# CTF Starter Guide

Capture The Flag exercises are legal training environments designed to teach
security concepts. Only attack the challenge systems provided by the CTF
organizer, and never reuse techniques against real systems without permission.

## Recommended Lab Setup
- A dedicated VM or container workspace.
- Python 3, Git, curl, jq, Wireshark, and a text editor.
- Burp Suite Community or browser dev tools for web challenges.
- Ghidra or Cutter for reversing challenges.
- CyberChef for encoding and decoding practice.

## Challenge Categories
- Web: authentication logic, input handling, sessions, and source review.
- Crypto: weak implementations, encoding mistakes, and math puzzles.
- Forensics: files, packets, logs, memory images, and timelines.
- Reversing: binaries, bytecode, and program behavior.
- Pwn: memory safety in isolated lab binaries.
- OSINT: public clues intentionally placed by challenge authors.

## Beginner Workflow
1. Read the challenge description twice and write down constraints.
2. Identify file types with `file`, `strings`, and metadata tools.
3. Keep notes of every command, assumption, and dead end.
4. Start with the simplest hypothesis before using advanced tools.
5. Validate the flag format before submitting.

## Safe Practice Rules
- Stay inside the CTF target list.
- Do not scan unrelated internet hosts.
- Do not attack other players or infrastructure.
- Do not publish active challenge spoilers without organizer permission.

## Learning Path
- Week 1: Linux shell, Python scripting, encodings, HTTP basics.
- Week 2: Web auth/session labs and OWASP Top 10 reading.
- Week 3: PCAP and file forensics practice.
- Week 4: Intro reversing with simple crackmes in a VM.
