CSAW CTF Final Round 2026
- Starts
- Ends
- Runs for
- 36 hours
- Format
- Jeopardy (online)
- Rating weight
- 1.00 - Rated
- Teams registered
- 2
Run by NYUSEC.
What the organisers say
CSAW CTF is one of the oldest and biggest CTFs. Designed as an entry-level, jeopardy-style CTF, this competition is for students who are trying to break into the field of security, as well as for advanced students and industry professionals who want to practice their skills.
Prep briefing
What past editions were made of
Counted across 261 challenges from 2025, 2025, 2024, 2024, using the categories the scoreboards themselves used. Two things to hold in mind while reading it. The archive indexes challenges that someone published a solution to, not whole scoreboards, so this is the shape of what people wrote about rather than of everything that was set. And where a scoreboard gave no category the challenge lands in misc, so a large misc slice means “unlabelled” rather than “miscellaneous”.
- pwn 24%(42)
- misc 20%(35)
- crypto 17%(30)
- rev 16%(29)
- web 12%(21)
- forensics 8%(14)
- osint 3%(5)
What to have open when it starts
Pwn
Get the offset and the libc base mechanically, so the thinking is spent on the chain rather than on arithmetic.
- Cyclic pattern generator and offset finder
- Buffer overflow offset finder
- Libc base address calculator
- ROP gadget finder
- Pwntools exploit script generator
New to this? Read Binary exploitation, Fuzzing and crash triage, After the shell: privilege escalation
Misc
Misc is whatever did not fit, which in practice means encodings and esolangs. Identify, do not guess.
- Cipher identifier and automatic decoder
- Recipe builder: chain decodes and transforms
- Brainfuck and esolang decoder
- Base64 decoder and encoder
- Regex tester with match offsets and capture groups
New to this? Read Recognising encodings, Misc, esolangs and prompt injection
Crypto
Have the cipher identifier open on the first paste. Most of the round-one crypto is a classical cipher or an RSA parameter mistake, and both are recognised faster than they are solved.
- Cipher identifier and automatic decoder
- RSA decryption and attack runner
- XOR cipher decoder and key recovery
- Vigenere cipher solver with automatic key recovery
- Modular arithmetic and number theory toolkit
New to this? Read Classical ciphers and frequency analysis, XOR and the cost of reusing a key, Block ciphers, modes and oracles, RSA and the parameters that break it, Discrete logs, Diffie-Hellman and elliptic curves
Reversing
Identify the binary before you open it. Knowing it is a .pyc, a JAR or a stripped ELF decides the next hour.
- ELF, PE and Mach-O binary analyzer
- Strings extractor for binaries and blobs
- Python .pyc bytecode disassembler
- Java .class disassembler
- WebAssembly disassembler
New to this? Read Reverse engineering, Mobile applications, Firmware, hardware and signals, Smart contracts and the EVM
The challenges people wrote about most
From previous editions, ordered by how many published solutions each attracted. Reading two solutions to one of these is the closest thing to a warm-up for this event that exists.
- slitherymisc · 2020 · 21 writeups
- authycrypto · 2020 · 17 writeups
- roppitypwn · 2020 · 17 writeups
- modus_operandicrypto · 2020 · 15 writeups
- baby_multpwn · 2020 · 14 writeups
- Alien Mathmisc · 2021 · 12 writeups