Skip to contentHacker gift guide · Christmas 2026

Learn Ethical Hacking by Playing: CTFs, Puzzles and Games

Learn ethical hacking by playing: free CTF platforms, video games that genuinely teach, physical puzzles and a 3-month plan to become self-sufficient.

Published on 7 min read

Yes, you can learn ethical hacking by playing, and it is how most professionals say they got started. CTFs, programming games and physical puzzles give you a clear goal, instant feedback and an unambiguous legal frame. Here are the options ranked by what they actually teach, plus a three-month plan to go from curious to self-sufficient.

Why games beat lectures

A security course explains what SQL injection is. A CTF puts a login form in front of you and lets you work it out. The difference comes down to three things.

  • A clear goal. Find the flag. You know when you have succeeded, without waiting for someone to mark your work.
  • Measured difficulty. Challenges are ranked from easy to hard, so you stay in the zone where you are stuck a little, but not too much.
  • A clean legal frame. Everything you attack was built to be attacked. Outside that frame, unauthorised access to a computer system is a criminal offence, under the UK's Computer Misuse Act 1990 or article 323-1 of the French Penal Code, for example.

Games have one limit: they reward puzzle-solving, whereas a real penetration test also takes method, rigour and a written report. Good learning paths therefore mix games with realistic practice. For the basics of the format, our guide what is a CTF walks through the challenge categories.

Free online platforms

PlatformLanguagePriceWhat you actually learnBest for
picoCTF (Carnegie Mellon)EnglishFreeVery well-explained challenges designed for school and university studentsComplete beginners
OverTheWireEnglishFreeThe "Bandit" wargame teaches the Linux command line one level at a timeFirst steps in a terminal
TryHackMeEnglishFree tier, subscriptionHeavily guided paths, from basics to pentestingBeginners who like guidance
Hack The BoxEnglishFree tier, subscriptionFull machines to compromise, challenges by categoryIntermediate players
CyberCTFEnglishFree, open sourceRealistic pentest labs that run on your machine: break into a simulated company systemPlayers moving from puzzles to real-world method
Hackropole (ANSSI)Mostly FrenchFree600+ challenges from past French national CTFs, with solutions, hardware includedBeginner to expert
Root-MeFrench, EnglishFreeSeveral hundred challenges by category, active communityBeginner to expert

If you only pick one to start, take picoCTF: the challenges are gentle and well written. OverTheWire's Bandit is the best way to get comfortable with a terminal, which everything else assumes.

CyberCTF, our sister platform, plays a different role. Instead of a string of puzzles, it offers labs that feel like a real engagement: a company system to compromise, with a different secret for every player so write-ups can't do the work for you. It is a good step after a few weeks of classic CTFs.

Hacking video games that teach something real

Plenty of "hacker" games only show green text scrolling past. A few teach real concepts.

GameWhat it really teachesWhat it doesn't
TIS-100 (Zachtronics)Assembly programming, thinking in registers and cyclesSecurity as such
Shenzhen I/O (Zachtronics)Building circuits with microcontrollers and reading datasheets, the core skill of hardware hackingReal-world parts
Turing CompleteBuilding a computer from logic gates, up to writing your own assemblerAttacks
NandGameThe same idea, free in the browserAttacks
BitburnerJavaScript programming to automate a fictional networkReal intrusion techniques
HacknetCommand-line vocabulary and atmosphereSkills you can reuse directly

Programming games are underrated. Understanding how a processor runs an instruction helps enormously with reverse engineering and binary exploitation. Shenzhen I/O in particular trains you to read technical documentation, which is what you will do constantly in front of a circuit board.

Story games like Hacknet have a different value: motivation. That counts, as long as you don't mistake them for training.

Physical puzzles and escape rooms

Screens only tell part of the story. Access badges, remote controls and connected devices rely on radio and electronics, and these are easier to learn with an object in your hand.

Commercial "cyber escape rooms" are mostly awareness tools: you learn to spot a password on a sticky note or a phishing email. Useful for a non-technical team, less so if you want to actually learn.

Physical CTF puzzles go further: the flag is hidden in the object, and getting it takes a real technical step. That is the idea behind our puzzles, designed in France. The NFC Escape Tag, planned for Christmas 2027, hides five NFC tags in a box, each leading to the next: the first ones read with a phone, the last one needs a dedicated reader such as the Proxmark3. Each puzzle has three honestly labelled levels and nothing to solder, and the official solution is published 60 days after delivery.

These formats work well as a group too: one person reads the tags, another takes notes, a third looks for the logic.

A 3-month learning plan

Here is a realistic plan at three to five hours a week. It assumes no prior knowledge.

Month 1: the basics

  • Weeks 1 and 2. OverTheWire Bandit, roughly levels 0 to 15. Goal: feel at home in a Linux terminal.
  • Week 3. Your first easy challenges on picoCTF, in the web and forensics categories.
  • Week 4. A session of NandGame or Turing Complete on the side, to understand what happens under the hood.

Month 2: pick a specialty

  • Choose one category (web, crypto or forensics) and solve ten challenges in it.
  • Write a short write-up for every challenge you solve, even if only you will read it. It is the best way to remember.
  • Enter your first online competition from CTFtime, without worrying about the rankings.

Month 3: beyond puzzles

  • Complete a realistic lab on CyberCTF or an easy machine on Hack The Box, and write a short report as if for a client.
  • Open the hardware door: a radio receiver, a hardware challenge on Hackropole, or a physical puzzle.
  • Find an in-person event, such as a university CTF or your country's national qualifier for the European Cybersecurity Challenge, and sign up.

After three months you won't be an expert, but you will know how to teach yourself, and that is the skill that matters.

Keep going

Play remains the best engine for learning security, as long as you vary the formats: online CTFs for method, programming games for foundations, and physical objects to get your hands on hardware. If that last part appeals, have a look at our physical CTF puzzles and join the waitlist. To give this kind of challenge to someone else, our gift guide for CTF players will help you choose.

Frequently asked questions

Can you learn ethical hacking for free?

Yes. picoCTF, OverTheWire, Hackropole and Root-Me are free, and TryHackMe and Hack The Box both have free tiers. You can make months of progress without spending anything. Hardware only becomes useful once you want to explore radio, NFC or electronics.

Do hacking video games actually teach anything?

Some do. Programming games such as TIS-100, Shenzhen I/O or Turing Complete teach assembly and circuit logic. Story games such as Hacknet mostly give you the vocabulary and the motivation, not skills you can reuse directly.

How young can you start?

Platforms built for schools, such as picoCTF, target secondary-school students. Logic games such as NandGame work for anyone who enjoys puzzles. The key is to set the rule from day one: you only attack what was built to be attacked.

Related articles

What is a CTF in cybersecurity? Formats, challenge categories, where to play (picoCTF, Hackropole, Root-Me, Hack The Box) and how to solve your first challenge.
Hardware CTF challenges explained: radio, NFC, BLE, serial buses, firmware and side-channel. Public write-ups worth reading and the minimum kit to take part.
Free resources to learn hardware hacking: books, YouTube channels, CTF platforms (Hackropole, Microcorruption, RHme), European conferences and a 3-month plan.