What Is a CTF in Cybersecurity? A Beginner's Guide
What is a CTF in cybersecurity? Formats, challenge categories, where to play (picoCTF, Hackropole, Root-Me, Hack The Box) and how to solve your first challenge.
A CTF (Capture The Flag) in cybersecurity is a competition in which you solve security challenges to find a "flag", a short string of text that proves you succeeded. It is the most common, and the most legal, way to learn ethical hacking, because everything you attack was built to be attacked. This guide covers the formats, the challenge categories, where to play and how to approach your first challenge.
What a CTF is: jeopardy, attack-defence and hardware
The principle never changes. The organisers hide a flag, something like flag{th1s_1s_a_fl4g}, inside a deliberately vulnerable system: a website, a program, a file, a circuit board. You find the flag, submit it on the platform and score points.
There are three main formats.
| Format | How it plays | Best for |
|---|---|---|
| Jeopardy | A board of independent challenges sorted by category and difficulty. Each one is worth points. | Beginners, solo or in a team |
| Attack-defence | Every team gets the same infrastructure. You defend your services while attacking everyone else's. | Experienced teams, high-level events |
| Hardware / physical | The challenges live inside an object: a circuit board, a tag, a radio beacon. Sometimes you take it home. | Electronics-curious players who want to get away from the screen |
Jeopardy CTFs usually last from a few hours to about ten days. Many platforms keep their challenges online all year round, so you can practise without waiting for a competition.
There are variants too: OSINT CTFs (Open Source Intelligence, investigating from public information), "king of the hill" games where you take and hold a machine, and realistic labs that simulate a real penetration test rather than a series of puzzles.
Challenge categories explained
In a jeopardy CTF, challenges are grouped into categories. The names vary a little between platforms, but these show up almost everywhere.
| Category | What you do | Typical beginner tools |
|---|---|---|
| Web | Find a flaw in a website: SQL injection, broken access control, a cookie you can edit | Browser dev tools, Burp Suite Community |
| Crypto | Break badly used encryption, recover a weak key | Python, CyberChef |
| Reverse engineering | Understand a compiled program to find out what it checks | Ghidra, strings, a debugger |
| Pwn | Exploit a memory bug (a buffer overflow) to take control of a program | GDB, pwntools |
| Forensics | Analyse a disk image, a network capture or a memory dump | Wireshark, Volatility, binwalk |
| Steganography | Find a message hidden in an image or a sound file | Dedicated tools, a hex editor |
| OSINT | Find a piece of information from public sources | Search engines, metadata |
| Hardware | Decode a signal, read a memory chip, analyse a serial bus | Logic analyser, SDR, NFC reader |
| Misc | Everything else: programming, logic, riddles | Whatever comes to mind |
One piece of advice: pick a category and stick with it for a few weeks. Web and forensics tend to be the most approachable because they need few prerequisites. Pwn and reverse engineering need more low-level programming background.
Where to play
Practice platforms, open all year
- picoCTF: Carnegie Mellon University's free platform, originally designed for secondary-school and university students. Its practice challenges are among the most beginner-friendly anywhere.
- TryHackMe: heavily guided learning paths, ideal for a very first contact. Part of it is free, the rest is subscription-based.
- Hack The Box: machines to compromise and challenges by category, with a free tier and paid plans. A step up from TryHackMe.
- Hackropole: run by ANSSI, the French national cybersecurity agency. It hosts more than 600 challenges from past editions of the French national CTF, with published solutions and a hardware category. Mostly in French, but the challenges themselves are often easy to follow.
- Root-Me: the long-standing French community platform, free, with several hundred challenges and an English interface.
- CyberCTF: our sister platform. It offers free, open-source, realistic pentest labs that you run on your own machine or server. Rather than a string of puzzles, you break into a simulated company system, as you would on a real engagement.
Competitions
Use CTFtime to find upcoming online competitions. It lists events, team rankings and a large archive of write-ups.
In Europe, national qualifiers feed into the European Cybersecurity Challenge (ECSC). In France, the qualifier is the FCSC, run by ANSSI every spring as a ten-day individual jeopardy CTF; the 2026 edition ran from 3 to 12 April, with challenges from beginner to expert level, hardware included. In-person events such as BreizhCTF in Rennes and leHACK in Paris are worth the trip if you can read a bit of French. Check your own country's national team selection if you are elsewhere in Europe.
Universities and clubs
Many universities have a student CTF team. If you are a student, that is often the easiest way in: ask your computing society.
Your first CTF, step by step
This method works whether you play on picoCTF, Hackropole or Root-Me.
- Set up a workspace. A Linux virtual machine (Kali or a plain Debian) keeps your main computer clean. Install Python, a text editor and a browser.
- Start with the 1- or 2-star challenges. Aim for three easy challenges in one category rather than one hard one.
- Read the description twice. Hints often hide in the title, the file name or an innocent-looking sentence.
- Write everything down. What you tried, what failed, which commands you ran. These notes become your first write-ups, the solution reports players publish after a CTF.
- Set a time limit. After an hour with no progress, look for a hint or move on. Getting stuck is not failure, it is the game.
- Read other people's solutions afterwards. This is where most of the learning happens: you discover the tool or trick you didn't know.
A few first reflexes for any file-based challenge:
file challenge.bin # what kind of file is it?
strings -n 6 challenge.bin # any readable text inside?
binwalk challenge.bin # files embedded in files?
These three commands solve a surprising number of easy forensics and reverse engineering challenges. If you would rather follow a structured path, our post on learning ethical hacking by playing lays out a three-month plan.
A reminder on the legal side: a CTF is legal because the organiser authorises you to attack their targets. Outside that frame, unauthorised access to a computer system is a criminal offence across Europe, for instance under article 323-1 of the French Penal Code or the UK's Computer Misuse Act 1990. You learn the skills here, and use them elsewhere only with written permission.
Physical CTFs: when the challenge fits in a box
Most CTFs are played on a screen. Yet a good part of real-world security lives in hardware: the radio in a remote control, the chip in a badge, the memory in a router. Hardware challenges appear in the big competitions, but they are rare at home, because you need a physical object to play.
That is the idea behind the CTF puzzles we design in France: the flag is hidden in something you hold in your hand. A Bluetooth beacon broadcasting an encoded message, a box of NFC tags played like an escape room, or a board with a memory chip to read, like the Firmware Dump, planned for 2028 with its USB programmer included. Each puzzle has three honestly labelled levels and nothing to solder, and the official solution is published 60 days after delivery so nobody stays stuck forever.
Hardware CTFs do need a little kit. A logic analyser, an SDR receiver or an NFC reader covers most beginner-level challenges. For a tour of the challenge families, read our post on hardware CTF challenges.
Where to go next
The easiest start is a free platform such as picoCTF or Hackropole, followed by a first online competition picked from CTFtime. If a challenge you can hold in your hand appeals to you, have a look at our physical CTF puzzles and join the waitlist. And if you are shopping for someone who already plays, our gift guide for CTF players collects the ideas that make sense.
Frequently asked questions
Do I need to know how to code to play a CTF?
Not to get started. Beginner challenges can be solved with a browser, a terminal and curiosity. Writing small Python scripts soon becomes useful for automating the boring parts, and CTFs are a good reason to learn.
Are CTFs legal?
Yes. A CTF is an environment built to be attacked, and the organisers explicitly allow you to do so. The limit is scope: you only attack the targets you are given, never the platform's infrastructure or other players, and you don't use the techniques anywhere else without permission.
How long does it take to get good at CTFs?
There is no fixed timeline. A few hours a week on a practice platform is enough to start solving easy challenges within a few weeks. What makes the difference is regular practice and reading write-ups after every challenge, solved or not.
What is a hardware CTF?
A CTF whose challenges are about physical hardware: a radio signal to decode, an NFC tag to read, a memory chip to dump, a serial port to find on a circuit board. The flag is hidden in the object rather than on a server.