Skip to content
PURPLEDUEL

What is a CTF and how to get started

Updated · 2 min read

A CTF (Capture The Flag) is a cybersecurity competition where you solve challenges to find a secret string, the flag, and earn points. It is the most fun and entirely legal way to practise: the targets are built to be attacked, and every challenge teaches a real technique.

The main formats

Challenge categories

A worked example: your first challenge

Imagine a 10-point challenge: "The flag is hidden somewhere in your working folder." With the Linux shell, the foundation of nearly every CTF, you could go about it like this:

$ ls
note.txt  documents
$ ls -a
.  ..  .hidden  note.txt  documents
$ cat .hidden
CTF{this_is_an_example}

The trick was a file whose name starts with a dot: plain ls does not list it, ls -a does. Once you find the flag you submit it to the platform, which checks it and awards the points. The format changes from contest to contest (CTF{...}, flag{...}, the name of the event), and the rules always say which one.

How to start, step by step

  1. Learn the Linux shell. ls, cd, cat, grep, find and pipes are the toolkit you will use in nearly every challenge.
  2. Study encodings and web basics: what an HTTP request is, what a cookie is, and why Base64 is not encryption.
  3. Pick a beginner platform: picoCTF, OverTheWire (wargames such as "Bandit") and TryHackMe offer guided paths from level zero.
  4. Read write-ups of the challenges you cannot solve: it is the most effective study method, and then try again on your own.
  5. Join a team and a real contest. The CTFtime website lists upcoming competitions.

From attack to defence: why CTFs help defenders

Someone who knows how a forgotten file is found, how a chatty header gives things away or how a badly protected secret is decoded also knows where to look for their own mistakes. Every solved challenge is a lesson about what not to leave lying around: hidden files holding secrets, editable cookies, talkative error messages, factory-default passwords. Attack-defence contests and labs with a final write-up turn that knowledge into defensive habits.

Golden rules: only play on the targets the contest provides, follow its rules and do not share flags during the competition. Using the same tools on systems that are not yours is illegal.

Keep reading