CTF Knowledge Index
A minimal field manual for Capture The Flag beginners. Browse categories, read guides, and find essential tools — all in one place.
categories
view all →Web Exploitation
Attack web applications — injection, authentication flaws, and client-side bugs that turn a browser into a weapon.
Cryptography
Break weak ciphers, exploit bad randomness, and recover keys from flawed cryptographic implementations.
Reverse Engineering
Disassemble and decompile binaries to understand what they do and extract hidden logic or flags.
Binary Exploitation
Exploit memory-corruption bugs — buffer overflows, format strings, and use-after-free — to hijack execution.
Forensics
Recover hidden data from files, disk images, memory dumps, and network captures.
OSINT
Use open-source intelligence — public records, metadata, and social media — to track down information.
Networking
Analyze traffic captures and protocols to extract flags and understand attacks.
Miscellaneous
Everything that does not fit a neat box — scripting puzzles, esoteric formats, and jeopardy oddities.
New to CTF?
Start with the web category — it covers the most common beginner challenges.
Support hackref
Give a star on GitHub if you find this field manual helpful!