Platform operational 00:00:00 UTC 0 teams competing

Rules

AetherGuard CTF: Official Rules

Welcome to AetherGuard CTF. These rules apply to every team and every participant for the duration of the event. Registering a team means you agree to follow them.

1. WHAT'S IN SCOPE

You are authorized to attack the challenge targets themselves, and only the challenge targets: the individual web, crypto, and reverse-engineering instances listed on the Challenges page once they go live. This includes normal offensive techniques against those targets, like directory and endpoint brute-forcing, parameter fuzzing, injection testing, authentication and session attacks, and, where a challenge is explicitly built around it, remote code execution and privilege escalation inside that challenge's own container. That's the game. Use real tools, do real recon, and don't feel bad about it.

Everything outside a challenge's own application is out of scope. This means, without exception:
- The CTF platform itself (ctf.aetherguard.xyz and ctf-management.aetherguard.xyz). No scanning, fuzzing, injection testing, or authentication attacks against the scoreboard, registration, or admin systems.
- The servers, containers, and networks that host the challenges, once you're not inside the challenge application anymore. If you achieve code execution inside a challenge, stay inside it. Attempting to break out of a container, pivot to the host, pivot to other containers, or touch anything not part of the intended challenge is a violation, not a bonus objective.
- Other teams, their infrastructure, and their accounts. No attacking, impersonating, or attempting to access another team's session, credentials, or submissions.
- Any AetherGuard system not explicitly listed as a challenge, including our corporate site, email, and internal tooling.

If you're ever unsure whether something is in scope, assume it isn't and ask us first. See section 7.

2. FLAGS AND SCORING

Each challenge has one flag in the format aetherguard{...} unless the challenge description says otherwise. Submit flags through the platform, not to us directly. Points are awarded once per team per challenge. Partial-chain challenges, for example an initial-foothold flag and a separate root or admin flag, are scored as two challenges and both are worth capturing. Hints, where available, unlock automatically on a timer or can be requested early at a point cost noted on the challenge, so that trade-off is yours to make. The leaderboard updates live. Final standings are based on total points, with ties broken by earliest time the tying score was reached.

3. PROHIBITED CONDUCT

The following will get a team disqualified, and may get an individual banned from future events:
- Attacking anything out of scope as defined in section 1, including any attempt to escape a challenge container or reach the underlying host.
- Denial-of-service or resource-exhaustion attacks against any AetherGuard system or another team, including deliberately overloading a challenge instance so other teams can't use it.
- Sharing flags, writeups, or solutions with another team during the competition, or submitting a flag your team did not obtain itself.
- Automated mass-scanning of the entire challenge fleet or platform in a way that degrades service for others. Targeted recon against a specific challenge you're actively working is fine. Carpet-bombing every host with every tool you own is not.
- Social engineering AetherGuard staff, volunteers, or other participants to obtain flags, hints, or access.
- Exploiting a bug in the scoring platform itself instead of reporting it. If you find one, see section 7. We'll usually thank you for it, and reporting a platform bug you found while playing fairly is never a rules violation.

4. FAIR PLAY

Play as the team you registered. Multi-accounting, having one person compete on several teams, or a team competing under someone else's registration is not allowed. Collaboration is expected within your own team and not expected between teams. Use of AI assistants, public writeups from past unrelated CTFs, and standard security tooling such as Burp, ffuf, sqlmap, and nmap against in-scope targets is allowed. This is a practical exercise, not a memory test.

5. AVAILABILITY

Challenges may be paused, adjusted, or taken temporarily offline if we find an unintended bug, an infrastructure issue, or an unscoped attack in progress. We'll announce any pause or schedule change on the platform. Time lost to an AetherGuard-side outage may be added back to the event at our discretion. It is not grounds for a score dispute.

6. ENFORCEMENT

AetherGuard staff have final say on rules interpretation and scoring disputes. Violations may result in point forfeiture, challenge lockout, or full disqualification, depending on severity, and we will tell you why if it happens to you. We are not trying to catch people out on technicalities. If something above is unclear, ask before you do it, not after.

7. QUESTIONS AND REPORTS

Found a bug in a challenge that feels unintended, a platform bug, or just have a rules question? Use the Support link on the site, or reach out through the contact listed on the platform. We'd rather answer a question than disqualify a team.

Good luck, and have fun.
Select a track
AetherGuard Radio