Skip to content

Introduction to capture-the-flag

27 modules · ~47 contact hours · no prerequisites beyond a browser

A sequenced introduction to the techniques capture-the-flag competitions actually test: encoding recognition, classical and modern cryptanalysis, hash cracking, web tokens, file and network forensics, steganography, and binary exploitation. Every technique is practised in a browser tool that runs the real algorithm locally, and assessed by a produced artefact rather than a quiz.

Materials

  • ctfpal - https://ctfpal.com. A static web application with 111 documented tools. No installation, no account, no cost.
  • Any modern browser. A locked-down lab machine or a Chromebook is sufficient.
  • Practice challenges are hosted by picoCTF and are free; the course links them rather than redistributing them.

Software and data-protection statement

All processing happens in the student’s browser using JavaScript and WebAssembly. Files students open are read through the File API and are never transmitted. There are no user accounts and no server-side storage. Google Analytics records page views; no student input, file, or work is passed to it. Work is held in the browser’s own IndexedDB on the student’s machine and can be cleared like any other site data. The source is public and MIT licensed, so it can be reviewed, forked, or self-hosted on institutional infrastructure.

Three features send student work outbound, and only when a student explicitly uses them: the HTTP request replayer and the path scanner, which contact a target the student names and are covered by the responsible-use policy below, and an optional AI triage helper that is inert unless the student supplies their own API key.

Assessment

Each module carries one checkpoint: a specific artefact the student either produced or did not. Because every tool is deterministic, two students who did the work correctly submit the same value, which makes marking fast and bluffing hard. Practice challenges are formative and ungraded.

Responsible use

Several tools perform active testing against a target the user names. Used against systems the user does not own and has no written permission to test, that is a criminal offence in most jurisdictions. Cover this before the web module rather than alongside it; a student who learns the technique without the boundary has been taught badly.

Module schedule

  1. 1. Recognising encodingsFoundation · 60 min · 59 challenges

    Tell Base64 from hex from Base32 from binary on sight, peel layered encodings, and learn why an encoding is not encryption.

    Objectives

    • Identify Base64, Base64-URL, hex, Base32, binary, and Morse from their alphabets alone
    • Decode a multi-layer wrapper without guessing the order
    • Explain why encoding provides no confidentiality
    • Recognise when a decode produced bytes rather than text, and switch approach
    • Read percent-encoding and HTML entities as transport artefacts rather than as the puzzle

    Checkpoint: Given a three-layer encoded string, produce the plaintext and state each layer in order.

    Tools: Cipher identifier and automatic decoder, Base64 decoder and encoder, Hex to text converter, Base32 decoder and encoder, Binary to text converter, URL decoder and encoder, HTML entity decoder, ASCII table with hex, decimal, octal and binary, Base58, UUID and colour utilities, Recipe builder: chain decodes and transforms. Reading: Spot the encoding: reading base64, base32, hex and friends at a glance, The first ten minutes: a triage playbook for any CTF challenge.

    Lesson pack · Student page

  2. 2. Classical ciphers and frequency analysisFoundation · 90 min · 24 challenges

    Break Caesar, Vigenere, and arbitrary substitution using letter statistics - and learn why statistics beat guessing.

    Assumes: 1. Recognising encodings.

    Objectives

    • Break a Caesar shift with chi-squared scoring rather than by reading 26 candidates
    • Recover a Vigenere key length using the index of coincidence, then the key itself per column
    • Distinguish a transposition from a substitution by looking at letter frequencies
    • Recognise a polygraphic or fractionating cipher - Playfair, Hill, ADFGVX - from what single-letter statistics fail to say
    • Explain why short ciphertexts defeat statistical attacks

    Checkpoint: Recover a Vigenere key from ciphertext alone and report the index of coincidence at each candidate period.

    Tools: Cipher identifier and automatic decoder, Caesar cipher decoder with automatic shift detection, ROT13 decoder, Atbash cipher decoder, Affine cipher solver, Vigenere cipher solver with automatic key recovery, Monoalphabetic substitution cipher solver, Rail fence cipher solver, Playfair cipher decoder, Hill cipher solver, Bacon cipher decoder, ADFGVX cipher decoder, Enigma machine simulator and cracker. Reading: Chi-squared, index of coincidence, and why classical ciphers fall.

    Lesson pack · Student page

  3. 3. Hashes, identification and crackingFoundation · 60 min · 17 challenges

    Identify a digest by shape, understand why hashing is one-way, and learn where wordlist cracking works and where it is a trap.

    Assumes: 1. Recognising encodings.

    Objectives

    • Identify a hash from its length and prefix, and name the ambiguities that length alone cannot resolve
    • Explain the difference between encoding, encryption, and hashing
    • Crack a fast unsalted hash with a wordlist and rule transforms
    • Recognise a deliberately slow hash and choose a different approach
    • Extend a Merkle-Damgard MAC without knowing the secret, and say which constructions stop that

    Checkpoint: Identify an unknown digest, justify the identification, then crack it - or argue from the algorithm why cracking is the wrong path.

    Tools: Hash identifier with hashcat mode lookup, MD5, SHA-1 and SHA-256 hash generator, In-browser hash cracker with rule transforms, SHA-3, BLAKE2, Keccak and RIPEMD calculator, Hash length extension attack. Reading: Hash cracking that actually works: identify, wordlist, rules, mask, Hash length extension: appending to a message you cannot read.

    Lesson pack · Student page

  4. 4. Reconnaissance and OSINTFoundation · 90 min · 37 challenges

    Treat open-source intelligence as a pivot loop rather than a search, and know what metadata survives which route.

    Assumes: 1. Recognising encodings.

    Objectives

    • Run the pivot loop: enumerate, expand, cross-reference, record
    • Predict which metadata survives a given publication route, and check the right thing first
    • Narrow an image's location from visible constraints without recognising the place
    • Enumerate an organisation's subdomains from certificate transparency rather than by probing
    • Work a leaked dataset from the shell - shape it, index it, then query it - rather than by opening files
    • State where open-source ends and unauthorised access begins

    Checkpoint: Given one photograph with no GPS tag, narrow its location to a city and state which visible constraint eliminated each region you ruled out.

    Tools: EXIF metadata viewer, GPS coordinate converter (DMS, decimal, UTM), Timestamp converter (Unix, ISO, FILETIME, HFS+), Strings extractor for binaries and blobs, Perceptual image hash: are these the same picture?, Regex tester with match offsets and capture groups. Reading: OSINT as a method, not a lucky search, Working a leaked dataset: OSINT on a pile of data.

    Lesson pack · Student page

  5. 5. Misc, esolangs and prompt injectionFoundation · 90 min · 33 challenges

    The category you cannot prepare for by learning a technique - so prepare the triage instead, and learn to identify a dozen shapes on sight.

    Assumes: 1. Recognising encodings.

    Objectives

    • Identify Brainfuck, Whitespace, Ook!, JSFuck and Piet from their character sets alone
    • Use a distinct-character count as a first-pass identifier for any unknown text
    • Recognise the recurring misc shapes: encoding chains, damaged codes, audio, text steganography
    • Read a file in hex before concluding it is empty or plain
    • Separate a prompt-injection challenge's instruction channel from its data channel, and attack the join
    • Recognise when a challenge is a joke and automate rather than repeat

    Checkpoint: Given five unlabelled artifacts, identify what each one is and name the tool that opens it, without solving any of them.

    Tools: Brainfuck and esolang decoder, Cipher identifier and automatic decoder, Zero-width character and text steganography decoder, QR code decoder, Audio spectrogram and SSTV decoder, Recipe builder: chain decodes and transforms, Regex tester with match offsets and capture groups. Reading: Esolangs and the misc pile, Prompt injection: a field guide for AI CTF challenges, Writing your own CTF tooling in Go.

    Lesson pack · Student page

  6. 6. XOR and the cost of reusing a keyCore · 90 min · 27 challenges

    Break single-byte and repeating-key XOR, then recover both plaintexts from a reused one-time pad by crib dragging.

    Assumes: 1. Recognising encodings.

    Objectives

    • Brute-force single-byte XOR and score candidates automatically
    • Detect a repeating keysize using normalised Hamming distance
    • Recover two plaintexts from a reused pad without ever learning the key
    • Explain why key reuse destroys a cipher that is otherwise information-theoretically secure
    • Recognise a stream cipher, a keystream generator and a hand-rolled 'custom' scheme as the same construction, and attack the keystream rather than the algorithm

    Checkpoint: Given two ciphertexts under one reused key, recover both plaintexts and describe each crib you used.

    Tools: XOR cipher decoder and key recovery, XOR crib dragging for many-time pads, Hex to text converter, Cipher identifier and automatic decoder, Recipe builder: chain decodes and transforms. Reading: XOR, crib dragging, and the two-time pad.

    Lesson pack · Student page

  7. 7. Block ciphers, modes and oraclesCore · 120 min · 19 challenges

    AES is not the target. ECB's repeated blocks, CBC's malleability, a padding oracle, a reused GCM nonce, and a predictable PRNG all are.

    Assumes: 6. XOR and the cost of reusing a key.

    Objectives

    • Recognise ECB from ciphertext alone by spotting repeated blocks
    • Flip a chosen bit of CBC plaintext by corrupting the previous block, and predict the collateral damage
    • Turn a padding error into a decryption oracle, byte by byte
    • Explain what a reused nonce costs in CTR and in GCM, and why the GCM case also forfeits authentication
    • Recover the state of an LCG or MT19937 from observed output and predict the next token
    • Recognise when a timing difference, not a plaintext, is the leak

    Checkpoint: Given a CBC-encrypted session cookie and a server that reports padding errors, recover the plaintext without the key and state how many oracle queries each byte cost.

    Tools: AES decryption tool (CBC, GCM, CTR, ECB), CBC padding oracle attack, AES-GCM nonce reuse (forbidden attack), Linear congruential generator predictor, MT19937 state recovery and predictor, Cipher identifier and automatic decoder. Reading: AES is fine. The mode around it is the challenge, Predicting the random: LCGs, Mersenne Twister, and seeded PRNGs, Side channels: when how long it took is the answer.

    Lesson pack · Student page

  8. 8. RSA and the parameters that break itCore · 120 min · 32 challenges

    Work the RSA decision tree - small modulus, close primes, tiny exponent, shared modulus - and learn to read a key for its weakness.

    Assumes: 6. XOR and the cost of reusing a key.

    Objectives

    • Recover a private exponent from a factored modulus
    • Choose an attack from the shape of n, e, and the number of ciphertexts
    • Apply Fermat factorization, Wiener's attack, and the common-modulus attack
    • Read the parameters straight out of a PEM or DER key rather than out of the challenge text
    • Explain why textbook RSA without padding enables attacks that padded RSA does not

    Checkpoint: Given three RSA challenges with different weaknesses, name the applicable attack for each before running anything, then verify.

    Tools: RSA decryption and attack runner, Fermat factorization for close RSA primes, Wiener’s attack on small RSA private exponents, RSA common modulus attack, Hastad broadcast attack on RSA, Modular arithmetic and number theory toolkit, ASN.1 and X.509 certificate parser. Reading: The RSA attack decision tree, Side channels: when how long it took is the answer.

    Lesson pack · Student page

  9. 9. Discrete logs, Diffie-Hellman and elliptic curvesAdvanced · 120 min · 9 challenges

    The other half of public-key crypto: weak groups, small subgroups, invalid curves, and the nonce that leaks a signing key.

    Assumes: 8. RSA and the parameters that break it.

    Objectives

    • Choose between brute force, baby-step giant-step and Pohlig-Hellman from the factorisation of the group order
    • Recognise a small-subgroup or invalid-curve parameter set before attempting anything
    • Recover an ECDSA private key from two signatures sharing a nonce
    • Recover a key from biased nonces using a lattice, and say how many signatures that needs
    • Explain why a signature scheme fails catastrophically on nonce reuse while encryption merely leaks

    Checkpoint: Given two ECDSA signatures over different messages, detect the shared nonce, recover the private key, and verify it by signing a third message.

    Tools: Discrete logarithm solver, ECDSA nonce reuse private key recovery, Biased nonce lattice attack (hidden number problem), Knapsack / subset-sum solver (Merkle-Hellman break), Modular arithmetic and number theory toolkit, ASN.1 and X.509 certificate parser. Reading: Discrete logs and the ways Diffie-Hellman is set up wrong, Elliptic curves in CTF: nonce reuse, biased nonces, and invalid curves.

    Lesson pack · Student page

  10. 10. Web recon and attack surfaceCore · 90 min · 46 challenges

    Find the endpoint the challenge is really about: unlinked paths, JavaScript-only routes, exposed .git, and the parameters nobody documented.

    Assumes: 4. Reconnaissance and OSINT.

    Objectives

    • Map an application's routes from its own JavaScript before running any wordlist
    • Choose a content-discovery wordlist from the stack rather than by size
    • Recover a source tree from an exposed .git directory, including deleted and dangling objects
    • Read response headers and error pages for the framework, and use that to narrow every later probe
    • State the authorisation boundary you are testing inside, in one sentence, before you send a request

    Checkpoint: From a target application, produce a list of routes with the evidence for each - source reference, header, or wordlist hit - and mark which of them are reachable without authentication.

    Tools: Directory and path scanner, Exposed .git directory dumper, HTTP security header analyzer, HTTP request replayer, Regex tester with match offsets and capture groups, Strings extractor for binaries and blobs. Reading: Web recon: finding the endpoint the challenge is really about, Git forensics: an exposed .git is the whole source tree.

    Lesson pack · Student page

  11. 11. Injection: SQL and everything after itCore · 120 min · 23 challenges

    One bug class, five parsers. Break out of a SQL string, a shell argument, an XML document, a NoSQL query and an LDAP filter, and read the response for confirmation.

    Assumes: 10. Web recon and attack surface.

    Objectives

    • Confirm an injection point with a detection payload before attempting exploitation
    • Move from a broken quote to a UNION select, and from a blind boolean to an extracted string
    • Recognise NoSQL, LDAP, XPath and CRLF injection from the sink rather than from the payload
    • Turn an XXE into a file read, and know which parsers stopped allowing that
    • Chain a command injection into an out-of-band confirmation when nothing is echoed back
    • Explain why every one of these is the same bug: data crossing into a parser as code

    Checkpoint: Extract one row from a database through a blind boolean injection and state, per character, which comparison confirmed it - then do the same extraction through a time-based channel.

    Tools: Web attack payload catalog, HTTP request replayer, URL decoder and encoder, Regex tester with match offsets and capture groups, Reverse shell generator. Reading: SQL injection: from a broken quote to the whole database, Injection beyond SQL: NoSQL, LDAP, XPath, CRLF and SSI, Command injection: making the shell run your half of the string, XXE: turning an XML parser into a file reader.

    Lesson pack · Student page

  12. 12. Client-side: XSS and the browser's trust modelCore · 90 min · 35 challenges

    Get your JavaScript to run in someone else's page, past a CSP and an admin bot - and see why polluting a prototype changes every object in the process.

    Assumes: 10. Web recon and attack surface.

    Objectives

    • Distinguish reflected, stored and DOM-based XSS by where the sink is, not where the payload went in
    • Read a Content-Security-Policy and name what it forbids, what it permits, and the gadget that gets past it
    • Exfiltrate a cookie or a bot's session to a collector you control
    • Recognise a prototype pollution sink and chain it to a gadget already in the page
    • Explain the same-origin policy in terms of what it protects, and name three legitimate exceptions to it

    Checkpoint: Land a payload that makes the challenge's bot issue a request to a URL you control, carrying its session, and state which CSP directive you had to work around.

    Tools: HTML entity decoder, URL decoder and encoder, Web attack payload catalog, HTTP security header analyzer, Regex tester with match offsets and capture groups. Reading: XSS in CTF: getting your JavaScript to run in someone else's page, Prototype pollution: editing the base class of every object.

    Lesson pack · Student page

  13. 13. Sessions, tokens and access controlCore · 120 min · 19 challenges

    Read and forge JWTs and Flask sessions, break the assumptions behind a session cookie, and win the races that a request boundary creates.

    Assumes: 3. Hashes, identification and cracking; 12. Client-side: XSS and the browser's trust model.

    Objectives

    • Decode a JWT and identify the attack its header enables
    • Forge an alg=none token and recover a weak HMAC secret offline
    • Unpack and re-sign a Flask session once the secret key is known, and find that key first
    • Choose between horizontal and vertical access-control tests, and prove each with two accounts
    • Exploit a check-then-act window with concurrent requests, and explain why a retry loop is not the same thing
    • Recognise a request-smuggling primitive from a header pair a proxy and a server read differently

    Checkpoint: Take a JWT-protected endpoint and reach an admin-only response, stating which of the three token weaknesses you used and why the other two did not apply.

    Tools: JWT decoder and signature verifier, JWT alg=none bypass generator, JWT secret brute force, Flask session cookie decoder, HTTP request replayer, HTTP security header analyzer. Reading: Attacking JWTs: alg=none, algorithm confusion, and the header fields nobody audits, Sessions, cookies, CORS and CSRF: the browser's trust rules, Race conditions: spending the same balance twice, Request smuggling: when the proxy and the server disagree.

    Lesson pack · Student page

  14. 14. Server-side takeover: from input to executionAdvanced · 120 min · 14 challenges

    SSRF, template injection, path traversal, file upload and deserialization - five routes from a parameter you control to code running on the server.

    Assumes: 11. Injection: SQL and everything after it.

    Objectives

    • Make a server fetch a URL you choose, and reach an internal service or a metadata endpoint with it
    • Detect template injection with an arithmetic probe and climb from it to a sandbox escape
    • Read an arbitrary file through traversal, then convert the read into execution
    • Get executable content past an upload filter by satisfying the check and the interpreter separately
    • Recognise a serialized blob by its header, and explain what a gadget chain is composed of
    • Order these five by what the target's stack makes plausible, rather than by preference

    Checkpoint: From one user-controlled parameter, produce evidence of code execution on the server - and write the chain down as a sequence of trust boundaries crossed, one line each.

    Tools: Web attack payload catalog, HTTP request replayer, Reverse shell generator, File type identifier by magic bytes, Magic byte and file signature table, ZIP archive inspector. Reading: SSRF: making the server fetch the flag for you, Template injection and the long climb out of a Python jail, Path traversal and local file inclusion: from ../ to code execution, File upload: getting the wrong bytes into the right place, Reading serialized blobs, and the gadget chains hiding behind them.

    Lesson pack · Student page

  15. 15. APIs, GraphQL and application logicCore · 90 min · 19 challenges

    The bugs that live between endpoints rather than inside one: object references, mass assignment, over-broad queries, and workflows that can be run out of order.

    Assumes: 13. Sessions, tokens and access control.

    Objectives

    • Enumerate an API's real surface from a specification, a client bundle, or introspection
    • Test an object reference for authorisation rather than for existence, using two accounts
    • Find a mass-assignment field by diffing what the API returns against what it accepts
    • Query a GraphQL schema for the fields the UI never asks for, and measure the cost of a nested query
    • Model a multi-step workflow as a state machine and find the transition nobody guards
    • Write a logic bug up in terms of the assumption it breaks, not the request that broke it

    Checkpoint: Against a multi-step workflow, complete it in an order the designer did not intend and state precisely which check assumed the previous step had happened.

    Tools: HTTP request replayer, JWT decoder and signature verifier, Web attack payload catalog, Docker image inspector: layers, history and deleted secrets, HTTP security header analyzer, Regex tester with match offsets and capture groups. Reading: Hacking APIs: the bugs that live between endpoints, Thinking like the designer: finding the intended flaw.

    Lesson pack · Student page

  16. 16. File forensics and carvingCore · 90 min · 45 challenges

    Identify files by their bytes, find data appended past a format's end marker, and pull evidence out of images, archives and documents.

    Assumes: 1. Recognising encodings.

    Objectives

    • Identify a file's real type regardless of extension
    • Find and extract data hidden after a format's terminator
    • Read EXIF, PNG chunks, and JPEG segments for metadata and appended payloads
    • Take a PDF or Office document apart by object and stream, and find the active content in it
    • Read an archive's central directory against its local headers, and spot the mismatch that hides a file
    • Repair a deliberately corrupted header

    Checkpoint: Given a polyglot file, extract every embedded file it contains and state the offset and signature of each.

    Tools: File type identifier by magic bytes, Magic byte and file signature table, Strings extractor for binaries and blobs, Hex viewer and hexdump, PNG chunk analyzer, JPEG marker and segment analyzer, EXIF metadata viewer, ZIP archive inspector, PDF object and stream analyzer, Office macro and OLE extractor. Reading: The first ten minutes: a triage playbook for any CTF challenge, Archive attacks: ZIP crypto, known plaintext, and Zip Slip, Document forensics: taking apart a PDF and an Office file.

    Lesson pack · Student page

  17. 17. SteganographyCore · 90 min · 32 challenges

    Sweep an image, audio file, or paragraph for hidden data across the whole technique space rather than guessing one method.

    Assumes: 16. File forensics and carving.

    Objectives

    • Extract LSB data across channels, bit orders, and traversal directions
    • Read a spectrogram to distinguish painted text, Morse, SSTV, and DTMF
    • Detect zero-width and whitespace steganography in plain text
    • Compare a suspect image against an original, perceptually and byte for byte, and say what the difference means
    • Explain why LSB survives in PNG and dies in JPEG

    Checkpoint: Solve a nested stego challenge and draw the chain of containers from the outermost file to the flag.

    Tools: Automatic steganography solver, LSB steganography extractor, PNG chunk analyzer, Audio spectrogram and SSTV decoder, DTMF tone decoder, Morse code translator, Zero-width character and text steganography decoder, Perceptual image hash: are these the same picture?. Reading: A workflow for image steganography, from magic bytes to bit planes, Audio steganography: spectrograms, LSB, and signals that are not music, Hiding in text: zero-width characters, homoglyphs, and whitespace.

    Lesson pack · Student page

  18. 18. Network forensicsAdvanced · 90 min · 20 challenges

    Triage a packet capture: find the one conversation that matters, extract transferred files, and spot exfiltration over DNS.

    Assumes: 16. File forensics and carving.

    Objectives

    • Use a protocol breakdown to decide where to look first
    • Reassemble a TCP stream and read a plaintext protocol
    • Extract files transferred over HTTP, FTP, or SMB
    • Recognise DNS tunnelling and decode the exfiltrated payload
    • Decrypt TLS from a capture when the key material is available, and say exactly what it takes
    • Infer the structure of an undocumented binary protocol from repeated messages

    Checkpoint: From a capture, produce the exfiltrated payload and the exact query sequence that carried it.

    Tools: PCAP analyzer for CTF network forensics, PCAP overview: protocols, conversations and hosts, Packet list and raw frame bytes, Follow a TCP stream in the browser, DNS queries from a PCAP, and DNS exfiltration, Find plaintext credentials in a packet capture, Extract HTTP requests and responses from a PCAP, Search a packet capture for flags, Decrypt TLS in a PCAP with an SSLKEYLOGFILE, Base32 decoder and encoder, Timestamp converter (Unix, ISO, FILETIME, HFS+), Strings extractor for binaries and blobs. Reading: PCAP triage: finding the flag in a hundred thousand packets, Reversing a binary protocol from a capture.

    Lesson pack · Student page

  19. 19. Memory and disk forensicsAdvanced · 120 min · 26 challenges

    Answer the three questions a memory image is asked - what was running, what was typed, what was on disk - and know why a scan beats a list.

    Assumes: 16. File forensics and carving.

    Objectives

    • Distinguish a raw memory image from a crash dump or hibernation file before analysing it
    • Explain why psscan finds processes pslist cannot, and what that costs in validation
    • Recover command lines from a Windows image, including the UTF-16 problem
    • Locate and carve a registry hive out of a dump and read persistence from it
    • Read ext, FAT and NTFS structures well enough to recover a deleted or resident file
    • Read the boot record chain and say where a bootkit would have to live

    Checkpoint: Given a raw Windows memory image, produce the process tree, identify the process that should not be there, and recover the command line it was started with.

    Tools: Memory dump, disk image and registry hive analysis, Strings extractor for binaries and blobs, File type identifier by magic bytes, Hex viewer and hexdump, Timestamp converter (Unix, ISO, FILETIME, HFS+). Reading: Memory dump triage: what was running, what was typed, what was on disk, Disk image forensics: partitions, deleted files, and slack, The boot process as a target: MBR, VBR, and bootkits.

    Lesson pack · Student page

  20. 20. Malware triage and defensive telemetryAdvanced · 120 min · 9 challenges

    Sort a pile of samples by similarity, defeat the tricks that stop them being analysed, and read the logs and telemetry that catch them.

    Assumes: 19. Memory and disk forensics.

    Objectives

    • Triage a sample statically - imports, sections, entropy, strings - and predict what dynamic analysis will show
    • Cluster related samples using import hashes and fuzzy hashing, and say what each measure actually compares
    • Recognise packing from section entropy and an import table with almost nothing in it
    • Name three anti-debug and three anti-VM checks, and the analysis change each one forces
    • Read Windows event logs and process telemetry into a timeline that supports or refutes a hypothesis
    • Explain what ETW and AMSI see, and where a defender's visibility ends

    Checkpoint: Given ten samples, group them by shared code, justify each grouping with the measure that produced it, and name the outlier that belongs to no group.

    Tools: ELF, PE and Mach-O binary analyzer, Strings extractor for binaries and blobs, Office macro and OLE extractor, PowerShell deobfuscator, Perceptual image hash: are these the same picture?, MD5, SHA-1 and SHA-256 hash generator. Reading: Triage at scale: hashing, similarity, and finding the odd sample, Anti-analysis tricks, and how reversing challenges use them, Log forensics and threat hunting for blue-team CTF, What the endpoint sees: ETW, AMSI, and userland hooks.

    Lesson pack · Student page

  21. 21. Reverse engineeringCore · 120 min · 101 challenges

    Get from an unknown executable to the one function that decides whether your input is right, and recognise which of four shapes the check takes.

    Assumes: 16. File forensics and carving.

    Objectives

    • Establish format, architecture and whether a binary is stripped, and say what each implies
    • Use strings and cross-references to find the check function without reading from main
    • Classify a flag check as direct comparison, transform-then-compare, hash-then-compare, or a constraint system
    • Invert a transform-then-compare check using the constants already in the binary
    • Choose between static reading and running it under a debugger, and say what each answers faster
    • Read managed bytecode - JVM, .NET, Python, WebAssembly - back to something close to source
    • Say when a decompiler helps and when its output is a reconstruction to be distrusted

    Checkpoint: Given a stripped 64-bit binary that transforms input before comparing it, name the transform, invert it, and produce the flag without running the binary.

    Tools: ELF, PE and Mach-O binary analyzer, Strings extractor for binaries and blobs, Java .class disassembler, Python .pyc bytecode disassembler, WebAssembly disassembler, Endianness converter and byte swapper, Struct pack and unpack (p32, p64, u32, u64), Hex viewer and hexdump. Reading: Reading a binary you have never seen before, Watching a binary run: dynamic analysis for reversing, Reversing managed code: .NET, Java, and Python bytecode, Reversing WebAssembly: a stack machine in the browser tab.

    Lesson pack · Student page

  22. 22. Mobile applicationsCore · 120 min · 23 challenges

    Take an APK apart: the manifest rules that define the attack surface, navigating DEX without decompiling it, and when to stop reading and hook.

    Assumes: 21. Reverse engineering.

    Objectives

    • Read an APK's structure from its zip listing and say what each part implies
    • Decode a binary AndroidManifest and identify every exported component
    • State the export rule correctly, including the intent-filter default
    • Follow a string to its load site and a method to its callers inside a DEX
    • Find the native library behind a JNI call and treat it as an ordinary ELF
    • Decide between static reading and runtime hooking, and justify the choice

    Checkpoint: Given an APK, list every component reachable by another app on the device, and say for each one which rule made it reachable.

    Tools: APK and IPA analyzer: manifest, exported components, DEX xrefs, Java .class disassembler, ZIP archive inspector, ELF, PE and Mach-O binary analyzer, Strings extractor for binaries and blobs. Reading: Reversing managed code: .NET, Java, and Python bytecode, Taking an Android app apart.

    Lesson pack · Student page

  23. 23. Firmware, hardware and signalsAdvanced · 120 min · 16 challenges

    Find the filesystem inside a firmware blob, read a debug interface off a board, and decode a captured signal back into bytes.

    Assumes: 21. Reverse engineering.

    Objectives

    • Locate and extract an embedded filesystem from a firmware image by signature and entropy
    • Identify the architecture and endianness of an embedded binary before disassembling it
    • Read a UART, SPI or I2C capture from a logic analyser back into framed bytes
    • Recognise what a JTAG or SWD interface offers, and why a challenge hands you one
    • Decode a captured RF or infrared transmission into its underlying symbols
    • Find hardcoded credentials and keys in an image, and explain why they cannot simply be rotated

    Checkpoint: From a firmware image, extract the root filesystem, find the credential or key it ships with, and state the offset and format of the container it came from.

    Tools: Firmware unpacker: entropy, filesystems and partition tables, Logic analyzer decoder: UART, I2C, SPI and 1-Wire, Flipper .sub and .ir decoder: RF and infrared captures, QR code decoder, ELF, PE and Mach-O binary analyzer, Strings extractor for binaries and blobs, Hex viewer and hexdump. Reading: Firmware challenges: the filesystem hiding inside the blob, Hardware and signal challenges: logic captures, RF, and barcodes.

    Lesson pack · Student page

  24. 24. Binary exploitationAdvanced · 150 min · 66 challenges

    Read a binary's protections, find an overflow offset in one crash, and build a ROP chain when the stack is not executable.

    Assumes: 21. Reverse engineering.

    Objectives

    • Read NX, PIE, canary, and RELRO from a binary and say what each rules out
    • Find an overflow offset with a de Bruijn pattern in a single crash
    • Build a ret2libc chain, including stack alignment
    • Turn a leaked pointer into a libc base and resolve arbitrary symbols
    • Turn a format string into an arbitrary read and then an arbitrary write
    • Name the four heap bugs that matter and the allocator behaviour each one abuses
    • Write shellcode that survives the challenge's constraints - length, character set, and seccomp

    Checkpoint: Given a 64-bit binary with NX and no PIE, produce a working ret2libc exploit and explain each entry in the chain.

    Tools: ELF, PE and Mach-O binary analyzer, Buffer overflow offset finder, Cyclic pattern generator and offset finder, ROP gadget finder, ROP chain and payload builder, Libc base address calculator, Format string exploit builder, Glibc heap exploitation helper, Shellcode assembler and library, Struct pack and unpack (p32, p64, u32, u64), Pwntools exploit script generator. Reading: From crash to shell: stack overflows, offsets, ret2win, and ret2libc, Integer bugs: overflow, signedness, truncation, and the off-by-one, Format string bugs: when %n writes where you point, The glibc heap: chunks, bins, and the four bugs that matter, Writing shellcode that fits: constraints, encoders, and seccomp.

    Lesson pack · Student page

  25. 25. Fuzzing and crash triageAdvanced · 120 min · 21 challenges

    Stop reading for the bug and make the crash come to you - then work out which crashes are the same bug and which one is exploitable.

    Assumes: 24. Binary exploitation.

    Objectives

    • Write a harness that reaches the interesting code in as few layers as possible
    • Build a seed corpus and say why each seed is there
    • Explain what coverage instrumentation buys, and what it costs on a slow target
    • Turn a sanitiser report into a one-line statement of the bug's class and location
    • De-duplicate crashes by root cause rather than by stack hash
    • Judge exploitability from the primitive rather than from the crash message

    Checkpoint: Take a small parsing target, produce a harness and a seed corpus, run it to a crash, and hand in the minimised input plus a one-sentence root cause.

    Tools: ELF, PE and Mach-O binary analyzer, Cyclic pattern generator and offset finder, Buffer overflow offset finder, Struct pack and unpack (p32, p64, u32, u64), Pwntools exploit script generator. Reading: Coverage-guided fuzzing: making the crash come to you, Integer bugs: overflow, signedness, truncation, and the off-by-one.

    Lesson pack · Student page

  26. 26. After the shell: privilege escalationAdvanced · 90 min · 32 challenges

    A shell is the middle of the challenge. Enumerate systematically, recognise the misconfiguration classes, and know what a Windows token actually grants.

    Assumes: 14. Server-side takeover: from input to execution.

    Objectives

    • Enumerate a Linux host in a fixed order and explain what each step rules out
    • Exploit SUID binaries, sudo rules and capabilities, and say which of the three is present from the evidence
    • Escape a restricted shell and a limited PATH
    • Read a Windows access token - user, groups, privileges, integrity level - and name what it permits
    • Explain how impersonation converts one privilege into another account's authority
    • Find persistence and scheduled execution as an attacker would, and as a defender would

    Checkpoint: From an unprivileged shell, escalate to root or SYSTEM and write the path as a chain: what you found, why it was privileged, and what it let you do next.

    Tools: Reverse shell generator, Web attack payload catalog, PowerShell deobfuscator, Strings extractor for binaries and blobs, ELF, PE and Mach-O binary analyzer. Reading: Linux privilege escalation: the shell is the middle of the challenge, Windows privilege escalation: tokens, SIDs, and the impersonation shortcut.

    Lesson pack · Student page

  27. 27. Smart contracts and the EVMAdvanced · 90 min · 5 challenges

    Public code, public state, and an execution model where a callback in the middle of your function is a normal event.

    Assumes: 21. Reverse engineering.

    Objectives

    • Read contract storage directly and explain why 'private' means unindexed rather than secret
    • Trace a reentrancy path and name the state update that happened too late
    • Distinguish delegatecall from call in terms of whose storage is written
    • Recognise an unprotected initialiser or owner-setting function from the bytecode alone
    • Follow a transaction trace to the exact call that changed the balance
    • Explain why an on-chain source of randomness is an attacker-observable value

    Checkpoint: Given a vulnerable contract, drain it in a single transaction and write down the call sequence, marking the exact point where the contract's own state was stale.

    Tools: EVM bytecode analyzer: disassemble, decode selectors, read storage, Hex to text converter, MD5, SHA-1 and SHA-256 hash generator, Struct pack and unpack (p32, p64, u32, u64). Reading: Smart contract challenges: reentrancy, storage, and the EVM, Thinking like the designer: finding the intended flaw.

    Lesson pack · Student page

Recommended reading

None of this is required to complete a module - every module is self-contained - but each one cites the specific chapters that go further than it does, and this is the combined list. Ordered alphabetically, with the modules that cite each book. Each title links to our notes on it, which is where a student without the book should start.

Licence

This syllabus and the tool it teaches are MIT licensed. Adapt it, reorder it, cut it to fit your term, and use it without attribution or permission.