Four teams. One clock.
A four-track cybersecurity training & competition platform
The landing is live at https://4ctf.com.
4ctf is a cybersecurity training and competition platform built around four tracks:
| Track | Focus |
|---|---|
| Red | Offensive labs on Kali Linux |
| Blue | Defense with ELK (Elasticsearch · Logstash · Kibana) SIEM |
| Purple | Secure coding & patches |
| Grey | Beginner / mixed on-ramp |
- Red — Isolated offensive labs in browser Kali Linux
- Blue — SIEM views, IR reports, forensics on ELK stack
- Purple — Vulnerable-app review and patch submit
- Grey — Guided rooms and low-stakes XP for newcomers
- Solo, team, classroom, and arena room modes
- Dynamic flags (HMAC + nonce) — no plaintext flags stored
- Hints with XP deductions; AI never leaks flags or credentials
- Classroom pause for instructors; reconnect until lab TTL
- Timed match: Red on Kali Linux vs Blue on ELK
- Shared clock, live WebSocket timer / alerts / scores
- Red scoring: authorized in-lab objectives only
- Blue scoring: IoC regex patterns + AI report rubric
- Matchmaking by skill band; isolation + TTL cleanup after each match
- Per-session sandboxed labs with mandatory TTL purge
- Network isolation — no lateral movement, no public-internet abuse path
- Lab heartbeats, warn / stop / purge lifecycle
- Capacity queue with live status when providers are full
- Course rails per track
- Pro-style certifications tied to proctored rooms
- Tournaments with prize pools
- Flywheel: learn → compete → certify → recruit
- Countdown launch page at 4ctf.com
- Waitlist signup
- AI chat (Ask AI) + message-the-developer inbox
- Spam guards: honeypot, fill-time, rate limits, disposable email block
| Area | Stack / capability |
|---|---|
| Red labs | Browser Kali Linux images (OCI) |
| Blue labs | ELK stack — Elasticsearch, Logstash, Kibana (Render) |
| Edge | Cloudflare Workers — TLS, WAF, DDoS, geo routing |
| Control plane | Node.js — auth, rooms, flags, match engine, WebSockets, AI proxy |
| Database | Turso (LibSQL) — flags, matches, telemetry, scores |
| Realtime | WebSockets — timer snapshots, scores, lab status |
| Flags | HMAC + nonce; one-shot consume; never in WS payloads |
| AI | DeepSeek proxy — hints + Blue report judging; schema-only output |
| Auth (planned) | Argon2id, rate limits, lockout audit |
| Ops | Lab reaper cron, TTL jobs, audit log, retention policies |
Four upright squares — Red · Blue · Purple · Grey — on a clean white field.
Mohammed Al-Abyah — Security Engineer · Riyadh
4ctf · Four teams. One clock.
