FinishedOpen competition for Syrian university students
Al-Kindi

Al-Kindi CTF

Named for the man who invented codebreaking.

A live competition for teams of two to four, open to students at Syrian universities. Every challenge teaches one technique, and the challenges are independent, so a team stuck on one is never blocked on the rest.

An open competition, run in partnership with Syrian universities

Held on 19 September 2026, online on Discord, with a live stream and a live scoreboard. Nearly five hours, with 35 teams on the board.

Final standings

The eleven teams that placed are below; all 35 are on the full scoreboard. Points only stood where a team kept to the rules: one lost 200 for using AI where the rules did not allow it, another lost 400 for not turning up to explain a solve.

#1

Alpha Team

1900 points · 7 solves

#2

Syndicate

1400 points · 6 solves

#3

Fsociety

750 points · 4 solves

PlaceTeamScoreSolves
1Alpha Team19007
2Syndicate14006
3Fsociety7504
4USSR7504
5m3rok bltmr7504
6VASES5503
7APT05504
8Rever$eAck4504
9Maltivista9114503
10CryptoKnight4503
11We don't hack Instagram accounts4503

Special mention

Top all-girls teamReverseEngi-tears250 points · 2 solves

Why al-Kindi

Abu Yusuf Ya'qub al-Kindi wrote On Deciphering Cryptographic Messages in Baghdad around the year 850. In it he described frequency analysis: count how often each symbol appears in the ciphertext, compare that against ordinary language, and a substitution cipher falls apart. The technique broke ciphers for the next seven hundred years, and Europe did not arrive at it independently until the Renaissance. He did not write about codebreaking. He founded it.

Format

StyleOnline, on Discord
Teams2 to 4 players
LengthAbout 3 hours
Open toEveryone

Categories

OSINTForensicsWebAndroidReversingNetworkPwn

Points

What each category is worth. Challenges are independent, so if one is not moving, leave it and come back.

Forensics100
Reversing100
Web200
Android200
OSINT200
Network300
Pwn400
Total on the board1500

These figures are approximate. The final scoring is explained live, a quarter of an hour before the contest starts.

Watch on YouTube

A few things about the CTF

Live, with commentary

The whole contest is streamed. Someone talks through what is happening, and the scoreboard updates as teams take flags.

Everyone in one Discord

Teams join the Discord server before the start and stay in it to the end. Questions, announcements and scoring all go through there.

Share your screen, get a hint

Any team that keeps its screen shared in Discord for the whole contest gets one small hint.

Briefing 15 minutes before

The rules, the scoring and anything that changed are explained on the YouTube live, a quarter of an hour before the clock starts.

The top five defend their solves

The five teams at the top of the board answer questions on Discord about the flags they took. A team that cannot explain its own solves loses its place.

AI is allowed, up to a point

Ask it, read with it, learn from it. What is not allowed is dropping a challenge file into a tool, running it, and letting it hand you the solution. A flag you cannot explain will not survive the live questions at the end.

What you take away

We could not fund this one: there is not much interest in the field in Syria yet. We hope the next one is backed, whether by government or by a company. For now there is no prize money, only recognition.

Top 10A certificate of participation.
Top 3The option to join the first Rushd cybersecurity cohort and be mentored through it.

Who wrote the challenges

Syrians, all of them. We went after the best people in the field we could reach: some never replied, others sat down and helped us shape this. Every one of them holds a cybersecurity certification, works in the field, or both. We name them on the day of the contest.

New to cybersecurity?

You do not need to arrive ready. Our fundamentals roadmap starts at Linux and works up through web exploitation and network testing, red team and blue team both, and every step on it is free.