Skip to content

CTF methodology

CTFs (Capture The Flag) are competitions where you solve security challenges to get “flags”. They’re the best way to practice hacking legally and in a structured way: they train the same skills as a real pentest, but in a controlled environment with a guaranteed solution.

Jeopardy independent challenges by category (web, pwn, crypto, forensics, rev, misc)
scored per solved challenge; the most common format
Attack-Defense each team defends its services and attacks others' (live)
King of the Hill keep control of a machine against others
Boot2root compromise a machine end to end (HTB/OSCP style)
1. ENUMERATION port/service scan (nmap), web, versions -> the most important
2. ANALYSIS understand each service; look for vulns/exploits/credentials
3. FOOTHOLD initial access (web shell, exploit, credentials) -> user flag
4. ESCALATION from user to root/SYSTEM (see linux-privesc/win-privesc) -> root flag
5. DOCUMENT notes on everything (for the writeup and to learn, see ctf-writeups)

“Enumeration is everything”: most stalls are from not enumerating enough.

- enumerate EXHAUSTIVELY before jumping to exploit (ports, dirs, params, versions)
- one step at a time; note EVERYTHING found (credentials, hints, rabbit holes)
- if stuck: re-enumerate, change the angle, review what you dismissed
- time-box per challenge in competition; don't obsess over one
- a "rabbit hole" is a false lead that burns time -> recognize it and get out
- if something requires too many improbable assumptions, it's probably NOT the way
- in Jeopardy, difficulty/points guide you; in boot2root, the "intended" path is usually simpler
Enum nmap, ffuf/gobuster, nikto, enum4linux
Web Burp (tool-burp), curl
Pwn/rev Ghidra, pwntools, gdb (see pwn-reversing)
Crypto CyberChef, sage, python (see crypto-*)
Forensics binwalk, volatility, wireshark (see dfir-*, crypto-stego)
  • Thorough enumeration is 80% of success; most stalls resolve by re-enumerating.
  • Documenting everything during the challenge eases the writeup (How to write writeups) and cements learning.
  • Recognize and abandon rabbit holes in time; time-box in competition.
  • CTFs train real pentest skills in a legal environment with a guaranteed solution.
  • Set a time cap per challenge and rotate; getting stuck on one (a rabbit hole) is mistake number one.
  • Take notes on everything you try: avoids repetition and helps when asking for a hint or collaborating.
  • Read the prompt carefully: file names, point values and description almost always hide the clue.
  • Identify the CTF type (Jeopardy/AD/boot2root)
  • Exhaustive enumeration (ports, services, web, versions)
  • Analyze each service; look for vulns/credentials
  • Foothold (user flag) and document the path
  • Privilege escalation (root flag)
  • Recognize and exit rabbit holes; time-box
  • Complete notes → writeup (How to write writeups)