Root the Box is a real-time capture the flag (CTF) scoring engine for computer wargames where hackers can practice and learn. The application can be easily configured and modified for any CTF style game. The platform allows you to engage novice and experienced players alike by combining a fun game-like environment with realistic challenges that convey knowledge applicable to the real-world, such as penetration testing, incident response, digital forensics and threat hunting. Screenshots & Demo: Additional platform screenshots and game examples. RootTheBox Demo – Note it may take a few seconds to wake up. Also, please don't change passwords on the example accounts, but feel free to register a new user. Features: Team Play or Individual Play, Real-time animated scoreboard, graphs, and status updates using websockets, Flag Types: Static, Regex, Datetime, Multiple Choice, File - with options for case sensitivity, Options for Penalties, Hints, Attempts, Level Bonuses, Dynamic Scoring, Categories and more, Built-in team
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A library for validating and accessing environment variables in Node.js programs
Mellivora Mellivora is a PHP-based CTF engine with a wide range of features for managing Capture The Flag competitions.
Directory containing components to build labs for Chapter 29 with setup instructions and VM information.
A visualization tool for uploading and visualizing data as graphs on-the-fly, based on AfterGlow and running on Django.
A lightweight CTF platform inspired by motherfuckingwebsite.com with a focus on challenge difficulty.
An open-source artifact metadata API for managing metadata about software resources and governing the software supply chain.
Certificate Transparency Monitor that alerts you when an SSL/TLS certificate is issued for your domains.
PINNED

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.