GCTF://FAQ

FAQ

Format, eligibility, and how Girls in CTF 2026 runs.

  1. What is this event?

    Girls in CTF 2026 is a cybersecurity competition for women and girls: a Jeopardy qualifying round, then head-to-head finals for the top Malaysian teams.

  2. Who can join?

    Open only to women and girls. Qualifying is open to Malaysian students and professionals; international participants may join the Qualifying Round subject to confirmation. The Final Round is for Malaysian participants only.

  3. How do I participate?

    Register an account, complete your profile, then create or join a team. When the board opens, solve challenges and submit flags.

  4. What is the qualifying round?

    Classic Jeopardy-style CTF (~20 hours, 9:00 PM – 4:00 PM next day GMT+8). Dynamic scoring. Categories typically include web, crypto, reverse, pwn, forensics, misc, and more.

  5. How do finals work?

    Top 8 teams advance to head-to-head matches (~5 hours window, 5:00 PM – 10:00 PM GMT+8). Each match lasts at most 30 minutes. Double-elimination — Winners Bracket and Losers Bracket.

  6. Final match format

    Before each match, each team bans one challenge category — the opponent learns the ban when the match starts. Each match has two challenges. Win by solving all first, or by fastest completion if neither team finishes all.

  7. Can I use AI?

    Yes — three leaderboards. Human is traditional CTF. Humanoid is human + AI you built yourself, no agents, no LLMs, no Codex. Cyborg is full AI. Pick a bracket and stay there. Full detail is on the AI Policy page.

  8. Where are the rules?

    Attack challenges, not infrastructure. No flag sharing outside your team. See Rules for conduct and scope, and tickets/Discord for support.