technique-ctf
Installation
SKILL.md
Technique CTF
Solve any flag-style challenge with a category-agnostic loop: triage the artifact, identify the exact spec or format, drive the smallest correct interaction, and let the target's own responses steer each next input — then verify and submit the flag.
When this skill applies
- Any controlled lab/CTF objective: a remote service, a downloadable bundle, a puzzle artifact, or a skeleton client to complete.
- Before reaching for a domain skill, to decide which
*-ctfskill(s) to load and how to structure the attack. - Whenever a target emits parseable feedback — validation errors, diffs, status codes, timing, or partial output — that can be used as an oracle.
- When several independent challenges (or independent parameter variants of one challenge) can be worked in parallel.
Operating model
- Triage. Inventory what you were given: hash and list files, read the brief literally, note the target
host:port, the stated flag format, and every concrete value (IDs, keys, payload strings, ports). Identify the dominant artifact class — it selects the domain skill. - Identify the spec. Name the exact format/protocol/algorithm before writing an exploit. Match magic bytes, headers, wording, and cited standards. The brief usually states the spec and the exact expected input — build to that, not to placeholder values in any example code.
- Minimal correct interaction. Send the smallest well-formed unit and observe. Probe liveness both ways: some services greet with a banner, others reply only after you send — send-then-recv, do not hang waiting for a banner.
- Read the oracle. Treat every response as signal. Precise validators say exactly what is wrong (
expected X but got Y,invalid state, a stack trace, a length, a 401 vs 403, a timing delta). Walk the error chain field by field; each rejection names the next thing to fix. This beats guessing and beats blind brute force. - Iterate / brute the smallest unknown. When one field is genuinely ambiguous after the oracle is exhausted, brute only that minimal space (e.g. a counter × a type bit), reconnecting/resetting state per attempt. Never brute a large space blindly when a signal exists.
- Extract and verify. Pull the flag with a format regex, sanity-check it, and only then submit. If a submission API exists, use it; confirm acceptance. Do not paste flags into external services.