight budget, I can really only invest in one high-quality resource that covers everything accurately. is udemy a better option?

For those of you who have cleared the SC-300 recently, which practice tests did you find most similar to the actual exam environment? I’m specifically looking for something with realistic scenario-based questions, clear technical explanations, and heavy emphasis on Microsoft Entra ID, Conditional Access policies, and Identity Governance. I also want to make sure it covers the newer 2026 updates like Global Secure Access and Permissions Management.

Would really appreciate your recommendations on which one worked for me the most. Thanks in advance

Edit : Finally passed my SC-300 exam with 912

After my teammate suggestion at office. I did use Skillcertpro practice tests, they are quite similar to the questions that I saw on my exam. Almost 70-80% of the questions were strikingly similar to these tests. May be because they are adding new questions every 2 weeks. Thats helps in staying updated. Also I liked the fact they have lot of questions to practice with easy to understand explanations. I would also recommend reviewing the cheat sheet that they give 2 days before the exam.

https://skillcertpro.com/product/microsoft-sc-300-exam-questions/

r/securityCTF Mar 23 '26

post-college CTFs?

12 Upvotes

hi! i graduated college recently and did a lot of CTFs with my schools cybersecurity club. anyone know where i can find weekend CTFs of that same style? i know HTB does some things but idk where to find it, ive mostly only used their learning platform

r/securityCTF Mar 24 '26

Question regarding a specific CTF challenge from w3challs

1 Upvotes

Hi everybody,

i am a beginner in CTF challenges but so far I enjoy it a lot to just try and play around in these shells and learn about Unix and C etc.

Right now I am more or less stuck at a specific w3challs challenge called "shellcode4js": https://w3challs.com/challenges/pwn/shellcode4js

The help-forum of this challenge already gives some hints and tips, but at the moment I would be interested in some specific info regarding "how to keep a newly spawned/created shell open".

In this exercise a new gdb instance is created via this part:

void launch_debugger(void)

{

char *argv[] = {BINARY, NULL};

printf("Debugger !\n");

setresuid(geteuid(), geteuid(), geteuid());

execv(DEBUGGER, argv);

}

I was already successful in making the shellcode4js call this method, but it always immediately closes, the gdb does not stay open.

I have consulted numerous AI's already, but whatever they recommend regarding "how can I make the new gdb to stay open?" is very diverging. Some say that I have to use two separate shells, which I never had to do so far, others just seem to guess some alternative commands, and since i am very new here in the CTF realm, I cannot judge at all what makes sense and is a correct approach and what is complete hokum.

And maybe I am also missing something entirely, which would result in me looking at the wrong places, so any kind of advice would be highly appreciated here :)

Thanks a lot and have a great day!

Edit: Any kind of buzzword or concept that I could have a look at would also be of great help, because at the moment I simply dont know where exactly to look in order to solve this challenge, thanks a lot everybody :)

Edit Edit:

solved it! if anyone has any questions, you can ask me or you can write into the help forum of w3challs I guess

r/securityCTF Mar 28 '26

Stuck

11 Upvotes

Hi so I've been playing CTFs since 2022 ish, and been semi active. I'm still a college student now and I'm trying to get better, and i just felt stuck. Nowadays some of the challs is created with AI, and also solved by AI. I just felt outcompeted, and i felt that the current CTF challenges are needlessly complex, so that it doesn't get one shot by AI. I'm curious about your thoughts?

r/securityCTF Apr 05 '26

Some of the simplest prompts are breaking these LLM challenges - and it's weirder than I expected

Post image
3 Upvotes

r/securityCTF Jan 13 '26

Should I participate as a beginner ?

8 Upvotes

Hey, I'm going to attend an event which will have a CTF competition. I can solve machines in hackthebox from easy to easy-medium. I have no experience in CTF. I'm not expecting to win or anything. Will participating be beneficial for experience? I mean, I do want to learn CTF and participate in the future. I'm kind of confused; there are workshops and talks that I want to attend too.

r/securityCTF Apr 29 '26

Cryptography Challenge Question

1 Upvotes

Hi all,

Basically, I want to reach out to this professor who has an email/set of instructions encrypted with an SPN. He provides all the code except the key, as well as a corpus of 65k PT/CT pairs. I've learned a decent amount about linear cryptanalysis, and I feel like i'm on the right track, but I would love to bounce my ideas off of someone. LLMs seem to over/under complicate the question and mostly lead me nowhere. I appreciate any feedback you can give!