HafezCTF
CTF assessments and security training

Measure security skill on real targets.

HafezCTF runs qualification-grade assessments and hands-on learning paths. Every participant gets an isolated environment and a flag that is theirs alone — so a shared answer is detectable by construction, not by suspicion.

Self-hosted · air-gap ready Isolated environments Security-first by design
Early access

Be first in when we open

HafezCTF opens to everyone soon. Leave your email and we will write to you the moment your account is ready.

One email when we launch. No newsletter, no spam.

The platform

An assessment engine, not a scoreboard.

Run a competition or a hiring gate on the same engine. What comes out is evidence you can act on — per-domain skill, difficulty profile, and a recommendation you can defend.

Isolated environments

Per-participant sandboxes with hardened isolation and blocked egress. Per-participant flags make sharing detectable by construction.

sandboxedegress blocked

Qualification-grade reports

Per-domain skill heatmaps, a difficulty profile and recommendation tiers, exportable — output a hiring panel can read, not a raw points table.

skill heatmapCSV export

Evidence, stated honestly

A score built on one solve is shown as one solve, not as a skill level. The report says what its own numbers rest on, so nobody over-reads them.

sample sizesstated rubric

Deploy on your terms

One command with Docker, or Kubernetes for scale. Self-hosted, air-gapped, or on a local cloud — no foreign cloud dependency.

DockerKubernetesair-gapped
The challenge engine

Built so a solve can't be faked or shared.

The mechanics are the point: every flag is a participant's own, sharing is detectable, and a challenge can be as many steps as the technique actually takes.

Per-participant dynamic flags

Each participant's flag is derived from a seed that is theirs alone, so a flag copied from someone else is simply invalid — sharing is defeated by construction, not by policing.

per-seeddeterministic

Cheat detection built in

Submit a flag that belongs to another participant's seed and it is recorded as an integrity event, attributed to both accounts, ready for an operator to review.

flag-sharingattributed

Multi-stage challenges

A challenge can be a sequence of stages, each with its own flag and points, so a hard target is graded by how far someone actually got — not all-or-nothing.

stagedpartial credit

Hints, first blood, dynamic scoring

Author-written hints reveal one at a time for a points penalty; the first solver takes a bonus; and a stage's value can decay as more people solve it.

graduated hintsfirst blooddecay
Security-first

We hold ourselves to the standard we test for.

The platform is built the way we would want a target built — the controls are the product, not an afterthought.

✓
Signed challenge packages Signatures verified before install — the supply chain is closed end to end.
✓
Hardened by default Strict content policy with no inline script or style, CSRF protection, passwordless sign-in, and a full audit log.
✓
Scanned continuously Dependency and container scanning gate every change before it ships.

Run an assessment that holds up.

Self-hosted, isolated per participant, and evidence you can defend. Stand it up yourself or get early access.

Request early access