CTF methodology
CTFs (Capture The Flag) are competitions where you solve security challenges to get “flags”. They’re the best way to practice hacking legally and in a structured way: they train the same skills as a real pentest, but in a controlled environment with a guaranteed solution.
CTF types
Section titled “CTF types”Jeopardy independent challenges by category (web, pwn, crypto, forensics, rev, misc) scored per solved challenge; the most common formatAttack-Defense each team defends its services and attacks others' (live)King of the Hill keep control of a machine against othersBoot2root compromise a machine end to end (HTB/OSCP style)General methodology (boot2root machine)
Section titled “General methodology (boot2root machine)”1. ENUMERATION port/service scan (nmap), web, versions -> the most important2. ANALYSIS understand each service; look for vulns/exploits/credentials3. FOOTHOLD initial access (web shell, exploit, credentials) -> user flag4. ESCALATION from user to root/SYSTEM (see linux-privesc/win-privesc) -> root flag5. DOCUMENT notes on everything (for the writeup and to learn, see ctf-writeups)“Enumeration is everything”: most stalls are from not enumerating enough.
Mindset and method
Section titled “Mindset and method”- enumerate EXHAUSTIVELY before jumping to exploit (ports, dirs, params, versions)- one step at a time; note EVERYTHING found (credentials, hints, rabbit holes)- if stuck: re-enumerate, change the angle, review what you dismissed- time-box per challenge in competition; don't obsess over oneAvoiding rabbit holes
Section titled “Avoiding rabbit holes”- a "rabbit hole" is a false lead that burns time -> recognize it and get out- if something requires too many improbable assumptions, it's probably NOT the way- in Jeopardy, difficulty/points guide you; in boot2root, the "intended" path is usually simplerEnum nmap, ffuf/gobuster, nikto, enum4linuxWeb Burp (tool-burp), curlPwn/rev Ghidra, pwntools, gdb (see pwn-reversing)Crypto CyberChef, sage, python (see crypto-*)Forensics binwalk, volatility, wireshark (see dfir-*, crypto-stego)Blue Team / learning
Section titled “Blue Team / learning”- Thorough enumeration is 80% of success; most stalls resolve by re-enumerating.
- Documenting everything during the challenge eases the writeup (How to write writeups) and cements learning.
- Recognize and abandon rabbit holes in time; time-box in competition.
- CTFs train real pentest skills in a legal environment with a guaranteed solution.
Tips and common mistakes
Section titled “Tips and common mistakes”- Set a time cap per challenge and rotate; getting stuck on one (a rabbit hole) is mistake number one.
- Take notes on everything you try: avoids repetition and helps when asking for a hint or collaborating.
- Read the prompt carefully: file names, point values and description almost always hide the clue.
Testing checklist
Section titled “Testing checklist”- Identify the CTF type (Jeopardy/AD/boot2root)
- Exhaustive enumeration (ports, services, web, versions)
- Analyze each service; look for vulns/credentials
- Foothold (user flag) and document the path
- Privilege escalation (root flag)
- Recognize and exit rabbit holes; time-box
- Complete notes → writeup (How to write writeups)