A collection of my CTF (Capture The Flag) challenge writeups. Each writeup documents my methodology, tools used, thought process, and key takeaways. Written to reinforce learning and help others in the community.
A Capture The Flag (CTF) is a cybersecurity competition or challenge where you solve puzzles to find hidden "flags" — usually strings like flag{s0m3_s3cr3t_t3xt}. They're one of the best ways to build real, hands-on security skills.
| Category | What You Do |
|---|---|
| Web | Find vulnerabilities in websites (SQLi, XSS, IDOR, etc.) |
| Forensics | Analyze files, memory dumps, packet captures |
| Cryptography | Break or decode ciphers and encryption |
| Reverse Engineering | Analyze compiled binaries to understand what they do |
| Pwn / Binary Exploitation | Exploit memory vulnerabilities (buffer overflow, etc.) |
| OSINT | Find information using open-source intelligence techniques |
| Steganography | Find data hidden inside images, audio, or other files |
| Miscellaneous | Anything that doesn't fit neatly elsewhere |
Start here → TryHackMe (most beginner-friendly, guided learning paths)
| Platform | Difficulty | Best For | Cost |
|---|---|---|---|
| TryHackMe | Beginner → Intermediate | Guided rooms, learning paths | Free + Paid |
| PicoCTF | Beginner | Pure CTF challenges, great for learning | Free |
| Hack The Box | Intermediate → Advanced | Machines, realistic scenarios | Free + Paid |
| CTFtime.org | Varies | Live competitions, find upcoming CTFs | Free |
| Blue Team Labs Online | Beginner → Intermediate | Defensive/SOC-focused challenges | Free + Paid |
Month 1 — TryHackMe Beginner Rooms
- Complete Beginner Path — Linux basics, networking, web fundamentals
- Pre-Security Path — How the internet, networks, and web apps work
- Introduction to Cybersecurity — Offensive vs defensive overview
Month 2 — PicoCTF
- Head to picoctf.org and work through the practice archive
- Start with: General Skills → Forensics → Web → Cryptography
- Each challenge has a point value — lower = easier
Month 3+ — Hack The Box & Live CTFs
- Try "Starting Point" machines on HTB (guided)
- Watch IppSec on YouTube for HTB walkthroughs
- Sign up on CTFtime.org and participate in beginner-friendly team competitions
# If using Kali Linux (recommended), most tools are pre-installed
# Key tools to know:
nmap # Network/port scanning
gobuster # Web directory brute-forcing
burpsuite # Web proxy / intercept
john / hashcat # Password cracking
binwalk # Firmware/file analysis
steghide # Steganography extraction
strings # Extract readable strings from binaries
file # Identify file types
xxd / hexdump # Hex inspection
cyberchef # Encoding/decoding (browser-based: gchq.github.io/CyberChef)Even if you needed hints or a walkthrough — document it. The writeup process forces you to truly understand what happened and builds your portfolio.
| # | Platform | Challenge / Room | Category | Difficulty | Date | Status |
|---|---|---|---|---|---|---|
| 1 | TryHackMe | Offensive Security Intro | Offensive Security | Easy | 2026-05-27 | ✅ Complete |
| 2 | TryHackMe | Careers in Cyber | Learning | Easy | 2026-05-27 | ✅ Complete |
| 3 | TryHackMe | What is Networking? | Networking | Easy | 2026-06-04 | ✅ Complete |
(Updated as challenges are completed)
Each writeup lives in its own folder. See the template below for the format used.
| Challenge | Platform | Category | Difficulty | Writeup |
|---|---|---|---|---|
| What is Networking? | TryHackMe | Networking | Easy | ✅ |
Copy this when creating a new writeup.
# [Challenge Name] — [Platform]
**Date:** YYYY-MM-DD
**Platform:** TryHackMe / PicoCTF / HTB / etc.
**Category:** Web / Forensics / Crypto / etc.
**Difficulty:** Easy / Medium / Hard
**Points:** XXX
**Flag:** `flag{REDACTED}`
---
## Challenge Description
> Paste the original challenge description here.
---
## Reconnaissance / Initial Thoughts
What did you notice first? What approach did you decide to take and why?
---
## Solution Walkthrough
### Step 1 — [What you did]
Explain your first step. Include commands you ran:
```bash
nmap -sV -sC 10.10.X.X
```What did you find? What was interesting?
Explain exactly how you captured the flag.
nmap— Port scanninggobuster— Directory enumeration
- [Takeaway 1]
- [Takeaway 2]
- [Takeaway 3]
- [Link to relevant documentation or resource]
---
## Tools Reference
### Web Exploitation
```bash
# Directory/file brute-force
gobuster dir -u http://target.com -w /usr/share/wordlists/dirbuster/directory-list-2.3-medium.txt
# Subdomain enumeration
gobuster dns -d target.com -w /usr/share/wordlists/SecLists/Discovery/DNS/subdomains-top1million-5000.txt
# SQL injection testing
sqlmap -u "http://target.com/page?id=1" --dbs
# Nikto web scan
nikto -h http://target.com
# Identify file type
file suspicious_file
# Extract strings from binary
strings suspicious_file | less
# Check file for hidden data
binwalk suspicious_image.png
# Extract hidden data from image
steghide extract -sf image.jpg
# Analyze image metadata
exiftool image.jpg
# Hex dump
xxd file.bin | head -50# Identify hash type
hashid 5f4dcc3b5aa765d61d8327deb882cf99
# Crack hash with John
john --wordlist=/usr/share/wordlists/rockyou.txt hash.txt
# Crack hash with Hashcat
hashcat -m 0 hash.txt /usr/share/wordlists/rockyou.txt
# Base64 decode
echo "aGVsbG8=" | base64 -d
# ROT13
echo "uryyb" | tr 'A-Za-z' 'N-ZA-Mn-za-m'# HTTP traffic only
http
# Follow a TCP stream — right-click a packet → Follow → TCP Stream
# Find credentials in clear text
http.request.method == "POST"
# Filter by IP
ip.addr == 10.10.X.X
# DNS queries
dns
| Tool | URL | Use |
|---|---|---|
| CyberChef | https://gchq.github.io/CyberChef | Encoding, decoding, everything |
| CrackStation | https://crackstation.net | Hash lookup |
| dCode | https://www.dcode.fr/en | Cipher identifier + decoder |
| Shodan | https://www.shodan.io | OSINT / internet-connected devices |
| VirusTotal | https://www.virustotal.com | Malware analysis |
| Decode.fr | https://www.decode.fr | Many encodings |
- TryHackMe Learning Paths — Best structured beginner content
- PicoCTF Archive — Hundreds of free challenges
- CTF101 — Category-by-category CTF guide
- IppSec YouTube — HTB machine walkthroughs
- John Hammond YouTube — CTF walkthroughs and security content
- LiveOverflow YouTube — Binary exploitation deep dives
- CTFtime.org — Calendar of upcoming competitions worldwide
- Look for beginner-friendly tags, or team up with others on CTFtime's team finder
hashtags2023 | B.S. Computer Science — CSU Sacramento | Cybersecurity Enthusiast