Skip to content
CyberCTF

Command Palette

Search for a command to run...

Documentation

Evidence, not flags

Why labs end with real business data, and why your evidence is unique to you.

A real pentest doesn't end with CTF{...}. It ends with a piece of evidence that proves impact to the client: the finance analyst's credentials, a customer's IBAN, next month's payroll total. CyberCTF labs work the same way.

Unique to you

Every lab is a public repository, so the evidence can't live in it. When you start a lab from the launcher:

  1. the launcher asks CyberCTF for a single-use launch token for you;
  2. the lab starts and exchanges that token for your evidence;
  3. the lab places it where it belongs in its data: a user account, an invoice, a vault entry.

The evidence always has a realistic business form (a valid IBAN, a strong password, an amount in the right range), but its value is generated for you. A value copied from someone else's writeup won't complete the lab for you.

Running a lab without the launcher

You can always clone a lab and run it with Docker Compose. Without a launch token it uses its public development evidence: perfect for practice and for contributors, but it can't complete the lab on your account.

No points, no leaderboard

CyberCTF is about practice. A lab is either completed or not; there are no points to farm.