technique-ctf

Installation
SKILL.md

Technique CTF

Solve any flag-style challenge with a category-agnostic loop: triage the artifact, identify the exact spec or format, drive the smallest correct interaction, and let the target's own responses steer each next input — then verify and submit the flag.

When this skill applies

  • Any controlled lab/CTF objective: a remote service, a downloadable bundle, a puzzle artifact, or a skeleton client to complete.
  • Before reaching for a domain skill, to decide which *-ctf skill(s) to load and how to structure the attack.
  • Whenever a target emits parseable feedback — validation errors, diffs, status codes, timing, or partial output — that can be used as an oracle.
  • When several independent challenges (or independent parameter variants of one challenge) can be worked in parallel.

Operating model

  1. Triage. Inventory what you were given: hash and list files, read the brief literally, note the target host:port, the stated flag format, and every concrete value (IDs, keys, payload strings, ports). Identify the dominant artifact class — it selects the domain skill.
  2. Identify the spec. Name the exact format/protocol/algorithm before writing an exploit. Match magic bytes, headers, wording, and cited standards. The brief usually states the spec and the exact expected input — build to that, not to placeholder values in any example code.
  3. Minimal correct interaction. Send the smallest well-formed unit and observe. Probe liveness both ways: some services greet with a banner, others reply only after you send — send-then-recv, do not hang waiting for a banner.
  4. Read the oracle. Treat every response as signal. Precise validators say exactly what is wrong (expected X but got Y, invalid state, a stack trace, a length, a 401 vs 403, a timing delta). Walk the error chain field by field; each rejection names the next thing to fix. This beats guessing and beats blind brute force.
  5. Iterate / brute the smallest unknown. When one field is genuinely ambiguous after the oracle is exhausted, brute only that minimal space (e.g. a counter × a type bit), reconnecting/resetting state per attempt. Never brute a large space blindly when a signal exists.
  6. Extract and verify. Pull the flag with a format regex, sanity-check it, and only then submit. If a submission API exists, use it; confirm acceptance. Do not paste flags into external services.
Installs
4
GitHub Stars
22
First Seen
Sep 5, 2026
technique-ctf — aeondave/malskill