HARDEN
Reduce verified security exposure in a vulnerable or misconfigured environment while keeping required services operational.
Explore Harden ↗Four-person teams move through Harden, Hack, and Hunt. Each track tests a different skill set, and all three contribute to the final ranking.
THREE DIFFERENT SECURITY PERSPECTIVES
CyberShield is one connected team competition made up of three distinct environments. Teams harden a defensive environment, attack a target network, and investigate evidence from a simulated incident.
The environments are designed around related professional skills.
View the preliminary schedule ↗Reduce verified security exposure in a vulnerable or misconfigured environment while keeping required services operational.
Explore Harden ↗Discover attack paths, exploit weaknesses, pivot through a target environment, and capture validated objectives.
Explore Hack ↗Analyze evidence, reconstruct activity, identify indicators, and determine what happened during a simulated incident.
Explore Hunt ↗Each track may use a different number of available points. To make the results comparable, every track score is first normalized to 100. The confirmed track weights are then applied.
Hack contributes 50% of the final score. Harden and Hunt each contribute 25%.
Verified improvement after the post-hardening assessment.
Validated flags and required evidence submitted through CTFd.
Correct investigative findings submitted through CTFd.
Complete validated hardening checks, flags, and investigative objectives.
Track points earned ÷ track points available × 100.
Multiply each normalized result by 25%, 50%, or 25%.
Add the three weighted results to determine the overall ranking.
(Harden × 0.25) + (Hack × 0.50) + (Hunt × 0.25)
All figures below are examples only. The same calculation will be applied to every team.
20 + 40 + 20 = 80.0
15 + 47.5 + 17.5 = 80.0
17.5 + 45 + 20 = 82.5
Organizers assess the template environment before the challenge. After time expires, each team environment is scanned. Points reflect verified reduction in weighted security weaknesses while required services remain available.
Teams earn points through CTFd for valid flags and required evidence obtained inside the authorized target environment. Higher-value objectives may require deeper access or several connected steps.
Teams earn points through CTFd for correct investigative findings, validated artifacts, and accurate conclusions drawn from the provided incident evidence.
Unlike Hack and Hunt, Harden is not scored by submitting flags to CTFd. Teams will not see their verified Harden score change in real time while they work.
After the Harden challenge ends, organizers will assess each team environment, verify that required services remain operational, compare the result with the pre-event baseline, and then calculate the normalized Harden score.
Organizers assess the template environment before the event.
Teams make security improvements during the challenge.
Organizers scan and validate each team environment after time expires.
The verified score is normalized to 100 and added to the final ranking.
The 25% / 50% / 25% weights are confirmed. Organizers will publish the final service checks, evidence requirements, penalties, leaderboard behavior, score-lock process, and tie-break order before competition begins.
FOUR IDENTICAL BUNDLES · SIXTEEN ITEMS
Each of the four highest-ranked teams will receive a CyberShield Team Prize Bundle. Every bundle contains four practical technology items for the team.
The top three teams will also receive training and certification opportunities. Training providers, certification exams, and award conditions will be announced when confirmed.
Compact USB-C charger with cable.
Ethernet, HDMI, power delivery, and USB connectivity.
Rotating aluminum desktop riser.
Compact crossbody bag with secure storage.
17–20 SEPTEMBER · ADDIS ABABA
Questions and rule updates will be shared on Telegram.