← All challenges

HARDEN.

Use an organizer-provided baseline to harden a realistic enterprise environment, reduce its attack surface, and submit the result for post-challenge measurement.

DAY 1Challenge
17 SEP 2026መስከረም 7
TEAM EVENTCollaborative defense
01 / OVERVIEW

LOCK IT DOWN

DEFENSE
YOU CAN
MEASURE.

Before the challenge begins, organizers assess the template environment and establish the scoring baseline. Teams then inherit a functioning copy that also contains security weaknesses. Your job is to understand what is exposed, decide what matters most, and harden the systems without breaking essential services.

After time expires, organizers scan the hardened environments and compare the results with the baseline. The challenge rewards practical risk reduction across Windows, Linux, and identity infrastructure.

02 / WHAT TEAMS WILL DO

FROM BASELINE
TO BETTER.

01

REVIEW

Study the organizer briefing, then inspect hosts, services, accounts, policies, and exposed ports across the environment.

02

PRIORITIZE

Separate urgent exposure from lower-impact findings and build a defensive plan under time pressure.

03

HARDEN

Secure operating systems, identity, services, access controls, and configurations while preserving required functions.

04

VERIFY

Confirm required services still work and collect evidence that the intended defensive changes were applied.

05

DOCUMENT

Record important changes and explain the defensive reasoning that guided the team’s decisions.

06

HAND OFF

Submit the hardened environment and requested evidence for the organizers’ post-challenge scan.

03 / ENVIRONMENT

REAL SYSTEMS.
REAL TRADEOFFS.

  • Windows and Linux systems
  • Identity and Active Directory components
  • Network services and exposed interfaces
  • User accounts, permissions, and security policies
  • Services that must remain available

HOW SCORING WORKS

Organizers run automated checks on the template environment before the challenge and on each team’s hardened environment after time expires. Teams earn credit for reducing security exposure and maintaining required services. Final weights, service checks, penalties, and tie-break rules will be published with the competition rules.

  • Reduce validated weaknesses
  • Keep required services operational
  • Avoid changes that create new exposure
  • Submit requested evidence before time expires
04 / PREPARE

ARRIVE
READY.

Review basic Windows and Linux administration, Active Directory security, access control, patching, service configuration, firewalls, and common hardening guidance.

Teams may draw on recognized guidance such as CIS Controls, NIST resources, ISO-aligned practices, or the Essential Eight. The competition will focus on practical outcomes, not memorizing a framework.

Bootcamp information →

SEPTEMBER 17 · ADDIS ABABA

READY TO
LOCK IT DOWN?

Register ↗