FAUST CTF has always been about having fun. While we do not limit how your team uses AI,
we want everyone to have fun and not feel forced to use AI in order to secure a good position
on the scoreboard.
We therefore provide an optional "low-llm" self-declaration during registration. Please see
our LLM Policy for eligibility and additional details.
FAUST CTF is an online attack-defense CTF competition run by FAUST, the CTF team of Friedrich-Alexander University Erlangen-Nürnberg. Its eleventh edition takes place on 26 September 2026.
Register nowFacts
Once again, the competition will work in classic attack-defense fashion. Each team will be given a Vulnbox image to host itself and VPN access. You will run exploits against other teams, capture flags and submit them to our server.
The service decryption password will be released at 2026-09-26 12:00 UTC. The actual competition will start at 13:00 UTC and run for eight hours.
News
Testing Vulnbox
Testing Vulnbox images are available. This is a testbox designed to test your setup in preparation for the CTF. This is not the final vulnbox and does not contain the services that will be used in the competition.On first login, the Vulnbox will ask you for some information and configure itself properly. You can log in as root using any of the following ways:
- Use SSH with the generated random password (may need port forwarding, for the NAT Network)
- Connect to the serial port of the VM (may need configuration)
- Use the graphical console of your virtualization software - not recommended if you want to deploy SSH-Keys or configure VPN.
- When hosting on a cloud provider, chances are that you can enter your SSH-Key when creating the VM (cloud-init is installed).
If you run into problems with the setup, try our suggestions from Basic Vulnbox hosting.
We provide two options for download:- An OVA bundle tested with VirtualBox
- A QCOW2 image tested with libvirt/KVM
To verify the integrity of your download, you may check the SHA256 sums.
Both images are identical, so use the one that fits your needs. The serivces inside are located in `/srv` and are encrypted with the password test.
To decrypt and start them, use the command /srv/extract-services.py /srv/testbox_services.tar.xz.gpg.
Note: Testbox and Vulnbox can not be connected to the game VPN at the same time, so make sure to shutdown the Testbox when the real Vulnbox is released.
Note: VPN configs are released in batches, so don't worry if you just signed up and there is no config to download yet..
Sponsored by Hetzner
Big thanks to Hetzner for sponsoring this years FAUST CTF again. Use their promo-code FAUST-CTF-2026 for 20€ of credits when registering a new Hetzner account.
Registration open (2026-09-04)
Registration is now open.
Date is released
We are happy to announce, that the FAUST CTF 2026 will take place on 2026-09-26 at 12:00 UTC. Registration will open soon.
