Skip to content

Latest commit

 

History

3 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 

Repository files navigation

4ctf logo

4ctf

Four teams. One clock.
A four-track cybersecurity training & competition platform

Live 4ctf

Live → 4ctf.com · MyßGitHub


Live

The landing is live at https://4ctf.com.


What is 4ctf?

4ctf is a cybersecurity training and competition platform built around four tracks:

Track Focus
Red Offensive labs on Kali Linux
Blue Defense with ELK (Elasticsearch · Logstash · Kibana) SIEM
Purple Secure coding & patches
Grey Beginner / mixed on-ramp

Features

Four tracks

  • Red — Isolated offensive labs in browser Kali Linux
  • Blue — SIEM views, IR reports, forensics on ELK stack
  • Purple — Vulnerable-app review and patch submit
  • Grey — Guided rooms and low-stakes XP for newcomers

Capture rooms & CTF

  • Solo, team, classroom, and arena room modes
  • Dynamic flags (HMAC + nonce) — no plaintext flags stored
  • Hints with XP deductions; AI never leaks flags or credentials
  • Classroom pause for instructors; reconnect until lab TTL

1v1 Arena (hero)

  • Timed match: Red on Kali Linux vs Blue on ELK
  • Shared clock, live WebSocket timer / alerts / scores
  • Red scoring: authorized in-lab objectives only
  • Blue scoring: IoC regex patterns + AI report rubric
  • Matchmaking by skill band; isolation + TTL cleanup after each match

Labs & sandboxes

  • Per-session sandboxed labs with mandatory TTL purge
  • Network isolation — no lateral movement, no public-internet abuse path
  • Lab heartbeats, warn / stop / purge lifecycle
  • Capacity queue with live status when providers are full

Learning & events (roadmap)

  • Course rails per track
  • Pro-style certifications tied to proctored rooms
  • Tournaments with prize pools
  • Flywheel: learn → compete → certify → recruit

Landing (live now)

  • Countdown launch page at 4ctf.com
  • Waitlist signup
  • AI chat (Ask AI) + message-the-developer inbox
  • Spam guards: honeypot, fill-time, rate limits, disposable email block

Technical features

Area Stack / capability
Red labs Browser Kali Linux images (OCI)
Blue labs ELK stack — Elasticsearch, Logstash, Kibana (Render)
Edge Cloudflare Workers — TLS, WAF, DDoS, geo routing
Control plane Node.js — auth, rooms, flags, match engine, WebSockets, AI proxy
Database Turso (LibSQL) — flags, matches, telemetry, scores
Realtime WebSockets — timer snapshots, scores, lab status
Flags HMAC + nonce; one-shot consume; never in WS payloads
AI DeepSeek proxy — hints + Blue report judging; schema-only output
Auth (planned) Argon2id, rate limits, lockout audit
Ops Lab reaper cron, TTL jobs, audit log, retention policies

Brand

4ctf four-square mark

Four upright squares — Red · Blue · Purple · Grey — on a clean white field.


Developer

Mohammed Al-Abyah — Security Engineer · Riyadh


4ctf · Four teams. One clock.

About

4ctf.com is a four-track training ground Red, Blue, Purple, and Grey plus four capture rooms, CTF events, and a judged 1v1 where Kali meets ELK.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors