Workshop session
Capture the Flag
Workshop CTF

Capture the Flag

Investigate each scenario, find the answer and submit it as the flag.

Workshop command view

Dashboard

Monitor readiness, live CTF status, leaderboard and participant progress from one overview.

Workshop readiness
Leaderboard
Participant Activity
Participant Rank Capture the Flag Points ⇅
Workshop roster

Participants

Provision accounts and track CTF progress.

All participants
Participant ⇅ Capture the Flag Delete
Progress Detail Reset
Live workshop operations

Control Center

Run the CTF session, control participant-facing visibility and manage registration from one operational surface.

Capture the Flag
Status —
Leaderboard
Participants —
Registration
Status —
CTF TIMER
--:--:--
No timer set — the clock runs only while Capture the Flag is on Run.
--
Registration Code
—
Capture the Flag content

Challenges

Create and manage the CTF questions, their flags, points and hints.

All challenges
SEQ Challenge Actions
Edit Delete Visible
Administration

Admin access management

Create and manage instructor accounts with full control panel access.

Add admin A random password and API token are generated automatically on creation.
All admins
Username Display name Status Actions
Token Password Disable Delete
Workshop configuration

Global operating settings

Workshop name, demo data and maintenance controls for this lab environment.

Workshop name

Shown on the login screen, the participant portal and the admin panel.

Demo Data

Add sample challenges and 10 demo participants with progress, to preview the dashboard and leaderboard.

Danger zone

Destructive maintenance

Use these actions only when preparing the lab for a new run or cleaning a completed workshop.

Clear Database

Deletes participants, challenges and all CTF progress. Admins and settings are kept.

This will permanently delete:
  • All participant accounts (admin preserved)
  • All challenges, completions and point penalties
Admins and settings are kept.
Factory Reset

Runs the full workshop reset flow and prepares the environment for the next group.

Workshop CTF

About

Made with love, coffee, and a suspicious number of “just one last tweak” moments. Built by humans who care about the details, even the tiny ones nobody notices… until they do.

Platform Workshop CTF
Built by Netskope Iberia team
Purpose Workshop & Training
Participant provisioning
Text-flag challenges
Timer & leaderboard
Workshop monitoring
Maintenance Inspect the release notes.
☕
Fuel for the team

If this lab helped your workshop run smoother, the Netskope Iberia team accepts thanks in coffee, cold beers, Bitcoin, or a good conversation at the next meetup.

Reference rate: 1 good conversation = 1 coffee. Premium challenge stories may qualify for beer tier. ₿
Help

Overview

This portal runs the Capture the Flag of your workshop: participants read each challenge, investigate, and submit the answer as a flag.

1
Challenges — create them, import a CSV or load the bundled template.
2
Participants — open registration in the Control Center or bulk-create accounts.
3
Run — set the timer and switch the CTF to Run. Follow the Dashboard and launch the award ceremony at the end.

Dashboard

Readiness, live CTF status, leaderboard and participant progress at a glance.

Workshop readiness

  • Capture the Flag (semaphore) — current CTF state: Stopped, Standby or Run. Click a light to change it.
  • Registration (semaphore) — open or close participant self-registration.
  • Participants — green when at least one participant exists.
  • Capture the Flag — green when at least one challenge is visible.

Leaderboard

Live podium of the top participants. Expand opens the fullscreen ranking to project; the award ceremony reveals the final ranking with music.

Participant activity

Every participant with their rank, challenges completed and total points.

Participants

All workshop participants and their CTF progress.

How participants join

In Control Center open registration and share the Registration Code; participants click Register here on the login screen. Alternatively, use the bulk-create button (top right) to generate accounts with random names — username and password are the same.

Table columns

  • Progress — challenges completed out of the visible total.
  • Detail — timeline of completions, wrong answers and hints.
  • Reset — clears the participant's completions, penalties and hints.
  • Delete — removes the participant and all their CTF data. Cannot be undone.

Control Center

The cockpit for running the live session. From here you govern the game state, registration, what participants can see, and the climax actions — without touching configuration.

Control cards

  • Capture the Flag — semaphore for the global CTF state: Stop (challenges hidden from participants), Standby (visible but submissions paused), Run (active). The card background turns red / amber / green to match. Also mirrored on the Dashboard.
  • Registration — open or close participant self-registration. When closed, the registration code stops working.
  • Leaderboard — show or hide the leaderboard for participants. When hidden, their leaderboard button disappears; you (admin) always keep full access on the Dashboard and in the ceremony.
  • Registration Code — the shared code participants enter to register. Copy it or edit it inline.

Quick actions

  • 🏆 Launch Award Ceremony — a fullscreen, music-synced ranking reveal for the prize-giving moment. The runners-up appear one by one, then the podium is revealed 3rd → 2nd → 1st with confetti. Use the on-screen Start / Stop / Replay controls.
  • Open Leaderboard — the live ranking in fullscreen, ideal to project during the workshop. Includes an autorefresh toggle.
  • Reset CTF progress — clears every participant's completions, points and penalties. Asks for confirmation and cannot be undone.
The leaderboard ranks all participants — those with no completions appear at the bottom with their penalty-adjusted score.

Challenges

Every challenge is a text question. The participant types an answer and presses Check; it is compared with the challenge's flag. The flag is never sent to the participant's browser.

Creating a challenge

1
Title and description — the scenario shown to participants.
2
Flag — the expected answer. Matching ignores upper/lower case and extra spaces, but is otherwise exact. Use %username to expect a different answer per participant.
3
Points — awarded on the first correct answer (default 50).
4
Hint — optional; revealing it costs −5 points.

Scoring and penalties

Total score = points earned − 5 × (wrong answers + hints used). After 5 wrong answers on a challenge it locks for 5 minutes.

Import / Export / Template

CSV columns: seq,title,description,flag,points,hint,visible. Import appends; Load template replaces all challenges (and progress) with templates/challenges.csv.

Delete all removes every challenge and all participant progress.

Admins

Manage admin accounts for the workshop. Admins have full access to this panel and are not visible to participants.

Creating an admin

1
Username — 5–12 characters, auto-uppercased (e.g. ALICE). This is the login code.
2
Display name — optional label shown in the table (e.g. Alice Smith).
3
Click Create. A popup shows the username, a randomly-generated password, and the API token. Save them immediately — the password is not stored in plain text and cannot be recovered.

Row actions

  • View token — shows the admin's API token for copying.
  • Reset password — generates a new random password and displays it once.
  • Enable / Disable — disabled accounts cannot log in. The row is dimmed. Not available for ADMIN-2026.
  • Delete — permanently removes the account. Not available for ADMIN-2026.

Bulk actions

  • Disable all — disables every admin except ADMIN-2026. Useful at the end of a session.
  • Delete all — permanently deletes every admin except ADMIN-2026.
ADMIN-2026 is the built-in default account and cannot be deleted or disabled. To replace it, create a new admin and use Disable all to lock out the default.

Global Settings

Demo data and maintenance actions.

Demo data

Adds 5 sample challenges (if missing) and 10 demo participants (DEMO-01 … DEMO-10, password = username) with varied progress, to preview the dashboard, podium and ceremony. Existing challenges are kept.

Clear database

Deleted: participants, challenges and all CTF progress. Kept: admin accounts and settings.

Factory reset

Everything in Clear database, plus settings back to defaults, every admin except ADMIN-2026 removed, and the ADMIN-2026 password cleared (you set a new one on the next sign-in).

Both actions are irreversible. Back up data/data.db first if you need the results.
—
Challenge progress
Activity timeline