About

Why this exists

There is a gap between finishing a cybersecurity course and being able to do the job. This event is an attempt to close a little of it in one Saturday morning.

The gap

Cybersecurity programs teach the vocabulary well. Students can define the kill chain, name the CIA triad, and explain what a threat actor is. That knowledge is real and it matters.

What almost nobody gets before their first job is the experience of sitting in front of a pile of evidence from a system they did not build, knowing something bad happened, and having to work out what. That skill is not on most syllabi, and it is close to the whole job in a security operations center.

So we built the thing that teaches it. One incident, four hours, real evidence, and no way through except by looking carefully.

What makes this different

Most capture-the-flag events are offensive. You break into a machine, you get a flag. They are fun, and they teach real skills, but they train the smaller half of the profession. Far more people get hired to defend than to attack.

This one runs the other way. We stand up a fictional company, complete with employees, their normal working day, and their normal noisy network traffic. Then we attack it ourselves using techniques taken from campaigns that have genuinely happened. We capture everything the company's systems recorded while it was going on.

That recording is what you get. Your team's job is to reconstruct the incident from it, the way a real analyst would, and then report on it the way a real analyst has to.

The write-up matters as much as the flags

Every team submits a short incident report structured on the SANS PICERL model: Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned. Judges from local industry and from both campuses read them.

That is deliberate. Finding the answer fast is a skill. Explaining what happened to someone who has to make a decision about it is a different skill, and it is the one that turns an analyst into someone worth promoting. Scores and write-ups together decide the winners.

Who is behind it

The event is a joint effort between Pima Community College, the University of Arizona, Tucson Electric Power, and Recorded Future. Public sector, private sector, and academia, which is roughly how the actual security community in this city works.

Everything is built and run by volunteers: working security practitioners, faculty, and students. Nobody is paid for this. It is free to attend because the partner organizations cover it.

Built by the people who play it

The environment, the fake company, the challenge questions, and the attack itself are built by a volunteer crew, and a lot of them are students. If you want to help, you are wanted. You do not need to be an expert. Most of the work is small, self-contained, and genuinely useful on a resume.

The one rule is that you cannot compete in an event you helped build. In exchange, builders get first shot at running the attack side next time, which is the more interesting job anyway.