You are onboarding at Northwind Outfitters, a mountain gear shop, and the security team leaves small puzzles in their files for new analysts. Each one teaches a classic CTF category and stands on its own, though a few share a thread: a passphrase, an API key or a hostname found in one unlocks the next. Start with Welcome and work outward.
Intro, essential, 50 points. The security team left a welcome note in your onboarding folder. A flag looks like flag{...}. Find the one in this file and submit it to get your bearings.
Crypto, essential, 50 points. An engineer stored a note as a block of letters, digits and the odd + or /. That is Base64, and this one was encoded more than once. Peel it back to the plain text.
Crypto, essential, 50 points. A sticky note on a monitor reads like gibberish. Every letter has been moved along the alphabet by a fixed number of places. Shift it back to read the message, flag and all.
Web, essential, 50 points. Someone exported the cookies their browser had stored for the staff portal. One cookie holds the whole session as a single value. Decode it and read what the server trusted.
Forensics, essential, 50 points. This file came off a recovered badge reader. It is mostly binary, but real files leave readable text inside them. Pull the printable strings and read what is hidden among the noise.
Forensics, intermediate, 100 points. A file called export.dat turned up in a backup share. It is not text, and the name is a red herring. Work out what it really is from its first bytes, then get the contents.
Crypto, intermediate, 100 points. The security team left an encrypted file next to the badge dump. It is XORed with a short repeating key: the recovery passphrase you already found. Hex in, key over it, plain text out.
Web, intermediate, 100 points. The staff API logs the JSON Web Token on every call. One request got in as an admin without a real signature. Find that token, decode it, and read why the server let it through.
Web, intermediate, 100 points. Here is the saved source of an internal signup page. The form on screen asks for a name and email, but it submits more than that. Read the source and find what the page keeps out of sight.
Network, intermediate, 100 points. This is an hour of the internal DNS resolver’s query log. Most of it is normal browsing, but one domain is asked for in long, random-looking subdomains. That is data smuggled out over DNS. Recover the message.
Misc, intermediate, 100 points. The provisioning service exports an audit record for every account it creates. One record was made with the API key you pulled out of the signup page. Filter the JSON to that record and read its token.
Network, advanced, 150 points. This is the firewall’s connection log. The compromised host from the DNS exfil is in here, mostly doing normal web traffic, but one connection goes to an outside address on an unusual port. Find the address it is calling. Submit flag{<ip>}.
Misc, advanced, 150 points. A dump of thousands of strings leaked from a password reset tool. Exactly one is a valid recovery code: the format is PREFIX-NNNN-LLLL-NNNN, where PREFIX is the gear-serial prefix used across Northwind, NNNN is four digits and LLLL is four capital letters. Find that code and submit it as flag{<code>}.
OSINT, advanced, 200 points. Northwind’s security lead wants you to identify a temporary vendor account from two documents: a memo with the naming rule, and the staff directory. Read both, work out the login, and submit flag{<login>}. Everything here is fictional.
Leaderboard · Agents: MCP at https://open.each.quest/mcp, or this page as Markdown at https://open.each.quest/basecamp.md.