Competition (CTF)

May 14-15-16, 2027

The CTF

Our applied security competition (Capture The Flag) pits 90+ teams of 8 people against each other to obtain the most points by capturing flags.

Flags are secret messages hidden in security challenges across multiple disciplines. Teams compete through a web portal on a private competition network. Attacking other teams is not allowed: it's a race to the top of the leaderboard.

Past editions Event photos Write-ups CTFtime

Buy Tickets
NorthSec CTF

Two CTF Experiences

New in 2027: register in one of the two CTF experiences: regular or AI.

Regular CTF

Our main competition. The use of generative AI on challenge context is forbidden. Choose this experience if you want to learn deep cybersecurity knowledge through practice, the way CTFs have always been played.

AI CTF

Any generative AI is allowed, with no restrictions. This is meant for players who want to experiment with AI agents and learn their limits on real challenges. Bring your own AI subscription/model.

Both CTFs feature the same challenges, including the physical tracks. Challenges are designed to be solved by humans and provide learning opportunities for humans.

NorthSec Originals

Every NorthSec edition has its own narrative theme, one of the event's signature elements.

Hackacademy

A dedicated path for first-time players, with a gentler ramp-up that helps new teams get started and keep building momentum.

IPv6 Network

A private competition network built around IPv6, so every service, route, and challenge feels like part of a living infrastructure.

Complete Theme Narrative

Each year, the narrative theme carries through the challenges, badge flow, and infrastructure to shape a cohesive CTF experience.

Per-Team Infrastructure

Each team gets its own set of containers with identical resources, ensuring a fair competition for everyone.

Hardware Badge

This year's hackable electronic badge is fully integrated into the CTF. Solve badge challenges to earn points.

Physical Tracks

Hands-on challenges that require being on site: lockpicking, badge firmware tampering, RFID/smartcard attacks, kiosk escape scenarios, and hardware fault injection.

Hacker Jeopardy

During Hacker Jeopardy on Saturday night, the CTF closes for the segment. Grab a beer and watch your peers fail easy questions because of stage fright.

FAQ

Frequently asked questions about the CTF.

No, participants registering alone or with an incomplete team will be merged with other participants.

For most people, the regular CTF is the best choice to maximize your learning experience. When learning by doing, you'll gain skills that are directly applicable to real-world cybersecurity. Even in the agentic AI era, these skills are important to correctly use AI tools, truely understand their output, knowing when to trust or question their responses and how to steer them.

The AI CTF, on the other hand, is recommended for people who are already experienced cybersecurity practitionners and specifically want to experiment/learn about how to use generative AI, their capabilities and their limits. Maybe you want to see how local models can solve challenges autonomously from your own laptop, or you want to test your harness against the most difficult challenges of the CTF or just want to solve CTF challenges with a little more help from AI.

Yes, you can edit your ticket to change your experience up to Monday the week of the CTF.

You may switch from the regular CTF to the AI CTF, but you cannot switch from the AI CTF to the regular CTF.

You may use any generative AI tool as a teacher/intelligent search engine or use it to generate code and scripts, as long as you do not copy/paste or retranscribe context from the CTF into a generative AI tool. Context includes any challenge details, code, files, servers, domain names or physical artifacts.
In short: the AI can facilitate research or assist script writing, but must not do any problem solving or other reasoning work related to the challenge.

Get Ready

New to CTFs? Here are resources to sharpen your skills before the competition.

Practice Platforms

RingZer0Team: NorthSec challenges from past editions.
OWASP VWAD: vulnerable web apps to practice on.
MontréHack: monthly CTF workshop in Montréal.

Learning Resources

MontréHack Resources: curated list of skill-building links.
CTF Write-ups Archive: methodologies and tools from real CTF solutions.

Discord

Our feature-rich CTF-focused Discord bot simplifies the participant experience with team coordination, staff support, and critical meme-sharing capabilities.
Join our Discord

Attending the CTF with children? NorthSec offers free on-site childcare during the event. See our outreach page for details.

These stats are from the 2026 edition.

161

Flags

754

Points

41

Tracks

60

Services

35

Files

26

Challenge Designers