Tucson, Arizona
A company just got breached. You have four hours and a pile of evidence. Work out what happened.
A capture-the-flag competition, but not the kind where you break into things. You play the defender. We build a fake company, we attack it on purpose, and we record everything its computers saw while it happened. On event day you get those records and work out the story: who got in, how, what they touched, and what they took.
This is the job real security teams do. Sift the evidence, follow the trail, and prove what happened. No prior CTF experience needed.
Come with a team or get placed on one. Everyone contributes, and the questions are built so newcomers can score early and often.
Flags earn points during the event. Afterward each team submits a short incident report using the SANS PICERL model. Both decide the winners.
Doors at 7:30am, competition from 8:00am to 12:00pm. Exact block times get confirmed closer to the date.
Short answer: you do not need to do anything. Longer answer, if you want an edge:
Any laptop with a web browser works. Windows, Mac, Linux, Chromebook. Nothing to install, and no VPN client to set up. You will get a link and a login.
If you know what a Windows event log is and roughly what the stages of an attack look like, you are in good shape. If not, that is what the warm up round is for.
We will post a small practice case and a walkthrough in the Discord a couple of weeks before the event. Optional, but the people who do it tend to carry their teams.
Come with up to five people, or show up alone and we will place you. Team matching happens in the Discord.
This event is free because these organizations back it. It is a public, private, and academic effort to grow cyber talent in Southern Arizona.
The Discord is where team matching, practice material, and every announcement happens. Scan it or click it.
discord.gg/XrESn2t8rk
Great. Join the Discord anyway. That is where you will find teammates, the optional practice case, and the answers to questions you have not thought of yet.
We need people to help build the environment, write challenge questions, and create the fake company. It is genuinely good resume material, and you get first shot at running the attack side next year.
If yours is not here, ask in the Discord.
No. The challenges are tiered. The early ones tell you exactly where to look, and they get harder from there. Plenty of teams will be first timers.
Anyone. The event is built for students first, and the difficulty is tuned for people early in their cyber education. Professionals, educators, and industry partners are genuinely welcome too, and plenty will be in the room.
No. Bring up to four teammates, or come solo and we will put you on a team.
A laptop and a charger. Everything runs in a web browser, so there is nothing to install beforehand.
Yes, and so is parking. Registration is required so we know how many seats and how much food to plan for.
Pima Community College East Campus, 8181 East Irvington Road, Tucson, AZ 85730. Doors at 7:30am.
Not this year. You are on the defending side, investigating an attack we already ran. A live attack track is something we are looking at for future events.
Yes, and we would love the help. Building the environment is genuinely good resume material. Builders cannot compete in the event they helped create, but they get first shot at running the attack side next time. Come say hello in the Discord.