Glossary · Term

capture-the-flag

← all terms

Definition

Plain language

A hacking competition where you prove you broke into a system by retrieving a hidden token.

As stated in the literature

A security exercise (CTF) in which participants solve exploitation challenges to recover a hidden 'flag' string; used as a source of genuinely difficult offensive-security tasks in distributed-attack and vulnerability benchmarks.

Also called: CTF, capture the flag

Why it matters: These contests provide realistic, hard hacking challenges that can be used to test how capable AI systems are at offensive security.

For example, a contestant might exploit a weakness in a target program to read a secret token like 'flag{you_win}' and submit it for points.

Heard on the show

“Most prior work on agentic vulnerability discovery worked on source code or capture-the-flag challenges — controlled environments.”
Episode 024 — An AI Agent That Found 28 Zero-Days in Windows — And What Made It Work

Related terms