Black Hat India 2026

Official CTF

Black Hat is landing in India this October 27-30. Compete in the official CTF and stand a chance to win highly prized Black Hat India Briefings Passes and other exciting rewards.

Event Starts In

-- Days
-- Hours
-- Minutes
-- Seconds
Total Challenges200
ModeOnline
Allowed Team Size3
Scheduled Date (IST)10 Oct, 7:30 PM
About the Event

Black Hat India 2026 Official CTF is a 24-hour online Jeopardy-style CTF with 200 original challenges. Top 3 teams will win Briefings Passes to attend Black Hat India 2026 along with other exciting prizes.

Black Hat India debuts in Bengaluru, October 27-30, featuring specialized cybersecurity Trainings with courses for all skill levels, a Summit Day, and the two-day main conference. Black Hat India 2026 will feature Briefings by experts from around the world presenting the latest research in cybersecurity risks, developments and trends, dozens of open-source tool demos in Arsenal, a robust Business Hall, networking and social events, and much more.

Challenge Categories

  • Web3
  • Smart Contract Exploitation
  • LLM Security
  • AI Security
  • Identity and Access Management (IAM)
  • Single Sign-On (SSO)
  • Digital Forensics & Incident Response (DFIR)
  • Cloud Native Security
  • Mobile Security
  • FinTech Security
  • Linux Security
  • Active Directory
  • DevSecOps
  • Binary Exploitation
  • Reverse Engineering
  • Web Security
  • Cryptography
  • OSINT
  • Steganography
  • Miscellaneous
  • Beginner Jeopardy Track

Prizes & Rewards

₹5,85,000Total Prizes Worth
Black Hat India 2026 CTF Champion

1st

₹1,95,000

3 Briefings passes worth Rs.65,000 each

2nd

₹1,95,000

3 Briefings passes worth Rs.65,000 each

3rd

₹1,95,000

3 Briefings passes worth Rs.65,000 each

CTF Sponsors

For sponsorship opportunities, please email [email protected]

Official CTF Partner

CTF7 is the platform this competition runs on — built for cybersecurity CTFs, hackathons and hands-on security labs, with live leaderboards, on-demand challenge infrastructure and built-in anti-cheat. Universities, student chapters and training teams use it to run their events end to end.

Visit ctf7.com

Official CTF Team

Shlok Kesarwani

Shlok Kesarwani

Black Hat India 2026 CTF Operational Lead & Engagement Team

Shlok Kesarwani is a Cyber Security Researcher with a strong focus on Active Directory security, penetration testing, red teaming, and CTF development. He has experience building practical security labs, researching modern attack techniques, and creating hands-on learning environments that bridge the gap between theory and real-world security.

A passionate community contributor, Shlok actively supports and helps grow the cybersecurity ecosystem by organizing community events, mentoring aspiring security enthusiasts, and collaborating with open security communities to promote hands-on learning and knowledge sharing.

Passionate about offensive security and continuous learning, he also shares technical knowledge through talks, workshops, and security research, with the goal of helping others develop practical, industry-relevant cybersecurity skills.

Akshay Jambagi

Akshay Jambagi

Black Hat India 2026 CTF Technical Lead
Malware Analyst - II, Microsoft

Akshay Jambagi is a Malware Analyst - II at Microsoft, part of the Microsoft AI Org and DJ at night. Over the last six years, he has worked across application security, OT/ICS threat research, malware reverse engineering, and AI-driven detection engineering at Cognizant, Subex, and Microsoft.

He has helped build and scale detection systems and threat-hunting programs that protect users at global scale, with a focus on turning deep malware analysis and threat intelligence into resilient, automated, AI-driven protections.


PH Reddy

PH Reddy

CTF Advisor | Head of MXDR Operations | Cybersecurity & OT Security Leader at Bengaluru International Airport

PH Reddy is a cybersecurity leader with 20+ years of experience across Managed XDR/SOC operations, Red Teaming, Threat Detection & Response, Offensive Security, OT Security, Cyber Resilience, and Critical Infrastructure Protection.

His expertise spans SIEM/XDR, Threat Hunting, Incident Response, Red Teaming, VAPT, OT Security, Security Architecture, and cybersecurity governance aligned with frameworks such as NIST, ISO 27001 and IEC 62443.

He holds industry-recognized certifications including OSCP, CREST CRT, CREST CPSA, LPT Master, CPENT, CEH and CCNA. He has also participated in offensive security and live-hacking initiatives.

Debojit Singh

Debojit Singh

CTF Auditor | Founder, BlackPanda Labs

Debojit Singh is the Founder of BlackPanda Labs, a cybersecurity-focused non-profit initiative dedicated to practical security education, research, and open-source projects. His primary focus is offensive security, web application security, red teaming, and vulnerability research.

A Certified Red Team Analyst (CRTA) and WEB-RTA, Debojit actively works on hands-on security challenges and CTFs. He contributes to the cybersecurity community through technical initiatives, security research, and practical learning environments, with a focus on developing real-world offensive security skills.

Frequently Asked Questions

The Black Hat India CTF 2026 is open to participants from anywhere in the world. Anyone interested in cybersecurity can participate, subject to the official CTF rules.

Participants can register through blackhat-india.com and create/register their squad.

A valid CTF account is required to participate.

No. Solo and duo participation is not allowed.

A team must have exactly 3 participants to play the CTF.

Each team must have exactly 3 members.

Teams with fewer or more than 3 participants will not be allowed to participate.

The CTF will run for 24 hours.

Official Start Time

7:30 PM IST (UTC+5:30)

International Time Conversion

LocationStart Time
🇮🇳 India (IST)7:30 PM
🌍 UTC2:00 PM
🇬🇧 London (BST)3:00 PM
🇺🇸 New York (EDT)10:00 AM
🇺🇸 Los Angeles (PDT)7:00 AM
🇸🇬 Singapore (SGT)10:00 PM
🇯🇵 Tokyo (JST)11:00 PM
The exact calendar date will follow the official Black Hat India event announcement.

The official event timezone is Indian Standard Time (IST), UTC+5:30.

The CTF will remain active for 24 hours from the official start time.

The CTF will be hosted online through the official Black Hat India CTF platform.

Participants can join the CTF from anywhere in the world.

Register through blackhat-india.com with your squad/team.

Once the CTF starts, participants will be able to access the CTF platform and begin solving challenges.

The CTF will contain multiple cybersecurity challenges designed to test practical security knowledge and problem-solving skills.

Anti-AI Challenge Design

The challenges are designed to be Anti-AI, meaning they are not intended to be easily solved simply by asking an AI tool for the answer.

Participants are expected to:

  • Think independently
  • Investigate the challenges
  • Experiment with techniques
  • Understand what they are doing
  • Apply practical cybersecurity skills

Even where AI may provide some assistance, participants may still need to put significant effort into solving the challenge.

The primary goal is to test and sharpen your actual cybersecurity skills.

The CTF uses a dynamic flag system.

Challenge flags may be generated or changed dynamically during the competition, so participants should not rely on copied or previously obtained flags.

The final scoring will be based on valid challenge submissions recorded by the platform.

Submit flags through the designated submission field on the CTF platform for the relevant challenge.

Important

Do not:

  • Attack the CTF dashboard
  • Manipulate the platform
  • Abuse platform functionality
  • Attempt to bypass the intended submission mechanism

Participants should simply solve the challenge and submit the flag through the intended interface.

The exact flag format will be provided when the CTF starts.

The expected format will generally look similar to:

BlackHatIndia{dynamic_flag}
Important: Because the CTF uses a dynamic flag system, participants should not assume that a flag found or shared elsewhere will remain valid.

First:

  1. Verify that the flag was copied correctly.
  2. Make sure it belongs to the correct challenge.
  3. Check for missing characters, spaces, or formatting issues.

Because the CTF uses a dynamic flag system, copied or previously obtained flags may not work.

For a genuine platform or flag-validation issue, contact: [email protected]

Please report the issue to: [email protected]

Please include:

  • Challenge name
  • Description of the issue
  • Error message, if any
  • Screenshot, where useful
Do not attempt to attack the infrastructure to troubleshoot or bypass the issue.

First, refresh the challenge and leaderboard.

If the solve or score is still not reflected, contact: [email protected]

Please include your:

  • Team name
  • Challenge name
  • Account details
  • Approximate submission time
  • Relevant screenshot/error

The CTF is designed to be a fair cybersecurity competition.

Participants must:

  • Follow the official CTF rules.
  • Only interact with systems and functionality intended for the CTF.
  • Respect other participants and teams.
  • Avoid any activity intended to gain an unfair competitive advantage.

Any violation may result in removal from the competition.

The following activities are strictly prohibited:

  • Attacking or abusing the CTF dashboard/platform
  • Manipulating or exploiting the CTF platform for an unfair advantage
  • Sharing CTF credentials
  • Giving CTF credentials to AI systems
  • Copying flags
  • Sharing flags
  • Sharing challenge solutions or answers
  • Sharing flags or solutions between teams
  • Communicating about active challenges with other participants outside your team through Discord, social media, or other online channels to gain an unfair advantage
  • Publishing active challenge solutions during the CTF
  • Logging into an account from suspicious multiple devices/regions
  • Any other activity intended to gain an unfair competitive advantage

A dedicated monitoring team will investigate suspicious activity using available platform logs and other relevant information.

Participants may use legitimate cybersecurity tools where appropriate for solving challenges.

However:

Creating or using scripts to attack, abuse, manipulate, or compromise the CTF platform/dashboard is prohibited.

AI Usage

The challenges are designed to be Anti-AI.

Participants must not share their CTF credentials with AI systems.

Using AI in a way that violates the competition rules or gives an unfair advantage may result in disciplinary action.

The goal of the CTF is to sharpen your own cybersecurity skills.

Absolutely not. Sharing flags is strictly prohibited.

If flag sharing is detected:

Both the sender and receiving team may be terminated/banned from the CTF.

This applies regardless of whether the participants know each other personally.

Normal communication is allowed.

However, participants must not communicate about active challenges, flags, answers, or solutions with people outside their own team through:

  • Discord
  • Social media
  • Private messages
  • Other online communication platforms

Such communication may result in a ban.

Participants should not log into the same account from multiple devices or suspicious/different geographical regions.

The platform may monitor account activity and login logs.

If suspicious activity or account sharing is detected:

The account may be disabled and the associated team may be banned from the CTF.

No. Participants cannot publish or publicly share:

  • Flags
  • Solutions
  • Walkthroughs
  • Challenge answers
  • Detailed write-ups

during the 24-hour CTF duration.

For any CTF-related query, technical issue, platform problem, or security concern, please contact: [email protected]

Please report security issues privately and do not exploit them for competitive advantage.

The prizes will be announced soon.

Prizes will be distributed on the event date, subject to the official eligibility requirements and competition rules.

Final winners will be determined after the CTF results have been reviewed and validated.