Team Kinetigor · Qualifier Sep 18, 04:30–16:30 UTC · Jeopardy · Humans submit flags
Registration open 6 contest games flag{...}Six Null Origin games
Your command screen: six Jeopardy columns, tools per game, our prep surfaces, agent demo, flag log.
8 drills · CTF terminal + ScenarioEngine
Eight competition lanes wired to real BountyWarz engines — hands-on payload terminal, OODA forensics drills, and Hunt recon. Clear required modules per category.
Pre-comp drill
Run the observation drill with a recorder. Measures time-to-first-action and submission flow.
OSCP · Security+ · CySA+
Fly London, breach CVE targets, pass security quizzes. All categories in one world.
CEH · OSINT fundamentals
Text range: scan hosts, observe evidence, name the weakness class. Same session as the 3D world.
Team coordination
Contest cockpit, extension sidebar, and local desk for game-day logging.
Each card links to an arena surface and a repo tool. Run local practice with python3 practice/verify.py in ctf-nullorigin.
OSCP · GWAPT · CPPT
CORS null-origin theme expected. SQLi, XSS, SSRF, LFI, auth bypass.
Security+ · CISSP
ROT13, RSA, classical ciphers. Use CyberChef for quick transforms.
GREM · OSCE
Static and dynamic analysis, XOR, strings, Ghidra workflow.
CEH · BTL1 OSINT
DNS, WHOIS, social traces, robots.txt, public metadata. Observation before exploitation.
GCFA · CHFI
File carving, trailing data, entropy, EXIF, memory and disk artifacts.
OSCP · GXPN · OSED
Buffer overflow, ret2win, checksec, pwntools, GDB.
CHFI · Security+
LSB, trailing bytes, steghide, zsteg, binwalk on every image.
pip install -r requirements.txt in ctf-nullorigin repo