Active Directory security ctf
Welcome to Bloodhound
A capture-the-flag built around misconfigurations and Active Directory shenanigans.
10+ flags in 4 categories, expanding your cyber knowledge to Windows, AD, Kerberos, and more fun stuff!
Find the flag, submit it, climb the scoreboard.
register a team
Register on the intranet. The credential will be sent on your student email account. Every submission counts toward your team's score.
pick a challenge
Browse by category: kerberos, privesc, phishing, and more! Choose your level of challenge from easy to insane!
submit the flag
Flags look like EPI{...}. Don't bruteforce flags, when you find a new user, try to find if it can connect to a machine, most flags are in C:\Users\$USER\Desktop\
exegol

Exegol is a fantastic toolkit, a dockerized OS with all the tool needed for cybersecurity.
It works on every OS (Linux, Windows, Mac) and have everything you need and even more!
It is very highly encouraged to use it for the CTF, as the tools are quite hard to install/setup.
If you decide not to use it, here is a short list of tools you'll need to manually install: neo4j, bloodhound, netexec, certipy, john, ntlmrelayx, responder, bloodyAD, impacket...
Installation instructions are on https://exegol.com/install
rules
- No attacking the CTFd platform itself, nor the VPN server or the infrastructure, READ THE SCOPE!
- Don't share flags or write-ups with other teams before, during or after the event.
- Have fun, checkup tools needed mentionned above, ALL are in Exegol preinstalled and preconfigured