ASIS CTF Quals 2026
- Starts
- Ends
- Runs for
- 24 hours
- Format
- Jeopardy (online)
- Rating weight
- 90.53 - Flagship
- Teams registered
- 177
Run by ASIS, with prizes listed on CTFtime.
What the organisers say
This year, ASIS CTF Quals 2026 and Iran Olympics CTF 2026 have joined forces and will be held as a single, merged event! Secure your spot in the top 3 global teams or the top 7 Iranian teams to win a fully-funded invitation to the highly anticipated onsite finals in Tehran this October: • Olympic Hardware CTF • Olympic Pwny Racing CTF All travel and accommodation costs are fully covered.
Prep briefing
What past editions were made of
Counted across 33 challenges from 2025, 2025, 2024, 2024, using the categories the scoreboards themselves used. Two things to hold in mind while reading it. The archive indexes challenges that someone published a solution to, not whole scoreboards, so this is the shape of what people wrote about rather than of everything that was set. And where a scoreboard gave no category the challenge lands in misc, so a large misc slice means “unlabelled” rather than “miscellaneous”.
- misc 43%(6)
- crypto 29%(4)
- web 21%(3)
- pwn 7%(1)
What to have open when it starts
Misc
Misc is whatever did not fit, which in practice means encodings and esolangs. Identify, do not guess.
- Cipher identifier and automatic decoder
- Recipe builder: chain decodes and transforms
- Brainfuck and esolang decoder
- Base64 decoder and encoder
- Regex tester with match offsets and capture groups
New to this? Read Recognising encodings, Misc and esoteric languages
Crypto
Have the cipher identifier open on the first paste. Most of the round-one crypto is a classical cipher or an RSA parameter mistake, and both are recognised faster than they are solved.
- Cipher identifier and automatic decoder
- RSA decryption and attack runner
- XOR cipher decoder and key recovery
- Vigenere cipher solver with automatic key recovery
- Modular arithmetic and number theory toolkit
New to this? Read Classical ciphers and frequency analysis, XOR and the cost of reusing a key, RSA and the parameters that break it
Web
Read the token before you read the source. A session cookie that decodes is the shortest path through half the web board.
- JWT decoder and signature verifier
- Flask session cookie decoder
- HTTP request replayer
- Directory and path scanner
- HTTP security header analyzer
New to this? Read Web attacks and session tokens
The challenges people wrote about most
From previous editions, ordered by how many published solutions each attracted. Reading two solutions to one of these is the closest thing to a warm-up for this event that exists.