Cyber Competitions Overview

ix
Peris.ai Feb. 18, 2025 https://peris.ai/post/what-capture-the-flag-competitions-teach-us-about-cybersecurity

Summary

The most important cybersecurity competitions fall into different categories, from prestigious Capture the Flag (CTF) events for skilled hackers to defensive competitions for students and challenges focused on specific, high-stakes exploits. The significance of a competition can vary depending on one’s career level and goals, whether it’s for learning, recruiting, or showcasing elite skills. There are also other competitions such as those on the Kaggle website and by Leet code (see weblinks for urls).

Cybersecurity competitions are excellent for skill development across all experience levels, from middle school to seasoned professionals. They primarily fall into Capture The Flag (CTF) events, which are problem-solving-focused, and Red Team vs. Blue Team competitions, which simulate real-world attacks and defenses.

Source: Gemini AI Overview – 10/23/2025

OnAir Post: Cyber Competitions Overview

About

For elite and experienced professionals

  • DEF CON CTF: Hosted at the famous DEF CON hacker conference, this is widely regarded as one of the most prestigious and challenging CTF competitions in the world. Winning teams are awarded the coveted “Black Badge,” and the event attracts top-tier hacking talent globally.
  • Pwn2Own: Focused on the exploitation of software vulnerabilities, Pwn2Own is a high-stakes competition where researchers earn significant cash prizes for discovering and demonstrating zero-day exploits in widely used software and hardware.
  • Google CTF: A global competition organized by Google, featuring high-quality, difficult challenges that cover a broad range of cybersecurity domains. It is respected for its well-designed challenges and its ability to attract both seasoned professionals and beginners.
  • SANS NetWars Tournament of Champions: A highly respected tournament that brings together the winners of various SANS NetWars competitions. It emphasizes practical skills and is a significant showcase of talent for industry professionals. 

For students and academic development

  • National Collegiate Cyber Defense Competition (NCCDC): This competition pits teams of college students against each other to defend a commercial-style network from a live “red team” of attackers. It is a foundational competition recognized by Congress for its focus on the defensive, operational aspects of cybersecurity.
  • CyberPatriot: Co-founded with the Air Force Association, this is the largest cyber defense competition for high school and middle school students. Its purpose is to inspire students to pursue careers in cybersecurity and other STEM fields.
  • National Cyber League (NCL): A biannual competition for high school and college students, the NCL provides a cloud-based “stadium” for students to test and build their practical cybersecurity skills. It also provides “scouting reports” that students can use with potential employers.
  • picoCTF: Hosted by Carnegie Mellon University, this is a free, beginner-friendly online CTF competition for middle and high school students. It has an interactive storyline and is a great learning tool

For team-based and specialized skills

  • Global Cyberlympics: This competition goes beyond a standard CTF by challenging teams in a broad scope of IT security areas, such as penetration testing, forensics, and malware analysis. It is open to professionals globally.
  • Capture the Flag (CTF) Series: Many universities and organizations host CTF competitions throughout the year. Websites like CTFtime track and rank these events, which can range from jeopardy-style puzzles to full-scale attack-and-defense scenarios. Teams from elite hacking groups and top universities often compete in these to prove their skills.
  • US Cyber Challenge (USCC): This series of online competitions and summer camps offers participants the chance to test their skills in a variety of information security realms, with challenges ranging from beginner to advanced. 

Web Links

Major International & National Competitions

Competition Name LevelFormat & FocusFrequency
DEF CON CTFAdvancedWorld-renowned CTF, the “Olympics” of hacking contests, with diverse and complex challenges.Annual
International Cybersecurity Challenge (ICC)Advanced (National teams)Top talent from global regions compete in CTF and Attack/Defense scenarios.Annual
Global CyberLympicsProfessionalInternational competition for professionals, involving various infosec challenges.Annual
National Collegiate Cyber Defense Competition (NCCDC)CollegiateA prominent Red Team vs. Blue Team event focusing on real-world defense and incident response scenarios.Annual
CyberPatriotHigh School/Middle SchoolFocuses on hardening virtual operating systems and defensive skills.Annual
National Cyber League (NCL)High School/CollegeBiannual competition with jeopardy-style challenges covering a broad range of security topics.Biannual
Collegiate Penetration Testing Competition (CPTC)CollegiateFocuses on professional penetration testing, reporting, and improving the security posture of a simulated business.Annual
DOE CyberForce CompetitionCollege/ProfessionalCenters on securing critical infrastructure systems, blending hands-on cyber education with real-world scenarios.Annual
US Cyber Challenge (USCC): Cyber QuestsAll LevelsA series of online quests with varying difficulty levels, focusing on analysis, forensics, and vulnerability identification.Spring (annually

Wikipedia

A team competing in the CTF competition at DEF CON 17

In computer security, Capture the Flag (CTF) is an exercise in which participants attempt to find text strings, called "flags", hidden in intentionally vulnerable programs, websites, devices, or other systems. CTFs are used for competitive and educational purposes. In the two most common formats, participants either solve stand-alone challenges provided by the organizers (jeopardy-style CTFs) or defend their own systems while attempting to steal flags from other participants (attack-defense CTFs). Mixed competitions combine elements of both formats.[1] Competitions may be held online or in person, may include hardware and physical-security tasks, and may be designed for beginners or experienced participants. The name is derived from the outdoor game of the same name. CTFs are widely used to develop, practice, and assess cybersecurity skills in academic, professional, and recreational settings.[2]

Overview

The first widely recognized cybersecurity CTF was held at DEF CON in 1996. Early DEF CON competitions used custom vulnerable services on a shared system and primarily tested offensive security skills; later attack-defense competitions required teams to protect their own services while attacking identical services operated by other teams.[3][4]

The two most common formats are jeopardy and attack-defense.[2] In a jeopardy CTF, teams solve independent challenges worth a fixed or dynamically adjusted number of points. Common categories include cryptography, digital forensics, web exploitation, binary exploitation, and reverse engineering.[2][5] Solving a challenge reveals a flag that is submitted to a scoring system. In an attack-defense CTF, teams are given equivalent vulnerable services and must keep their own services available, patch vulnerabilities, and repeatedly exploit opposing teams to obtain flags.[2] Mixed competitions combine jeopardy challenges with attack-defense targets.

CTFs can cover a broad range of technical skills, including software exploitation, password cracking, network analysis, programming, and incident response. A study of 15,963 published CTF solutions found that challenges emphasized technical topics, particularly cryptography and network security, while human-centered subjects such as social engineering and cybersecurity awareness were comparatively underrepresented.[6]

Educational applications

Presenter walks through the solution of a CTF challenge

CTFs are commonly used in cybersecurity education because they combine hands-on exercises with competition and gamification. Reviews of cybersecurity competitions have found that well-designed CTF activities can increase engagement and provide opportunities to practice technical problem-solving, although their educational value depends on factors such as challenge design, learner preparation, guidance, and feedback.[7][8]

Educational CTF platforms target a range of audiences. PicoCTF, organized by Carnegie Mellon CyLab, was created to introduce middle- and high-school students to computer security.[9] Pwn.college, maintained by a team at Arizona State University, provides free challenge-based material and supports parts of the university's cybersecurity curriculum.[10]

CTF-style exercises have also been integrated into university courses.[11][12] One documented example used jeopardy-style CTF assignments in an introductory information-security course at the National University of Singapore.[13]

CTF and related cyber-range exercises are also used by military academies and government training programs. The National Security Agency's NSA Cyber Exercise is a year-round education and training program that culminates in a competition for students from United States service academies and military colleges.[14]

Competitions

Many organizers register competitions with the CTFtime platform, which maintains an event calendar, archives challenges and write-ups, and calculates seasonal ratings for teams and events.[15][16]

Community competitions

LakeCTF Finals 2026 event @ EPFL

CTFs are organized by security conferences, universities, companies, and independent community teams. Conference-associated events include the DEF CON CTF, HITCON CTF, competitions held at Security BSides events, and SANS Institute NetWars tournaments.[2][17]

The DEF CON CTF is one of the longest-running major CTF competitions. It has been described by media outlets as the "World Series of hacking"[18] and the "Olympics of hacking".[19] Teams generally qualify through a separate qualification event before competing in the in-person finals. In 2026, DEF CON selected the Benevolent Bureau of Birds to organize the competition for a four-year term. The group brings together members of Carnegie Mellon University's Plaid Parliament of Pwning, the University of British Columbia's Maple Bacon, and The Duck, a team associated with the cybersecurity company Theori.[20] Before becoming organizers, the three groups competed together as Maple Mallard Magistrates and won four consecutive DEF CON CTF titles from 2022 through 2025.[21] Plaid Parliament of Pwning had participated in nine winning DEF CON CTF teams overall by 2025, the most in the competition's history.[22]

The New York University Tandon School of Engineering hosts Cybersecurity Awareness Worldwide (CSAW), a student-run cybersecurity event whose competitions include a jeopardy-style CTF. The 2021 qualification round recorded more than 1,200 teams with at least one point.[23][24]

Many community teams are associated with universities and organize their own events. Examples include Carnegie Mellon University's Plaid Parliament of Pwning and the University of California, Santa Barbara team Shellphish, which has organized the International Capture The Flag competition.[25][26]

Some community events are online and open to a broad audience. Examples include the SANS Holiday Hack Challenge, which combines guided cybersecurity exercises with a CTF track, and TryHackMe's beginner-oriented Advent of Cyber challenge series.[27][28]

Government-supported competitions

Government-supported competitions include the DARPA Cyber Grand Challenge, in which autonomous systems played a machine-only CTF in 2016, and the ENISA-supported European Cybersecurity Challenge.[29][30]

In 2023, the United States Space Force-sponsored Hack-A-Sat 4 finals used Moonlighter, an operational satellite in low Earth orbit. Space Systems Command described it as the first CTF hacking competition conducted on an operational satellite.[31]

Corporate-supported competitions

Corporations and other organizations use CTFs for workforce training, recruitment, and skills evaluation, as well as sponsor public competitions.[32] Google, for example, operates a public online jeopardy competition and related experimental events.[33]

Artificial intelligence and the decline of traditional CTFs

The increasing ability of large language model-based systems to solve cybersecurity challenges has prompted debate over the future of capture-the-flag competitions, particularly the jeopardy format. AI agents can analyze challenge files, invoke security tools, generate and test exploits, retrieve flags, and produce written explanations with limited human involvement. In a 2026 study of 41 participants in a live, on-site CTF, competitors delegated increasingly large subtasks to an AI assistant as the event progressed; when four autonomous agents were separately evaluated on the same previously unreleased challenges, the best-performing agent placed second overall and outperformed most participating human teams.[34]

Competitive teams have also developed specialized CTF-solving systems. Squid Proxy Lovers, one of the first to develop an agent, reported that its Squid Agent framework solved 46 of 50 challenges in the CTFTiny benchmark, while remaining less reliable on novel, large, or long-context challenges.[35]

The adoption of these systems has raised questions about what conventional leaderboards measure. Participants may obtain flags or complete solutions without understanding the underlying vulnerability, and differences in access to models, computing resources, or inference budgets may influence results. Researchers studying AI-assisted cybersecurity competitions have proposed measures such as separate autonomy levels, traceable submissions containing agent logs or code, and scoring criteria designed for human & AI collaboration.[36]

Competition organizers have responded through restrictions and disclosure requirements. The rules for the 2026 DEF CON CTF Qualifier prohibited fully or primarily autonomous teams but allowed human competitors to use large language model-based tools when humans remained meaningfully involved in directing the work.[37] Teams classified their AI use as No AI, Low AI, or Human-Led AI, with those classifications displayed on the public scoreboard.[37][38]

Alongside conventional jeopardy challenges, the qualifier included King of the Hill (KoTH) and LiveCTF challenges. These formats repeatedly evaluated submitted programs or strategies instead of awarding points only when a team retrieved a single static flag.[39]

In July 2026, OtterSec, a blockchain security auditing company, announced the Save CTFs Fund, a US$100,000 initiative supporting experiments with competition formats intended to remain meaningful as AI capabilities increase.[40][41] The company argued that conventional jeopardy scoring could increasingly reflect available inference budgets and advocated formats that compare the performance of exploits, defensive patches, bots, or strategies over multiple rounds.[41]

OtterSec described the resulting community discussion as including declarations of the "death of CTFs".[41] The debate more specifically concerns whether traditional human-focused jeopardy scoring remains an effective measure of cybersecurity skill. AI-use disclosures, restrictions on autonomous teams, and continuously evaluated formats indicate that some organizers are adapting CTFs rather than abandoning them.

  • In Mr. Robot, a CTF tournament is depicted in the third-season premiere, "eps3.0_power-saver-mode.h". The technical advisers for the series said the scene was based on real-world CTF events and used a challenge adapted from a previous security competition.[42]
  • In The Undeclared War, a CTF is depicted in the opening scene as a recruitment exercise used by GCHQ.[43]
  • Go Go Squid!, a Chinese television series, centers partly on characters training for and competing in fictionalized international cybersecurity competitions.[44]

See also

References

  1. "What is Capture The Flag?". CTFtime. Retrieved 16 July 2026.
  2. 1 2 3 4 5 European Union Agency for Cybersecurity (10 May 2021). Contemporary Practices and State-of-the-Art in Capture-the-Flag Competitions (PDF) (Report). ENISA. ISBN 978-92-9204-501-2. Retrieved 16 July 2026.
  3. Trickel, Erik; Disperati, Francesco; Gustafson, Eric; Kalantari, Faezeh; Mabey, Mike; Tiwari, Naveen; Safaei, Yeganeh; Doupé, Adam; Vigna, Giovanni (2017). Shell We Play A Game? CTF-as-a-service for Security Education (PDF). 2017 USENIX Workshop on Advances in Security Education (ASE 17). USENIX Association. Retrieved 16 July 2026.
  4. Cowan, Crispin; Arnold, Seth; Beattie, Steve; Wright, Chris; Viega, John (April 2003). Defcon Capture the Flag: Defending vulnerable code from intense attack. Proceedings DARPA Information Survivability Conference and Exposition. Vol. 1. pp. 120–129. doi:10.1109/DISCEX.2003.1194878. ISBN 0-7695-1897-4. S2CID 18161204.
  5. Chung, Kevin; Cohen, Julian (2014). Learning Obstacles in the Capture The Flag Model. 3GSE '14: 2014 USENIX Summit on Gaming, Games, and Gamification in Security Education. USENIX Association. Retrieved 16 July 2026.
  6. Švábenský, Valdemar; Čeleda, Pavel; Vykopal, Jan; Brišáková, Silvia (March 2021). "Cybersecurity knowledge and skills taught in capture the flag challenges". Computers & Security. 102 102154. arXiv:2101.01421. doi:10.1016/j.cose.2020.102154. Retrieved 16 July 2026.
  7. Balon, Tyler; Baggili, Ibrahim (24 February 2023). "Cybercompetitions: A survey of competitions, tools, and systems to support cybersecurity education". Education and Information Technologies. 28 (9): 11759–11791. doi:10.1007/s10639-022-11451-4. ISSN 1573-7608. PMC 9950699. PMID 36855694.
  8. Vykopal, Jan; Švábenský, Valdemar; Chang, Ee-Chien (26 February 2020). Benefits and Pitfalls of Using Capture the Flag Games in University Courses. Proceedings of the 51st ACM Technical Symposium on Computer Science Education. pp. 752–758. arXiv:2004.11556. doi:10.1145/3328778.3366893. ISBN 9781450367936. S2CID 211519195.
  9. "picoCTF aims to close the cybersecurity talent gap". Carnegie Mellon CyLab. Retrieved 16 July 2026.
  10. "pwn.college". pwn.college. Retrieved 16 July 2026.
  11. McDaniel, Lucas; Talvi, Erik; Hay, Brian (January 2016). Capture the Flag as Cyber Security Introduction. 2016 49th Hawaii International Conference on System Sciences. pp. 5479–5486. doi:10.1109/HICSS.2016.677. ISBN 978-0-7695-5670-3. S2CID 35062822.
  12. Leune, Kees; Petrilli, Salvatore J. (27 September 2017). Using Capture-the-Flag to Enhance the Effectiveness of Cybersecurity Education. Proceedings of the 18th Annual Conference on Information Technology Education. Association for Computing Machinery. pp. 47–52. doi:10.1145/3125659.3125686. ISBN 978-1-4503-5100-3. S2CID 46465063.
  13. Vykopal, Jan; Švábenský, Valdemar; Chang, Ee-Chien (26 February 2020). Benefits and Pitfalls of Using Capture the Flag Games in University Courses. Proceedings of the 51st ACM Technical Symposium on Computer Science Education. pp. 752–758. arXiv:2004.11556. doi:10.1145/3328778.3366893. ISBN 9781450367936. S2CID 211519195.
  14. "NSA Cyber Exercise (NCX)". National Security Agency. Retrieved 16 July 2026.
  15. "CTFtime". CTFtime. Retrieved 16 July 2026.
  16. "CTFtime FAQ". CTFtime. Retrieved 16 July 2026.
  17. "SANS Cyber Ranges". SANS Institute. Retrieved 16 July 2026.
  18. Korber, Sabrina (8 November 2013). "Cyberteams duke it out in the World Series of hacking". CNBC. Retrieved 16 July 2026.
  19. Siddiqui, Zeba (17 August 2022). "Hacker tournament brings together world's best in Las Vegas". Reuters. Retrieved 16 July 2026.
  20. "UBC competitive hacking team to organize this year's top-tier cybersecurity competition". University of British Columbia Department of Computer Science. 31 March 2026. Retrieved 16 July 2026.
  21. "UBC wins fourth consecutive time at world-renowned "Capture the Flag" hacking competition". University of British Columbia Department of Computer Science. 29 August 2025. Retrieved 16 July 2026.
  22. "Carnegie Mellon's Hacking Team Wins Fourth Straight, Record Ninth Overall DEF CON Capture-the-Flag Title". Carnegie Mellon University. 11 August 2025. Retrieved 16 July 2026.
  23. "CSAW". New York University. Retrieved 16 July 2026.
  24. "CSAW'22 Cybersecurity Games & Conference". New York University Abu Dhabi. Retrieved 16 July 2026.
  25. "Carnegie Mellon's Hacking Team Wins Fourth Straight, Record Ninth Overall DEF CON Capture the Flag". Carnegie Mellon University. 11 August 2025. Retrieved 16 July 2026.
  26. "iCTF: the International Capture The Flag Competition". University of California, Santa Barbara. Retrieved 16 July 2026.
  27. "Holiday Hack Cybersecurity Challenge 2025". SANS Institute. Retrieved 16 July 2026.
  28. "Advent of Cyber 2025". TryHackMe. Retrieved 16 July 2026.
  29. "Cyber Grand Challenge". Defense Advanced Research Projects Agency. Retrieved 16 July 2026.
  30. "European Cybersecurity Challenge". European Cybersecurity Challenge. Retrieved 16 July 2026.
  31. "Global teams of security researchers compete in first-ever capture-the-flag hacking competition in space" (PDF). Space Systems Command. 14 August 2023. Retrieved 16 July 2026.
  32. Cherinka, Robert (2018). "Using Cyber Competitions to Build a Cyber Security Talent Pipeline and Skilled Workforce". Advances in Intelligent Systems and Computing. Springer. pp. 280–289. doi:10.1007/978-3-030-01177-2_20.
  33. "Google CTF". Google. Retrieved 16 July 2026.
  34. Tang, Tingxuan; Janis, Nicolas; Montague, Kalyn Asher; Eykholt, Kevin; Kirat, Dhilung; Park, Youngja; Jang, Jiyong; Nadkarni, Adwait; Xiao, Yue (2026). "Understanding Human-AI Collaboration in Cybersecurity Competitions". arXiv:2602.20446 [cs.CR].
  35. "Squid Agent – A Multi-Agent CTF Auto Solver". Squid Proxy Lovers. 18 November 2025. Retrieved 16 July 2026.
  36. Xi, Haoran; Shao, Minghao; Milner, Kimberly; Putrevu, Venkata Sai Charan; Rani, Nanda; Udeshi, Meet (2026). "AI In Cybersecurity Education—Scalable Agentic CTF Design Principles and Educational Outcomes". arXiv:2603.21551 [cs.CR].
  37. 1 2 "Birding Rules – DEF CON CTF Quals 2026". Benevolent Bureau of Birds. Retrieved 16 July 2026.
  38. "Scoreboard – DEF CON CTF Quals 2026". Benevolent Bureau of Birds. Retrieved 16 July 2026.
  39. Suehiro (5 June 2026). "DEF CON CTF Qualifier 2026 参加記" [Participation report for the DEF CON CTF Qualifier 2026]. NF Labs Engineering Blog (in Japanese). Retrieved 16 July 2026.
  40. "OtterSec". OtterSec. Retrieved 16 July 2026.
  41. 1 2 3 Debono, Michael (7 July 2026). "Announcing the Save CTFs Fund". OtterSec. Retrieved 16 July 2026.
  42. Kazanciyan, Ryan (30 September 2020). "Mr. Robot Disassembled: eps3.0_power-saver-mode.h". Medium. Retrieved 16 July 2026.
  43. Woodward, Alan (7 July 2022). "'Some staff work behind armoured glass': a cybersecurity expert on The Undeclared War". The Guardian. ISSN 0261-3077. Retrieved 16 July 2026.
  44. "Former child star follows 'destiny'". China Daily. 17 July 2019. Retrieved 16 July 2026.
  • CTFtime – an archive and calendar of past, current, and upcoming CTF competitions.

    Discuss

    OnAir membership is required. The lead Moderator for the discussions is Cyber Curators. We encourage civil, honest, and safe discourse. For more information on commenting and giving feedback, see our Comment Guidelines.

    This is an open discussion on the contents of this post.

    Home Forums Open Discussion

    Viewing 1 post (of 1 total)
    Viewing 1 post (of 1 total)
    • You must be logged in to reply to this topic.
    Skip to toolbar