Beta

HafezCTF

Security Training and Assessment Platform

A Capture the Flag platform for assessment-grade competitions and hands-on learning paths, with per-participant flags, isolated environments, and deployment on your own infrastructure.

About HafezCTF

HafezCTF is HafezSecure's Capture the Flag platform, built to measure real capability rather than just rank scores. Typical CTF platforms sort participants by points and stop there, but an organization qualifying bug bounty researchers or screening candidates needs a defensible signal. HafezCTF provides it with per-participant flags, isolated environments, multi-stage challenges and anti-cheat detection. One engine has two faces: time-boxed Events and an always-on Academy. The platform can be operated by HafezSecure as a managed service or installed on your own infrastructure.

2
Modes: Events and Academy
1:1
Isolated Environment per Participant
On-Prem
Deployment Option
Signed
Challenge Bundles

Two Modes, One Engine

A challenge written once runs both as a scored task in an event and as a lab in the Academy

Events
Time-boxed competitions with a live scoreboard, first-blood and decay scoring, open, invite-only or closed registration, and participant write-ups reviewed by your operators.
Academy
Always-on learning paths that combine lessons with hands-on labs and track each learner’s progress. Labs reuse the same challenges as Events, so training and assessment share one library.

Key Features

The mechanics that turn a competition into an assessment instrument

Per-Participant Dynamic Flags
Every participant receives a unique flag for the same challenge, so a shared flag points straight back to where it came from.
Isolated Environments
Each participant attacks a private, hardened instance of the challenge with outbound traffic blocked, so nobody interferes with anyone else’s work.
Multi-Stage Attack Chains
Challenges can require several linked steps, each with its own flag, to reflect how real vulnerabilities are chained together.
Anti-Cheat and Integrity View
Flag reuse across participants is detected automatically, and a complete submission ledger lets operators review every suspicious pattern.
Verified, Signed Challenges
No challenge is published until an automated solver proves it can be solved end to end, and challenge bundles are cryptographically signed.
Operator Console
Manage event settings, challenges, running environments, participants and write-up reviews from one console, with every operator action audited.

Use Cases

Wherever security skills need to be measured or built in practice

Hiring and Candidate Screening
Bug Bounty Researcher Qualification
Security Team Training and Readiness
Competitions and Community Events

How It Works

From choosing challenges to acting on the results

1
Build the Challenge Set
Choose challenges from the library or author your own; each one passes the automated solvability check before it can be used.
2
Configure the Event or Path
Set the time window, registration mode and scoring rules for an event, or arrange modules and labs into a learning path.
3
Participants Solve
Participants sign in without passwords, launch their own isolated environment and submit the flags they capture.
4
Review the Results
Go beyond the scoreboard: review write-ups, integrity signals and progress to see who can actually do the work.

Why HafezCTF

What sets HafezCTF apart from a typical CTF platform

Assessment-Grade Signal
Built to tell apart two people with the same score, so a competition result can support a hiring or qualification decision.
Runs on Your Infrastructure
The whole platform can be installed on hardware you control, from a single server to a Kubernetes cluster, with no dependency on external services.
Security-First Design
Passwordless sign-in, server-side sessions, strict content security policy, rate limiting and an audit log are built in, not bolted on.
Backed by Competition Experience
Designed by HafezSecure’s team, drawing on years of designing and competing in capture-the-flag events.
Planning a Competition or Training Program?
Contact our team to discuss running a competition, screening candidates, or installing HafezCTF on your own infrastructure