# CTF Wiki: A Free Reference for Learning Capture the Flag Security Competitions

> CTF Wiki is a community-written reference site for Capture the Flag competitions, covering the techniques and tools used in categories such as pwn, web security, cryptography, and forensics. It was established on GitHub in October 2016, builds with mkdocs, and runs locally or via Docker.

**ctf-wiki/ctf-wiki** — Come and join us, we need you!

- Repository: https://github.com/ctf-wiki/ctf-wiki
- Website: https://ctf-wiki.org
- Stars: 9,667 · Forks: 1,440
- Language: Python
- License: NOASSERTION
- Published: 2026-09-21 · Updated: 2026-09-21 · Language: en
- Canonical page: https://hysenlabs.com/projects/ctf-wiki-ctf-wiki

## What CTF Wiki is and who it is for

CTF Wiki is a free reference site for Capture the Flag security competitions, established on GitHub in October 2016 by a community of security enthusiasts. CTF competitions originated at DEFCON in 1996 and have grown into a major format for competitive security learning. Players solve security challenges across categories that typically include binary exploitation (pwn), web security, cryptography, reverse engineering, and forensics. The README acknowledges that online information about CTF is scattered and that the learning curve for beginners is steep, which is the problem CTF Wiki addresses by providing a structured, indexed reference in one place. The target reader is someone new to CTF competitions who needs to learn foundational techniques before or during their first events. The site is deployed publicly at ctf-wiki.org; local hosting is also supported for contributors or readers who prefer an offline copy.

## How CTF Wiki covers security competition topics

The site currently focuses on the basic skills required for CTF competitions. The README identifies two areas planned for future expansion: advanced CTF techniques and special topics that appear in competitions. Beyond the competition focus, the project plans to add content about tools used in general security research and broader security discussions. One stated policy stands out: CTF Wiki will never publish books. The README frames this as a deliberate choice tied to the principle that new techniques replace old ones, and that a fixed printed text would become stale. The site is intended to be updated as the field evolves. Content covers techniques in the categories that appear in CTF competitions, with sections accessible at ctf-wiki.org. The ctf-wiki/ctf-wiki repository is the content and build source; the deployed site is the intended primary reading interface.

## Repository organization and the sister repositories

The top-level structure is: a docs/ directory containing the actual wiki content as Markdown files, a scripts/ directory with the Python build scripts, a requirements.txt listing the mkdocs dependencies, and a Dockerfile for container-based serving. The content in docs/ is the core; the rest is build infrastructure. CTF Wiki has two companion repositories. The ctf-challenges repository contains the practice challenges mentioned in articles, organized by category, so readers can follow a technique explanation with a corresponding hands-on problem. The ctf-tools repository holds the tools that the wiki references in its technique descriptions. Together the three repositories form a study system: ctf-wiki for reading, ctf-challenges for practice, and ctf-tools for the tooling. The README recommends learning to ask smart questions and using Google for self-directed research alongside reading the wiki.

## Building and running CTF Wiki locally

The wiki uses mkdocs, a Python-based static site generator, with the mkdocs-material theme. To build and serve locally:

```shell
# 1. clone
git clone https://github.com/ctf-wiki/ctf-wiki.git
# 2. requirements
pip install -r requirements.txt
# generate static file in site/
python3 scripts/docs.py build-all
# deploy at http://127.0.0.1:8008
python3 scripts/docs.py serve
```

The build-all command generates static files in a site/ directory, and serve starts a local server on port 8008. Changes to Markdown files in docs/ are picked up dynamically during a serve session. For a fully static deployment without setting up Python, Docker is the alternative:

```
docker run -d --name=ctf-wiki -p 4100:80 ctfwiki/ctf-wiki
```

This pulls the pre-built image and serves the wiki at http://localhost:4100/.

## What CTF Wiki covers and what it leaves out

The README is direct about the current scope: the wiki mainly contains basic CTF skills. Advanced techniques and special competition topics are identified as planned content, not yet written. CTF Wiki does not host competition challenges itself; those live in ctf-challenges. It does not provide a scoring system, a competition platform, or interactive labs. The site is a reference, not an environment. Two languages are documented: the English README points to the English content; README-zh_CN.md covers the Chinese version. The wiki advocates freedom of knowledge and states it will never be commercialized. It has an independence policy similar to a community wiki: no single organization controls it commercially. The limitations section of the README offers advice that is unusually direct about prerequisites: learn to ask smart questions, know at least one programming language such as Python, and practice actively.

## CTF Wiki versus HackTheBox: reference versus interactive lab

HackTheBox is a commercial platform that provides hosted, interactive virtual machines for security practice. Players connect to those machines over VPN and try to gain access to flags. HackTheBox includes scoring, leaderboards, and a structured learning path. CTF Wiki provides none of those features; it is a text reference. The practical difference is that reading CTF Wiki gives you the conceptual background for a technique, while HackTheBox gives you a machine to apply that technique on. The two are complementary rather than competing: reading about a stack overflow technique in CTF Wiki and then practicing it on a HackTheBox machine is a natural study workflow. CTF Wiki is free with no account required; HackTheBox has paid tiers for certain content.

## License status and maintenance

The repository license field is listed as NOASSERTION, meaning the license was not recognized by GitHub's automated detection. The README links to a LICENSE file but does not state a specific SPDX identifier. Before redistributing or publishing content derived from CTF Wiki, reviewing the LICENSE file directly is necessary to understand the terms. The contributing guide is at ctf-wiki.org/en/contribute/before-contributing/. The README lists specific attributes the project values in contributors: the ability to learn quickly, problem-solving orientation, and a sustained interest in security techniques. Contributions go through a review process documented at the contributing guide URL before being merged into the site. The last push to the repository was on 2026-08-23, reflecting ongoing content updates to the wiki.

## Conclusion

CTF Wiki is the right starting point for someone learning Capture the Flag competitions who wants a structured, free reference to read before and during competitions. It does not host challenges; for practice problems, the companion ctf-challenges repository organizes examples by category. For anyone building a new iOS project or looking for hosted labs with scoring, CTF Wiki is not the answer. Check the license status (NOASSERTION) before redistributing content; the wiki policy states it will never publish books and will never be commercialized.

## FAQ

### What does CTF stand for?

CTF stands for Capture the Flag. It is a competitive format for computer security challenges where participants solve problems in areas like binary exploitation, web security, cryptography, and forensics to capture a flag string that proves they solved the challenge. The format originated at DEFCON in 1996.

### What is CTF and how does it work?

CTF competitions present security challenges across multiple categories. Participants analyze programs, web applications, encrypted messages, or forensic data to find a hidden flag string. Solving a challenge earns points, and the team or individual with the most points wins. CTF Wiki covers the foundational techniques needed to approach these challenges.

### What is CTF used for?

CTF competitions are used for learning and practicing computer security skills in a structured, competitive format. They also serve as a way to demonstrate technical ability to employers. CTF Wiki specifically targets people who want to learn CTF techniques from a free, indexed reference.

## Sources

- [ctf-wiki/ctf-wiki on GitHub](https://github.com/ctf-wiki/ctf-wiki)
- [Issues](https://github.com/ctf-wiki/ctf-wiki/issues)
- [Project website](https://ctf-wiki.org)
- [README](https://github.com/ctf-wiki/ctf-wiki/blob/master/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/ctf-wiki-ctf-wiki
