RCTF (Reflare Capture the Flag)

RCTF delivers monthly challenges based on real-world breaches from the last 30 days. Participants navigate hands-on scenarios that simulate recent attack vectors, strengthening their defensive skills.

Subscribe to RCTF’s evolving challenges to stay ahead of emerging threats through interactive, practical, skill-building exercises.

Strength Over Compliance

Compliance is important, but it's insufficient for maintaining a strong defence against the latest evolving threats.

Monthly RCTFs simulate the latest breaches in a secure and isolated environment. Users gain hands-on experience of defending against today's emerging threats.

This dynamic approach strengthens skills, enhances threat awareness, and helps organisations stay ahead of evolving vulnerabilities.

Timely
Proactive
Impactful

Runs in the Cloud

RCTF uses containerised infrastructure that leverages container inheritance and HTML5-based RDP rendering to provide a secure Reflare-hosted environment in which vulnerabilities and exploits can be accessed safely and securely.

The platform creates vulnerable challenge services and ephemeral player instances on demand inside an isolated network.

Users connect to their player instances through a browser-based interface, which gives them everything they need to solve the challenges.

Scalable
Reliable
Effortless

Risk-Free Environment

Reflare’s infrastructure delivers cost-effective scalability and security.

This eliminates the need to host offensive security tools on company devices and reduces the burden on IT departments by simplifying setup and ongoing management.

Buy your users an annual subscription license, and relax, knowing they are proactively strengthening your defenses against the threats of the day.

Efficient
Secure
Easy

Waving the Flag

Capturing a flag in RCTF signifies that a user has successfully identified, exploited, or defended against a simulated cyber threat.
 
This achievement validates their understanding of real-world attack vectors and defence strategies.
 
Teams can apply their experience to proactively strengthen their company’s security posture in daily operations.
Achievement
Validation
Confirmation

Who it’s for

Red Teams:

Practice modern TTPs, sharpen OPSEC discipline, and run recurring internal competitions. Use results to target skill gaps.

Developers:

Think like an attacker to write safer code. Explore how real exploits work and how to prevent them.

Contractors:

Ensure your third-party vendors have the skills required to keep your systems safe.

 

The Starter’s Guide to Strengthening Skills with CTF


What teams say

Security Lead,
SaaS (500+ employees)

“Exactly the ‘real breach’ practice we were missing.”

Head of Engineering,
Fintech

“Our devs now understand modern attack vectors.”

CISO,
Gov Agency

“The cloud isolation keeps IT calm while we train aggressively.”



 

Challenge yourself against the demo today

Experience RCTF

 

What you’ll experience in the demo

  • A scenario inspired by a recent breach, delivered as an approachable, multi‑stage challenge.

  • A fully remote, HTML5‑rendered desktop—preloaded with the tools you need.

  • A clean dashboard to track progress at an individual and team level.

 



FAQs