GCTF://FAQ
FAQ
Format, eligibility, and how Girls in CTF 2026 runs.
-
What is this event?
Girls in CTF 2026 is a cybersecurity competition for women and girls: a Jeopardy qualifying round, then head-to-head finals for the top Malaysian teams.
-
Who can join?
Open only to women and girls. Qualifying is open to Malaysian students and professionals; international participants may join the Qualifying Round subject to confirmation. The Final Round is for Malaysian participants only.
-
How do I participate?
Register an account, complete your profile, then create or join a team. When the board opens, solve challenges and submit flags.
-
What is the qualifying round?
Classic Jeopardy-style CTF (~20 hours, 9:00 PM – 4:00 PM next day GMT+8). Dynamic scoring. Categories typically include web, crypto, reverse, pwn, forensics, misc, and more.
-
How do finals work?
Top 8 teams advance to head-to-head matches (~5 hours window, 5:00 PM – 10:00 PM GMT+8). Each match lasts at most 30 minutes. Double-elimination — Winners Bracket and Losers Bracket.
-
Final match format
Before each match, each team bans one challenge category — the opponent learns the ban when the match starts. Each match has two challenges. Win by solving all first, or by fastest completion if neither team finishes all.
-
Can I use AI?
Yes — three leaderboards. Human is traditional CTF. Humanoid is human + AI you built yourself, no agents, no LLMs, no Codex. Cyborg is full AI. Pick a bracket and stay there. Full detail is on the AI Policy page.
-
Where are the rules?
Attack challenges, not infrastructure. No flag sharing outside your team. See Rules for conduct and scope, and tickets/Discord for support.