Classical ciphers and frequency analysis
Break Caesar, Vigenere, and arbitrary substitution using letter statistics - and learn why statistics beat guessing.
Assumes1. Recognising encodings
By the end you can
- Break a Caesar shift with chi-squared scoring rather than by reading 26 candidates
- Recover a Vigenere key length using the index of coincidence, then the key itself per column
- Distinguish a transposition from a substitution by looking at letter frequencies
- Recognise a polygraphic or fractionating cipher - Playfair, Hill, ADFGVX - from what single-letter statistics fail to say
- Explain why short ciphertexts defeat statistical attacks
1. Read
2. Use the tools
In the order they come up while solving. Read what each one does, or go straight to the workspace tab that runs it.
- Cipher identifier and automatic decoder
Paste anything and find out what it is. ctfpal runs every decoder and rotation, including multi-pass cascades, and ranks results by English-likeness and flag patterns.
Open it in the workspace - Caesar cipher decoder with automatic shift detection
Break a Caesar shift without guessing. ctfpal scores all 26 rotations by chi-squared letter frequency and puts the English one first.
Open it in the workspace - ROT13 decoder
Apply ROT13 (and ROT47) instantly. ROT13 is its own inverse, so the same operation encodes and decodes.
Open it in the workspace - Atbash cipher decoder
Decode Atbash, the keyless substitution that maps A to Z, B to Y, and so on. Its own inverse.
Open it in the workspace - Affine cipher solver
Brute-force every valid affine key pair and rank the 312 candidate decryptions by English-likeness.
Open it in the workspace - Vigenere cipher solver with automatic key recovery
Decrypt Vigenere with a known key, or recover the key from ciphertext alone using index-of-coincidence period detection and per-column chi-squared.
Open it in the workspace - Monoalphabetic substitution cipher solver
Break an arbitrary substitution cipher automatically by hill-climbing on quadgram statistics - no key, no guessing.
Open it in the workspace - Rail fence cipher solver
Brute-force rail fence transposition across 2-8 rails and every starting offset, ranked by English-likeness.
Open it in the workspace - Playfair cipher decoder
Decrypt Playfair with a known keyword, using the 5x5 digraph square. Recognisable by its even length and total absence of doubled letters.
Open it in the workspace - Hill cipher solver
Encrypt and decrypt with matrix keys over mod 26, including matrix inversion and known-plaintext key recovery.
Open it in the workspace - Bacon cipher decoder
Decode Baconian ciphers, including the versions hidden in letter case, font changes, or two repeated symbols.
Open it in the workspace - ADFGVX cipher decoder
Decrypt ADFGX and ADFGVX - a Polybius substitution followed by a columnar transposition, and unmistakable from its six-letter alphabet.
Open it in the workspace - Enigma machine simulator and cracker
Run Enigma I, M3 and the four-rotor M4 in the browser, and recover the rotor order and start positions of an unplugged machine by brute force.
Open it in the workspace
3. Try one now
Generated in your browser and checked in your browser. No account, nothing to download, and a fresh one whenever you want another.
4. Practise on the real thing
Real picoCTF challenges that use these techniques, easiest first. 24 match in total - see the full index.
Common mistakes
The wrong turns this topic reliably produces. Written as the mistake rather than the rule, because the rule is easy to agree with and easy to walk straight past.
- Reading a flat frequency profile as 'not a substitution cipher' when unchanged English frequencies in a scrambled text are the signature of a transposition.
- Scoring a 20-character ciphertext statistically. Below roughly 100 characters the second-best key often outscores the right one, and the answer has to come from a crib instead.
- Assuming English. A challenge whose plaintext is a flag format, a base64 blob, or another language breaks every frequency table the tool ships with.
- Stripping spacing and punctuation before analysis. Word boundaries survive most classical ciphers untouched, and on a short ciphertext the pattern of word lengths is a stronger crib than any frequency table.
- Accepting the solver's top-ranked mapping and fixing the spelling by hand until it reads. That converts a hypothesis into an answer without ever testing it; the confirmation has to be a crib that had to fit.
Checkpoint
Recover a Vigenere key from ciphertext alone and report the index of coincidence at each candidate period.
Teaching note
This is the first module where the tool's output is a ranked list rather than an answer. Students need to be told explicitly that reading the ranking - and noticing when the top two candidates score similarly - is the skill being taught.
Go deeper
The lessons above are written to get you through a challenge. These go after the subject instead. Each one opens our notes on that chapter - what it argues, what to take from it and where it stops - so this is somewhere to read now rather than a book to buy first. Nothing here is affiliate-linked or sold by us.
Chapter 11, Implementing and Attacking Cryptography
Black Hat Go - Tom Steele, Chris Patten, and Dan Kottmann
Implementing a cipher and then attacking your own implementation is the fastest cure for treating ciphers as black boxes.
Chapter 5, Cryptography
Designing Secure Software - Loren Kohnfelder
Explains why these ciphers are historical curiosities rather than options, in the vocabulary modern designs use.
Every book the curriculum cites has a page in the library.