Poster: To Play or Not to Play: Insights and Lessons Learned from 20 Years of CTFs with ENOFLAG

arXiv:2607.13480 · cs.CR · Submitted 2026-07-15 · Read on arXiv

Jörg Schneider, Sebastian Neef, Sebastian Koch

cs.CR

Submitted: 2026-07-15

Comments: Preprint; To be published at DIMVA 2026 ( https://www.dimva.org/dimva2026/ )

Code: https://github.com/CTFd/CTFd

License: http://creativecommons.org/licenses/by/4.0/

The gist: Security contests in the form of CTF (Capture The Flag) exercises are nowadays a common way to learn cyber security.

Terminology

Abstract

Security contests in the form of CTF (Capture The Flag) exercises are nowadays a common way to learn cyber security. 20 years ago at DIMVA 2006 the on-site CTF CIPHER II was one of the conference highlights and led to the foundation of the team ENOFLAG. In this poster, we reflect on the changes in the CTF gameplay and report on lessons learned while running an academic CTF team for 20 years.

Related papers