Framework
0Chencc/CTFCrackTools avatar
0Chencc/CTFCrackTools

CTFCrackTools X replaces a form full of ciphers with a node canvas

The next-generation CTF Swiss Army Knife powered by Rust & Tauri. Features a visual node-based workflow and local AI intelligence for extreme performance and automation.China's first CTFTools framework.

2,163 stars306 forksRustGPL-3.0

At a glance

What is it?
CTFCrackTools X is a Rust and Tauri rebuild of a 2016 CTF toolbox that trades a long form of cipher inputs for a React Flow canvas where encoders, hashes and classical ciphers are wired together. It ships as one native binary per platform, and its algorithm list stops at five symmetric ciphers.
Who is it for?
If you are learning ciphers, teaching them, or working CTF tasks where you want to see every intermediate value, CTFCrackTools X is worth installing: the graph is the point, the download is a single file, and the GPL-3.0 licence is harmless for study and awkward for commercial redistribution. Skip it if your work needs RSA or ECDSA, if you need to script conversions inside a pipeline, or if a permissive licence is required where you work.
Can I use it commercially?
Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
Is it still maintained?
Yes. The repository last received commits 150 days ago.
What is it written in?
Mainly Rust, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.

Editorial analysis

Why the form UI of V4 became a graph

CTFCrackTools first shipped in 2016, and the author's note at the end of the README is unusually blunt about what it was: a beginner's tool, not a serious one. Version X is a rewrite rather than an increment, and the README frames it as a table. V4 had a traditional form, ran on a Java runtime, weighed about 50MB or more, and needed a JRE installed before it started. X has a node-based workflow, runs natively, and the same table places it under 15MB. The person this is for is a competitor at two in the morning with a Base64 string that decodes into something else, and the problem the rewrite attacks is the mismatch between a form and a solve. In a form, every algorithm gets its own row of inputs and its own output box. In a real chain, the interesting part is the order of the steps and the intermediate values between them, and a graph keeps those visible and lets you rewire them when a step turns out to be wrong.

Input, an encoding node, Output, and the wiring between

The canvas is React Flow inside a Tauri shell. package.json pins reactflow at ^11.11.4 and zustand at ^5.0.12, with React 19.2.4 and Tailwind 4 bundled through Vite 7. The workflow the README describes takes four moves: download a build for your system, start the app to an empty canvas, right-click to add nodes, then connect an Input to an encoding node to an Output, type your text and execute. That is the entire data flow, and it is deliberately thin. Nothing in the documentation describes a node with two inputs, a conditional branch, a loop, or a node that reads a file from disk. The dependency list does contain @tauri-apps/plugin-dialog and @tauri-apps/plugin-fs, which is what a file picker would be built on, but the README never says which node uses them. If your solve depends on unpacking a binary or opening an attachment before decoding anything, expect to do that step outside the canvas and paste the result in.

The algorithm list is symmetric crypto only

Five groups are disclosed, and the counts in their headings add up to 44 named algorithms, a little above the 43+ the section header claims. Encoding takes 15: Base64, Base32, Base58, Base85, Hex, URL, ASCII, Binary, Morse, UUEncode, ROT47, Unicode, HTML Entity, JWT Decode and Brainfuck. Classical ciphers take 11, from Caesar, ROT13 and Atbash through Vigenère, Beaufort, Playfair, Polybius, Affine, Rail Fence, Bacon and XOR. Modern crypto gets 5, and all five are symmetric: AES-128-CBC, DES, 3DES, Blowfish and RC4. Hash and KDF takes 6, which is MD5, SHA1, SHA256, SHA512, HMAC-SHA256 and PBKDF2. Text processing takes 7 and ends with Length. The gap that matters is the modern crypto group. There is no RSA, no DSA, no ECDSA and no curve arithmetic anywhere in the list, and JWT appears only as a decode operation with no signature verification named. For a challenge category that is usually decided by key exchange, five symmetric ciphers is a short answer.

There is no install step, only a download and one chmod

The download section points at the Releases page and gives the exact artefact name for each platform: ctfcracktools-x-{version}-windows-x64.exe on Windows x64, ctfcracktools-x-{version}-macos-arm64.dmg and ctfcracktools-x-{version}-macos-x64.dmg for the two macOS architectures, and ctfcracktools-x-{version}-linux-x64 for Linux, which arrives with no file extension at all. The single command in the whole documentation is a permission fix for that Linux build:

bash
chmod +x ctfcracktools-x-*

Run the binary or open the disk image and you land on an empty canvas, with no runtime to install because the README states the app is native on Windows, macOS and Linux. That is the concrete gain over V4, where a JRE was a prerequisite. What the download section does not offer is a checksum, a signature, or a build provenance note, so on a shared machine you are trusting the release artefact itself.

Source builds run through pnpm, Tauri 2 and a complexity gate

The README does not document building from source, but the repository carries the full Tauri layout with src-tauri/ beside src/, a pnpm-lock.yaml, and a package.json with conventional scripts. The build script is tsc -b && vite build and the dev script is vite. The part worth reading is the ci gate, which is a single shell chain:

bash
pnpm typecheck && pnpm lint && pnpm lint:complexity

That last pass is not ceremonial. It switches on three limits the default eslint configuration would not enforce: complexity capped at 15, max-depth at 4, and max-lines-per-function at 100. For a codebase that is mostly algorithm implementations, a hundred-line function ceiling is a real constraint on how you write a cipher, and it tells you what the maintainer considers too long before you open a pull request. Running those three commands is the check the project built for itself.

No export, no shortcuts, and an AI claim nobody explains

Several things a user looks for first are missing from the documentation. There is no mention of saving or exporting a graph, no undo, no clipboard behaviour, and no keyboard shortcut list. Extensibility appears only in the branding, where X stands for eXtreme, eXtensible and neXt, yet there is no plugin API, no custom node guide and no scripting surface, so read that letter as an intention. More pointed, the repository description advertises a visual node-based workflow plus local AI intelligence, and no part of the README explains what the local AI does, what it runs on, or whether it needs a download before it works. The root also holds docs/ and scripts/ directories that the README leaves undescribed. The author note is worth keeping in view, because the person who wrote it says plainly that the tool was never among the good ones.

GPL-3.0 and a release history with a visible gap

The licence is GPL-3.0, with LICENSE at the repository root. That is the opposite of a permissive choice, and it matters on the first day if you ever intend to ship this inside a closed product, because a rewrite of an older tool does not inherit the freedom you had with V4. On cadence, three releases are visible: v0.1.0 on 2025-12-25, v0.1.1 on 2026-02-06, and v0.1.2 on 2026-05-05, which is also the date of the last push to main. That is one release every two to three months, with nothing committed since 2026-05-05. Sitting at version 0.1.x is its own signal, and for a tool whose main interaction is dragging nodes around a canvas, a changed layout in a later release costs more than a changed command line would.

Where a browser toolbox or a shell one-liner fits better

Two alternatives cover the same ground with different trade-offs. A browser toolbox such as CyberChef carries a far larger catalogue of operations and also has a command line mode for scripted work, so nothing is installed and nothing is platform specific, at the price of handling local files inside a tab. A shell pipeline built from base64, xxd and openssl covers the encoding and hashing half of this list with tools already on the machine, and it is pipeable and scriptable in a way no node canvas is; what it does not give you is the visible chain of intermediate values. CTFCrackTools X sits between the two: a local native binary with a small curated node set and a graph you can rewire. That is the right shape for learning a cipher by trying variants, and the wrong shape for an asymmetric challenge or for a conversion that has to run unattended in a script.

Editorial conclusion

If you are learning ciphers, teaching them, or working CTF tasks where you want to see every intermediate value, CTFCrackTools X is worth installing: the graph is the point, the download is a single file, and the GPL-3.0 licence is harmless for study and awkward for commercial redistribution. Skip it if your work needs RSA or ECDSA, if you need to script conversions inside a pipeline, or if a permissive licence is required where you work. Verify three things before you commit: that the five modern crypto entries still match your challenge set, that the local AI feature named in the repository description does something you need, since the README never explains it, and whether anything newer than v0.1.2 from 2026-05-05 has been released before you pin a version.

Frequently asked questions

Does CTFCrackTools X need a Java runtime?

No. The README's comparison table lists a JRE as a V4 requirement and describes X as native on Windows, macOS and Linux with no runtime to install.

Which algorithms are built into CTFCrackTools X?

Five groups are listed: 15 encoding operations, 11 classical ciphers, 5 modern ciphers, 6 hash and KDF entries, and 7 text operations, including AES-128-CBC, RC4, PBKDF2 and JWT Decode.

How do I run the Linux build of CTFCrackTools X?

Download ctfcracktools-x-{version}-linux-x64 from the Releases page, then make it executable with the command the README gives: chmod +x ctfcracktools-x-*

Does CTFCrackTools X support RSA or other asymmetric algorithms?

No asymmetric entry appears in the list. The modern crypto group is AES-128-CBC, DES, 3DES, Blowfish and RC4, and JWT is offered as a decode operation only.

Can I save a workflow I build in CTFCrackTools X?

The README does not document saving, exporting or reopening a graph, and it gives no keyboard shortcut list either. A custom node or plugin interface is not described either, despite the eXtensible framing of the X name.

Official sources

  1. 0Chencc/CTFCrackTools on GitHub
  2. License: GPL-3.0
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/0chencc-ctfcracktools.svg)](https://hysenlabs.com/projects/0chencc-ctfcracktools)