ZenRage
Writing BreachPoint CTF Season 2 CTF challenge author, BREACH POINT (CTF)

I write CTF challenges that stay calm until you think you've solved them. Web, API, reverse engineering, IoT, blockchain, cryptography and steganography for breachpoint.live. Every hosted challenge ships as one clean Docker Compose stack with a flag injected fresh at boot.

The first thing you pull out will look exactly like the flag. It isn't.

Every hosted challenge is a Docker Compose stack that boots clean with one command, with the flag generated in memory at deploy time — nothing static, nothing reused across instances.

Solve chains stay in scope: no layer is there for padding, and the last step is usually gated on proving you actually understood the ones before it, not just brute-forcing your way past them.

Challenges shipped
21
Seasons written for
2
Categories covered
12
Difficulty range
Easy → Hard++

Challenges

Open any row for the story, the flag format and a nudge. Filter by season or category to narrow the list.

How these ship

Every hosted challenge is one Docker Compose stack, no manual setup steps, and a flag generated fresh in memory at boot. Play the live seasons at breachpoint.live.

challenge / deploy
$ docker compose up --build
Building gateway ... done
Starting gateway ... done
flag injected at boot — held in memory, unique per instance
>

Deployment & infrastructure

Challenge authoring stops at Docker; getting it live — and keeping it live — during a 24-to-36-hour competition window is its own job, across both seasons.

Season 1 is where this started: almost every deployment-class challenge in Siege of Troy — Break The Chain's lending/token/oracle/insurance stack, the NFT marketplace, Trusted Envoy's API surface — was containerized, deployed, and kept alive by hand during the live event, Dockerfiles and compose configs patched in place when something broke mid-competition rather than pulled and rebuilt from scratch. Hosting infrastructure came down again once the event closed; the writeups kept the live URLs as a record of what was actually running.

Season 2's insane-tier stack runs on Google Cloud — verified as a working host down to the kernel level, not just "it booted." Continuity Paradox needs a real kernel with eBPF and BTF support to attach a live syscall tracepoint, and can't run under a syscall-sandboxed runtime like gVisor or Kata; GCP was the actual target confirmed to meet that bar, including working around Intel TSX being disabled there rather than assuming it away.

S1 host ops
Live, by hand
S2 host
Google Cloud
Orchestration
Docker Compose
CI/CD
GitHub Actions
ControlDetail
Privilege modelScoped per challenge, not blanket-granted: cap_add: [BPF, PERFMON] instead of --privileged or CAP_SYS_ADMIN, then programmatically dropped from the bounding set before any player-reachable code runs.
Resource limitsPer-challenge mem_limit and cpus, tuned individually rather than a single shared default across the fleet.
Restart policyunless-stopped where a clean respawn is just recovery; on-failure where the crash-and-respawn cycle is part of the intended exploit path.
CI/CDGitHub Actions recomputes the readiness dashboard and challenge log straight from each folder's own README on every push touching a challenge category — the status board can't silently drift from what's actually in the repo.
Live event opsSame discipline extends into the event window itself: keeping instances up, isolated, and swapped or patched without disrupting a running scoreboard.

Where I've written

Two seasons of BreachPoint CTF, from junior member to lead challenge author.

  • 2026Season 2 — FederationWeb, API, Reverse, IoT, OT, Stegno, Misc · 10 challenges
  • 2026Cloud Deployment OperationsFull-time · Feb–Mar 2026, Hyderabad
  • 2026Season 1 — Siege of TroyReverse, Crypto, Blockchain, Pwn, Stegno, OSINT · 11 challenges
  • 2025Joined BREACH POINT (CTF)Part-time · Dec 2025–Feb 2026

What Season 1 participants said

Unedited feedback from teams after the 24-hour Siege of Troy run, via breachpoint.live.

Experience the challenges

breachpoint.live

Register and play the live seasons on the platform. For collaboration, commissions or anything else, reach me directly.