UNG Cybersecurity Capstone Program

About UNG CTF Platform

A comprehensive Capture The Flag platform designed for senior-level cybersecurity students

Our Mission

This platform provides hands-on experience with real-world security challenges, preparing students for professional cybersecurity careers. Each challenge is carefully crafted to reinforce course concepts and introduce industry-standard tools and methodologies.

Platform Features

Real-World Security

Challenges based on actual security incidents and industry scenarios

Progressive Difficulty

From beginner-friendly to expert-level challenges

Educational Focus

Learn industry-standard tools and methodologies

Professional Skills

Build portfolio-worthy security analysis capabilities

Challenge Categories

Network Forensics

PCAP analysis, protocol inspection, traffic monitoring

Cryptography

Encryption breaking, key analysis, secure implementation

Digital Forensics

Disk analysis, memory forensics, artifact recovery

Web Security

SQL injection, XSS, authentication bypass techniques

Malware Analysis

Reverse engineering, behavioral analysis, C2 extraction

Cloud Security

AWS/Azure misconfigurations, IAM analysis

Penetration Testing

Privilege escalation, exploitation, post-exploitation

GRC & Compliance

NIST CSF, risk assessment, security frameworks

Flag Format

All flags in this CTF follow a standard format for consistency:

ung{descriptive_text_here}

Example: ung{sql_injection_bypass_complete}

Rules & Guidelines

Academic Integrity

Work individually unless instructed otherwise. Collaboration on understanding concepts is encouraged, but flag sharing is prohibited.

Tool Usage

Use any tools and resources available to you. Learning to leverage professional security tools is part of the educational experience.

Documentation

Document your methodology and findings. This practice is essential for professional security work and will be valuable for your portfolio.

Ethical Conduct

All activities must remain within the scope of this platform. Do not attack external systems or infrastructure.