Skip to content
CyberCTF

Command Palette

Search for a command to run...

Documentation

Contributing labs

How CyberCTF labs are built, published and kept honest.

Every lab lives in its own public repository in the CyberCTF organization.

Anatomy of a lab

  • docker-compose.yml: the lab's services, including the evidence service that fetches the player's evidence at startup;
  • lab.json: public metadata: title, category, difficulty, the evidence kind and its development value;
  • tests/: automated tests proving the vulnerability is exploitable and the evidence reachable only through it.

Rules every lab follows

  • Realism first: a plausible company, a plausible system, one vulnerability.
  • Evidence, not magic strings: the proof is real business data, placed at runtime and reachable only by exploiting the lab.
  • No spoilers: nothing in the UI, logs or README hints at the vulnerability or the evidence.
  • Tested: CI runs the exploit path against the development evidence.

Publishing

When a lab is pushed to main, its workflow publishes the images and registers the lab with CyberCTF as a draft. It goes live once reviewed.