c0c0n 2026

c0c0n is a 19 years old platform that is aimed at providing opportunities to showcase, educate, understand and spread awareness on Information Security, data protection, and privacy...

Venue & Date

c0c0n CTF, the c0c0n capture the flag competition

A two-day, hands-on capture the flag competition at c0c0n 2026. Play solo or in a team of up to three.

Feel free to bring your AI agents.

CTF Theme: City under Attack

The CTF takes place in a fictional city under attack, a modern, hyper-connected city where almost every essential service runs on technology.

Beginner to Advanced level challenges

Hospitals, fire stations, government offices, universities, power plants, businesses, and residential buildings all depend on interconnected digital systems to keep the city running. But now, those systems are being targeted.

Players take on the role of hackers working to assess the systems that keep the city running. They will investigate exposed services, exploit vulnerabilities, move through compromised systems, uncover misconfigurations, trace suspicious activity, and collect intelligence hidden across the city's infrastructure.

Every vulnerability discovered and every flag captured represents a piece of intelligence that can help the city's defenders understand their attack surface, identify potential attack paths, and strengthen their systems before the attackers make their move.

AI tools, agents and AI-assisted workflows are allowed. You are responsible for checking anything they produce before you rely on it.

Bring your AI agents

The attackers will not work alone. Neither should you.

Point your agents at the city's systems and let them scan, script and chain while you decide where to strike. The faster you map the attack surface, the sooner you find the way in.

An agent only works as well as the person steering it. Check what it finds before you rely on it, because a wrong answer costs you the flag.

Two days, two stages

Day-One: Open for all

Day-one will be the open stage of the c0c0n CTF, where all eligible participants can take part in the competition and work through a range of hands-on cyber security challenges. The challenges will be spread across different areas of cyber security, with varying levels of difficulty, allowing participants to choose challenges based on their skills and experience while also exploring areas they may be less familiar with.

AI agents and AI-assisted workflows will be allowed during Day-one. Participants can use AI tools while working on the challenges as part of their problem-solving process. Participants will be responsible for verifying and validating any output generated by the tools before using it.

Day-Two: Closed Environment

Day-two will be conducted as a closed challenge stage for the top five teams from Day-one. The teams will be given access to a controlled environment designed specifically for the second stage of the competition. Unlike Day-one, the challenges will be presented as more involved scenarios that require teams to work through multiple steps rather than solve individual problems in isolation.

The environment will be isolated from the conference network and will be accessible only to the qualifying teams.

What CTF players should know and bring

Only onsite players are allowed!

Eligibility & Registration

  • Open to all registered c0c0n attendees with a valid event pass.
  • Participation slots may be limited and will be confirmed by the organizers.
  • Participants must carry a valid photo ID for registration and verification.

Team Formation

  • Teams can have up to 3 participants. Solo participation is allowed.
  • Teams must be finalized before the CTF begins.
  • Each team must nominate a team captain as the primary point of contact with the organizers.
  • Each participant can be part of only one team.
  • Team changes after registration require organizer approval.

Prerequisites

  • Participants should bring their own laptop with the required security tools installed and prepare their systems in advance.
  • Internet access will not be provided at the CTF venue. Participants are expected to arrange their own internet connectivity.
  • Participants should bring their own charger and any required accessories.

Schedule

Day One

9:00 A.M
Registration starts
10:00 A.M
Day One starts
9:00 P.M
Day One ends

Day Two

09:00 A.M
Day Two starts
2:00 P.M
Day Two ends

Rules of engagement

Allowed Techniques
  • Any offensive technique is fair game against in-scope range targets.
  • Public exploits, custom tooling, exploitation frameworks (Metasploit, Impacket, Sliver, etc.) are all allowed.
  • Automated scanning and brute-forcing against challenge boxes is permitted, within reason.
  • Teams may share write-ups and tooling after the competition ends, not during.
Out of Scope
  • No attacks against other participants, their devices, or their accounts.
  • No attacks against the venue network, conference infrastructure, or any system not explicitly listed in scope.
  • No DoS or resource exhaustion against shared infrastructure or the scoring platform.
  • No attacks against the scoreboard, the CTF platform, or organizer systems.
  • Persistent backdoors on shared boxes that block other teams are forbidden.
Disqualification
  • Sharing flags or complete challenge solutions between teams.
  • Attacking systems outside the defined scope can result in immediate disqualification.
  • Deliberately disrupting another team's access, challenge environment, or progress is prohibited.
  • Repeated platform abuse or attacks against organizer infrastructure result in disqualification and ejection from the venue.
  • Disqualified teams will lose their eligibility for prizes and progression to Day 2.
Conduct & Disputes
  • The c0c0n Code of Conduct applies for the entire duration of the CTF.
  • Direct any complaints or disputes to the CTF organizers at the help desk, do not air them publicly.
  • Found a bug in the platform or the range itself? Report it privately. Do not exploit it for points.
  • Be respectful to other competitors, the organizers, and the venue staff.
  • Organizer decisions on conduct issues are final and binding.

Scoring & Challenge Progress

  • Each flag carries a fixed point value based on category and difficulty.
  • Points are awarded when the correct flag or required solution is submitted through the CTF platform.
  • Day 1 scores determine the teams that progress to Day 2.
  • The top 5 teams from Day 1 will receive access to the Day 2 closed environment.
  • Tiebreakers resolved by total time-to-capture across all flags.
  • Live scoreboard available throughout the competition. Updates may have a small lag.
  • Organizer decisions on scoring disputes are final.

Prizes

First Prize - Worth USD 3,498

OffSec Course + Certification Bundle

Win an OffSec Course + Certification Bundle and choose from eligible OffSec courses, excluding OSAI and OSEE. Each bundle includes access to the selected course and the corresponding certification exam.

  • Team Play: 2 OffSec Course + Certification Bundles for the First Prize-winning team
  • Individual Play: 1 OffSec Course + Certification Bundle for the First Prize winner

Register

Open to all registered c0c0n attendees with a valid event pass.

Register for the c0c0n before it's too late!

Registration starts on Day One at 9:00 A.M, 9 October, 2026 (Friday)

Partners

Together with organizations that support collaboration, innovation and a stronger cybersecurity community.