The Ascent drops you into a penetration test engagement with a minimal briefing: get inside, reach the cloud, retrieve the data. You’re already through the door, but all you have is a laptop and one objective. The company’s crown jewels are sitting somewhere in a cloud environment and the only way to reach them is to find your way through each stage, one by one. What comes next is yours to discover.
One mission. One kill chain. Each stage unlocks the next. You earn points for every stage you get through and the challenges scale in difficulty to mirror a real-world engagement, with no shortcuts and no skipping ahead. So, it’s you, the infrastructure and sixty minutes. The Ascent is the battleground for offensive security enthusiasts ready to prove they can go the whole way from a locked network to the cloud.
Players should have penetration testing skills, networking, service enumeration and web exploitation. Cloud and VPN concepts being a plus but not required.
Goal
Goal of the Competition
Rules
– Bring yourself and a laptop, everything else you need is provided at the stand.
– The competition runs in rounds of up to 5 players at a time, with a 60-minute time limit per round so sign up to reserve your slot.
– Each player receives their own isolated instance of the target, no attacking other players or shared infrastructure.
– Points are awarded per stage. Hints are available but reduce that stage points.
– Ties are broken by furthest stage reached, then by time, then by fewest hints used.
– Use any tools and scripts you like.
– Scope Definition: The scope of the competition will be explicitly defined and communicated by the organizers prior to the start of the event. Contestants must adhere to the defined scope, which may include network devices, specific targets, systems or applications within the simulated environment. Any attempts to access systems beyond the scope are strictly prohibited.
– Denial of Service (DoS) Prohibition: Participants are strictly prohibited from engaging in any form of Denial of Service (DoS) attacks against the competition environment. This includes but is not limited to flooding, overloading, or otherwise disrupting the availability or functionality of systems.
– Fair Play and Non-Disruption: The spirit of the competition is based on fair play and ethical hacking. Any actions intended to disrupt the competition, such as hiding or tampering the flags once found, engaging in cheating, or sabotaging the progress of other participants, will not be tolerated and may lead to immediate disqualification.
– Compliance with Laws and Regulations: All participants are required to comply with local, national, and international laws and regulations related to computer security and ethical hacking. Any illegal activities or actions that could potentially harm the competition environment, participants, or external systems are strictly prohibited.
– Respect for Privacy: Contestants must respect user privacy and any personal data discovered during the competition must not be disclosed or exploited in any way. Participants are expected to handle sensitive information with the utmost care and ethics.
– Responsible Disclosure: If participants discover unknown vulnerabilities during the competition, they should report them to the organizers. Exploitation of undisclosed vulnerabilities that were not part of the competition’s scope is prohibited.
– Time Limitation: The competition is time-limited, and participants must adhere to the specified start and end times. All activities must cease at the conclusion of the competition.
– Sportsmanship: Participants are expected to maintain a high level of sportsmanship throughout the competition. Any disrespectful or unsportsmanlike behavior towards fellow participants, organizers, or sponsors will not be tolerated.
– Organizer’s Authority: The organizers have the final authority in all matters related to the competition. Their decisions are binding and any disputes or rule violations will be addressed by the organizing committee.
– Consequences of Violations: Violations of these rules may result in penalties, disqualification, or other actions as determined by the organizers, which may include banning participants from future competitions.
– The Ascent is designed to be a challenging but fair cybersecurity competition and adherence to these rules ensures a positive and ethical environment for all participants.
PRIZES
TBD
REGISTRATION
- You need to have an account on CyberEDU. Register here or login here.
- Authenticate in your account and click on this link (this is required only the first time). This will give you access to a private space called “DefCamp”. See the picture below.

- Go to section Compete as instructed. You should see all the active contests.
- Click on any contest of interest and make the Pre-Registration.
- Have fun!

