Measure security skill on real targets.
HafezCTF runs qualification-grade assessments and hands-on learning paths. Every participant gets an isolated environment and a flag that is theirs alone — so a shared answer is detectable by construction, not by suspicion.
Be first in when we open
HafezCTF opens to everyone soon. Leave your email and we will write to you the moment your account is ready.
One email when we launch. No newsletter, no spam.
An assessment engine, not a scoreboard.
Run a competition or a hiring gate on the same engine. What comes out is evidence you can act on — per-domain skill, difficulty profile, and a recommendation you can defend.
Isolated environments
Per-participant sandboxes with hardened isolation and blocked egress. Per-participant flags make sharing detectable by construction.
Qualification-grade reports
Per-domain skill heatmaps, a difficulty profile and recommendation tiers, exportable — output a hiring panel can read, not a raw points table.
Evidence, stated honestly
A score built on one solve is shown as one solve, not as a skill level. The report says what its own numbers rest on, so nobody over-reads them.
Deploy on your terms
One command with Docker, or Kubernetes for scale. Self-hosted, air-gapped, or on a local cloud — no foreign cloud dependency.
Built so a solve can't be faked or shared.
The mechanics are the point: every flag is a participant's own, sharing is detectable, and a challenge can be as many steps as the technique actually takes.
Per-participant dynamic flags
Each participant's flag is derived from a seed that is theirs alone, so a flag copied from someone else is simply invalid — sharing is defeated by construction, not by policing.
Cheat detection built in
Submit a flag that belongs to another participant's seed and it is recorded as an integrity event, attributed to both accounts, ready for an operator to review.
Multi-stage challenges
A challenge can be a sequence of stages, each with its own flag and points, so a hard target is graded by how far someone actually got — not all-or-nothing.
Hints, first blood, dynamic scoring
Author-written hints reveal one at a time for a points penalty; the first solver takes a bonus; and a stage's value can decay as more people solve it.
We hold ourselves to the standard we test for.
The platform is built the way we would want a target built — the controls are the product, not an afterthought.
Run an assessment that holds up.
Self-hosted, isolated per participant, and evidence you can defend. Stand it up yourself or get early access.
Request early access