CTFd++ is a fork of CTFd, the open-source Capture The Flag framework. It keeps the full CTFd feature set and adds competition operations, review workflows, anti-cheat tooling, and quality-of-life improvements.
Use ./run.sh as the entrypoint for this deployment. Running ./run.sh with no arguments prints the help text.
- First run:
./run.sh startgenerates local credentials, writes.env, and starts Docker Compose. - Normal restart/re-up:
./run.sh startordocker compose up -dstarts the existing instance with the current.envand data. It does not rotate credentials. - Full local reset:
./run.sh resetstops the stack, deletes local data/config/credentials, generates fresh credentials, and starts a new instance. Use./run.sh reset --yesto skip the confirmation prompt.
After startup, open CTFd++ at http://<server>/ or http://<server>:8000/.
For development, run uv sync and uv run serve.py with Python 3.11.
requirements.txt is generated from uv.lock for pip and Docker installations.
- Removed the admin reset feature and Danger Zone UI. Switching back to user mode now requires a full CTFd++ reset from the CLI.
- Added automatic exports every 20 minutes while the competition is running. Exports are saved in
.export, and the oldest exports are removed when the folder reaches 1 GB.
Reworked the admin panel into a persistent left sidebar layout so high-use sections stay visible, including review workflows, scoring tools, and system configuration.
Added challenge submission metadata for AI Source links and solver/script uploads.
Added Custom configuration for the accepted AI Source regex, solver file count limit, and solver total size limit.
Added per-challenge Need AI and Need Solver settings, including challenge creation/editing controls and admin challenge-table indicators.
Added AI Source and Solver links to the admin submissions table, syntax-highlighted solver previews, AI Source tooltips, and a manual Verified checkbox for reviewer tracking. Assistants with submission read and file permissions can review/download solver uploads without broad write access.
Added anti-cheat event detection and review tooling for shared IPs, shared user agents, shared browser fingerprints, repeated wrong answers, rapid solves, challenge-file download timing, and churn-style signals.
Added a Ticket admin workflow for targeted user/team notifications. Pending tickets repeat on page refresh until moved to Ongoing; resolving a ticket requires a resolve note and is final. Tickets support toast or alert presentation, optional notification sound, and assistant access through the normal permission system.
Added an Announcer Bot under admin configuration for Discord webhook solve announcements. It supports first blood, second blood, third blood, and normal solve announcements, configurable bot identity, embed colors/images/footer, editable JSON templates, test sends, delivery logs, and manual resend from a saved log payload.
Added Post-Revoke Calc for simulated post-event score review, including simulated bans, solve/award revokes, percentage score adjustments, notes, challenge score recalculation, bracket filtering, reset backups, CTFd++ export/import support, and PDF export. Challenge rows can be opened to review every correct submission for that challenge with the same score percentage, revoke, note, and banned-status controls.
Added an Assistant admin role with configurable access control. Full admins can grant scoped access to admin sections, including separate read/write permissions for Users, Teams, Submissions, and Post-Revoke Calc.
- Added
run.shto initialize fresh deployments, reuse existing credentials/data on normal starts, and reset local infrastructure on request. - Added
reset.shfor full-instance reset with seven confirmations. It exports the current instance into.reset, archives.exportinto.resetwith a timestamp, and then starts a fresh stack. - Added
scripts/trigger_anti_cheat.pyto generate local demo events for validating the anti-cheat detectors.
CTFd++ is built on top of CTFd. All core CTFd functionality is included: challenges, dynamic scoring, teams and users, scoreboard, plugins, themes, imports/exports, email, and more. See the upstream CTFd repository and CTFd documentation for base platform usage and configuration.
CTFd++ is distributed under the Apache License 2.0, the same license as CTFd.
- Logo by Laura Barbera
- Theme by Christopher Thompson
- Notification Sound by Terrence Martin
















