We have been hard at work developing our industry-focused CTF, and we're ready to start teasing what we've been making.

CTF Categories and Rules

BSides 2026 CTF Categories

RF

Hunt, decode, analyse and abuse signals, spectrum and wireless systems in challenges built for people who like their packets over the air.

Crypto

Crack codes, reverse ciphers and unravel cryptographic mistakes hiding secrets where they definitely should not be.

AI (!)

Break, test, prompt, manipulate and defend AI systems in challenges that explore where machine learning gets weird, risky or unexpectedly useful.

OSINT

Follow the breadcrumbs across the universe and turn scattered public clues into answers, attribution and flags.

GRC (?!)

Yes, really! Governance, risk and compliance turned into challenges that reward sharp thinking, good judgement and security-minded decision-making.

Forensics

Pick through logs, files, memory and captures to work out what happened, how it happened and what was left behind.

Web

Find the bugs, break the logic and dig through web apps full of vulnerable code, shaky auth and questionable developer choices.

Others…

The wildcard category for strange, experimental or last-minute challenges that do not fit neatly anywhere else, because sometimes the best ideas appear right before game day.

CTF Rules — Changelog

Changes since the initial rules release

This version supersedes the rules as originally published. Where the two conflict, this document applies. 

Maximum team size is now four, reduced from five. 

No first-solve bonus. Dynamic scoring still applies — a challenge's value decreases as more teams solve it, down to a floor — but early solves no longer earn more points. Every team that solves a challenge finishes with the same score for it. 

Flagship challenges have been removed, along with the unlock requirement and the proof-of-solve write-up verification process attached to them. No challenge in the set is locked or requires manual verification. 

There is no story or narrative. Story challenges are gone and challenges stand alone. 

Category list updated. Reverse Engineering is now a category in its own right. Others is now Misc. GRC is no longer confirmed — it may be included, and this will be confirmed in the Discord. Web, Crypto, Forensics, OSINT, RF and AI are unchanged. 

Prize structure replaced. The educational write-up and video explainer prize has been withdrawn. The prizes are now four CREST CPSA vouchers for first place, the Spirit of CTF Prize, and spot prizes during the event. See section 3. 

Flag hoarding is now an explicit rule with stated consequences. See section 4.1. 

AI guidance clarified — permitted as a learning aid, with the requirement that you can explain your own solve. Further guidance may be issued during the event via Discord. See section 2. 

The Discord is the official announcements channel for all challenge updates, resets, hints and notices. 

A live RF challenge is confirmed, transmitting on-site during the event. An RTL-SDR is useful if you have one. Receive-only. 

Flag format documented as `bsadl26{...}`. 

Everything else stands as published, including scope of activity, availability and fairness, tie-breaks, hint release, conduct, RF safety and spectrum use, enforcement and appeals. 

CTF Rules — Jeopardy Format with Dynamic Scoring

1. Competition format

This is a jeopardy-style CTF

Challenges are organised by category, with points varied based on difficulty. 

Teams may attempt challenges in any order, unless otherwise specified. Every challenge stands on its own — nothing is locked, and there is no required order of progression. 

1.1. Dynamic scoring

Each challenge has: 

  • a base score when unsolved 

  • a minimum score floor

  • The score awarded decreases as more teams solve that challenge. 

  • Scores never drop below the minimum. 

There is no first-solve bonus. Every team that solves a challenge ends up with the same score for it — the challenge's final value once all solves are in. Solving first does not earn extra points. 

This differs from static scoring, where each challenge is worth a fixed amount decided in advance. Here the teams playing determine what a challenge is worth: if only a handful of teams crack it, it stays worth a lot, and if almost everyone gets it, its value settles toward the floor. The intent is to reward skill and persistence, not speed. Take the time you need on the hard ones. 

2. Use of AI tools is permitted

  • AI tools are permitted as learning aids. AI use does not exempt teams from the requirement to demonstrate meaningful human understanding and engagement with the solve. 

  • You must understand your own solution and be able to explain it if asked — the solve path, the observations that mattered, and why the approach worked. 

  • The organising team may issue additional guidance on AI use during the event. Any such guidance will be posted in the Discord and applies from the time it is announced. 

3. Prizes

First place — CREST Practitioner Security Analyst (CPSA)

 examination vouchers

The top team on the final scoreboard receives four CREST CPSA examination vouchers, one per team member, generously provided by CREST International

Spirit of CTF Prize

Awarded to the team that best demonstrates learning, good sportsmanship and determination, judged by the organisers and independent of scoreboard position. A team finishing well down the standings is exactly as eligible as a team at the top. We are looking for teams who arrived knowing little and visibly worked their way up, who refused to give up on a hard challenge, or who went out of their way to help other players. 

Spot Prizes

Handed out during the event for standout moments — a clever piece of thinking, a well-earned solve, a good question, or genuine perseverance. These are weighted heavily towards new and newer CTF participants. If this is your first, second or third CTF, these are aimed squarely at you. 

4. Flag submission

  • Flags must be submitted via the official platform. The standard flag format is `bsadl26{...}`; where a challenge uses a different prefix, its description will say so. 

  • Flags must be obtained by solving challenges in alignment with the spirit of the competition. Brute-forcing flags or exploiting the platform itself to reveal them is prohibited. 

  • Do not publicly disclose solutions, flags, write-ups, walkthroughs, or challenge-specific hints until after the event is over. 

  • Unintended solve paths may be patched without notice during the event. 

4.1. No flag hoarding

Submit flags as you solve them.

Flag hoarding — deliberately holding solved flags and dumping them onto the scoreboard near the end of the event to manipulate the standings — is against the rules. The live scoreboard is what other teams use to gauge how they are going, and what organisers use to judge which challenges need a hint. Deliberately distorting it is unsportsmanlike. 

The scoring gives you nothing for doing it, since every team that solves a challenge receives the same score for it regardless of when they submit. 

Any instance considered obvious and malicious will result in disqualification from prizes. This targets deliberate manipulation, not a team who saved up a couple of solves over a coffee break. 

5. Scope of activity

Only interact with systems explicitly provided. 

Do not attack: 

  • the scoring platform 

  • infrastructure outside scope 

  • other teams 

Specific external help from non-participants or non-team-members is against the rules. 

General learning and reference use is allowed. 

Scope clarifications included in challenge descriptions are authoritative. 

For example, you may

  • ask someone to remind you how a specific feature of a technology works or consult public documentation. 

You may not

  • send the problem statement, challenge files, service endpoint, or solve context to a friend, colleague, or external expert and ask them to solve it for you. 

6. Teams

  • Teams must register with an appropriate name. 

  • Teams compete independently; flag sharing is prohibited. 

  • Each participant may have only one account

  • Teams may have a maximum of four participants

  • Organisers and challenge authors may participate informally if approved by the CTF organisers but are ineligible for prizes

7. Availability and fairness

 Organisers may: 

  • fix or update challenges 

  • patch unintended solve paths 

  • restart services without notice 

 No guaranteed uptime is provided during the event. 

 No compensation, score adjustment, or prize adjustment is guaranteed for downtime. 

 Best effort will be made to inform all participants of technical issues and resolve them quickly. 

 Tie-breaks will be resolved in favour of the team with the earlier final solve timestamp. 

 CTF organisers may release hints for unsolved challenges (optionally with a score adjustment to the challenge) provided these hints are shared to all participants. 

8. Conduct

  • Respect other participants and organisers. 

  • Disruptive or unsportsmanlike behaviour may result in disqualification or ineligibility for prizes. 

RF Safety & Spectrum Use

9. Authorised RF activity only

  • RF challenges are designed for receive-only participation by competitors. 

  • Participants must not transmit RF unless explicitly authorised by organisers. 

  • Only designated operators, such as AREG or approved organisers, may operate transmitters. 

10. Regulatory compliance

  • All event RF activity must comply with Australian Communications and Media Authority (ACMA) requirements. 

  • Event transmissions, where used, will occur within appropriate allocations and operating conditions. 

  • Participants must follow organiser instructions regarding RF equipment, antennas, SDRs, receivers, and foxhunt activity. 

11. Receive-only participation

  • Participants may use receive-only equipment to observe, capture, decode, or analyse signals that are part of the event. 

  • Participants must not: 

    • transmit 

    • jam 

    • spoof 

    • replay 

    • interfere with public communications, emergency services, event infrastructure, or other participants 

12. Equipment safety

  • Do not tamper with, reconfigure, damage, relocate, or interfere with provided RF equipment, antennas, SDRs, receivers, transmitters, or supporting infrastructure. 

  • Follow organiser instructions at all times. 

13. Foxhunt

  • Only organisers may deploy foxhunt transmitters. 

  • Participants must not: 

    • move foxhunt transmitters 

    • tamper with foxhunt transmitters 

    • shield, obscure, or damage foxhunt transmitters 

14. Enforcement

  • Violations of any of the above rules may result in: 

    • withheld points 

    • prize ineligibility 

    • disqualification 

    • removal from the event 

    • escalation if serious safety, legal, or regulatory breaches occur 

Enforcement is at the discretion of the CTF leads.

Organiser decisions are open to appeal through the broader BSides Committee.

15. Announcements

All challenge updates, resets, hints and important notices will be posted in the BSides Adelaide Discord. It is the primary contact point during the event. Please join before the event starts: https://discord.gg/gnQB4z4NK