Technology That Evaluates Real Skill

Assess real talent. Hire verified cybersecurity engineers.

Ricoz CTF Platform replaces theoretical multiple-choice quizzes with live, hands-on Capture The Flag assessments. Candidates prove their practical skills in Web Exploitation, Cryptography, and Reverse Engineering.

JWT & Role Based (ADMIN, REVIEWER, CANDIDATE)Fastify + MongoDB + Mongoose

Engine Architecture

Ricoz CTF Assessment Stack

Active Node

Monorepo

Next.js 15 & Fastify

Enterprise Stack

Database

MongoDB + Mongoose

Dual-Resilient Engine

Active Assessment Session: Benchmark 2026Live Scoring
Candidate Devin V.
Flag: ricoz{sql_...}+100 pts
Role-Based Access Control

Engineered with 3 distinct access roles.

Every endpoint and portal view is enforced via Fastify JWT authentication and authorize guards.

ADMIN

Full Tenant Control

Manage company profiles, invite reviewers, publish assessments, configure passing criteria, and manage all challenges.

API: GET /api/auth/admin-only

Challenge Authoring

Author challenges with secret flags, hints, docker image endpoints, categories, points, and dynamic score formulas.

Global Candidate Analytics

Inspect live assessment leaderboards, monitor flag submission frequency, and detect abnormal solve anomalies.

Database Architecture

Domain Models & Persistence

Schema in packages/database

Test with live database →

User

Model

Platform & tenant users with RBAC

id (UUID)
email (Unique)
passwordHash
name
role (ADMIN|REVIEWER|CANDIDATE)
companyId (FK)

Company

Model

Tenant organizations hiring talent

id (UUID)
name
slug (Unique)
website
logoUrl

Assessment

Model

Cybersecurity skill assessment batches

id (UUID)
title
slug
companyId (FK)
createdById (FK)
durationMinutes
passingScore
status

Challenge

Model

Hands-on CTF labs and challenges

id (UUID)
title
slug
category
difficulty
points
flag (Secret)
resourceUrl

Submission

Model

Candidate flag submissions & score history

id (UUID)
challengeId (FK)
assessmentId (FK)
userId (FK)
submittedFlag
isCorrect
pointsAwarded

AssessmentCandidate

Model

Candidate test session & progress state

id (UUID)
assessmentId (FK)
userId (FK)
status (INVITED|IN_PROGRESS|COMPLETED)
score
startedAt
completedAt
Sample CTF Challenge Library

Hands-on Vulnerability Labs

Seeded challenges ready to test via the database seed.

Sign in to solve challenges →
Web Security
Easy100 pts

SQLi Administrative Bypass

Analyze legacy login queries and bypass authentication via union-based SQL injection vulnerability.

Flag Format

ricoz{sql_injection_bypass_success_2026}

Authentication
Medium200 pts

JWT None Algorithm Escalation

Exploit flawed token signature validation logic to forge an admin role JWT header.

Flag Format

ricoz{jwt_none_alg_privilege_escalation}

Cryptography
Medium250 pts

RSA Fermat Modulus Factorization

Extract confidential secrets by factorizing close-prime RSA modulus keys with custom scripts.

Flag Format

ricoz{fermat_factorization_revealed_keys}

Reverse Eng
Hard350 pts

ELF License Keygen Crack

Disassemble stripped x86_64 ELF binary and reverse anti-debugging routines to generate license keys.

Flag Format

ricoz{anti_debug_stripped_binary_mastery}

Ready For Testing

Try the Authentication & Role System

Sign in using the pre-seeded Admin, Reviewer, or Candidate accounts, or register a new user to test the Fastify JWT APIs.