Recruiting · rolling applications
Break things.
Capture flags.
NXT_CTFS is a competitive cybersecurity team tackling web, binary, and cryptography challenges together.
$whoami
nxt_ctfs · competitive capture the flag
$ls ./categories
web pwn rev crypto forensics osint
$./recruit --status
open · no minimum solve count
$
Events
Latest events
Where the team has competed recently, with a writeup for every solve.
About
Who we are
We are a team of security researchers, students, and hobbyists who compete in Capture The Flag competitions year-round. We study real-world vulnerabilities, break intentionally vulnerable systems, and share what we learn with each other.
Whether you have solved one challenge or a thousand, there is a place here to sharpen your skills alongside people who enjoy the same puzzles.
Categories
What we work on
Six core disciplines, one team. Pick a lane or work across all of them.
| Category | What it involves | Tools we reach for |
|---|---|---|
| Web exploitation | Injection flaws, auth bypasses, and logic bugs in modern web apps. | burp · sqlmap · ffuf |
| Binary exploitation | Memory corruption, stack and heap attacks, exploit development. | pwntools · gdb · ROP |
| Reverse engineering | Disassembling binaries to understand and manipulate behavior. | ghidra · ida · angr |
| Cryptography | Breaking weak ciphers, protocol flaws, and implementation bugs. | sage · z3 · rsactftool |
| Digital forensics | Recovering evidence from disk images, memory dumps, and packet captures. | volatility · wireshark · binwalk |
| OSINT | Tracking down information from public sources and open data. | maltego · exiftool · sherlock |
Team
Who you will be working with
The people behind the handles. Each keeps a solo page for the events they run alone.
nxt@ctf:~$ ssh guest@sandbox
Try a box
A two-hop privilege escalation, running in the page. You land as guest with no privileges. Find the flag and read it. No hints past this line.
Join
Want in?
We take new members on a rolling basis. Tell us a bit about yourself and what you like to break.
- No minimum solve count; curiosity counts more.
- We compete year-round and write up what we learn.
- Reply usually lands in your inbox within a week.