
Want to try your hand at hacking satellites, spacecraft and ground control systems? Miss out on Hack-A-Sat? Want to explore the final frontier of cybersecurity?
STARPWN is the official Aerospace Village space hacking CTF! Back door flight computers, trojan flight software, exploit CVE's, reverse protocols, and more! During your space hacking journey, you’ll learn all about the environmental and operational constraints of space systems, how they affect cybersecurity posture, and impact exploitability.
The Tech Stack & Categories
Participants can expect challenges inspired by real-world aerospace engineering and offensive security
NASA F Prime Framework
Challenges involving the open-source flight software used for various small satellite missions.
Satellite Communications
Deep dives into CCSDS protocols, radio frequency (RF) signal processing, and packet capture (pcap) analysis.
Ground Data Systems (GDS)
Attacking the bridge between Earth and orbit
01 COMPETITION FORMAT
STARPWN is a jeopardy-style Capture The Flag (CTF) competition. Participants compete individually or in teams to solve challenges across multiple categories, earning points for each correct flag submission.
Our primary method of communication will be Discord. All updates and communication regarding the competition will happen there, and that's also where you can reach out to the organizers if needed.
Make sure to read and understand our AI/LLM/Agent policy below
02 TEAM RULES
There are no limits on team size. If you intend to participate alone, create a solo team.
-
Each participant may only be a member of one team.
-
Team names must not be offensive or inappropriate.
-
Sharing flags or solutions between teams is strictly prohibited.
03 FLAG SUBMISSION
Flags follow the format STARPWN{.*} (only printable ASCII characters) unless stated otherwise in the challenge description.
-
Flag submissions are case-sensitive. Submit exactly as captured.
-
No flag-hoarding. If you find a flag it should be submitted right away, this is to ensure a level playing field for all teams at each step of the way.
04 SCORING
Most challenges use dynamic scoring where points decrease as more teams solve them.
-
When a challenge has a static score for some reason, that is noted on the description.
-
Every team receives the same amount of points for a challenge, regardless of the solve time.
-
The team with the highest total points at the end of the competition wins.
-
In the event of a tie, the team that reached the point total first will be ranked higher.
05 PROHIBITED ACTIONS
-
Do not attack the competition infrastructure (CTFd platform, scoring servers, or other supporting systems).
-
Do not attack other participants or their systems.
-
Do not brute-force flag submission endpoints.
-
Do not share flags, hints, or solutions publicly during the competition.
-
Do not use automated tools to spam or degrade platform performance.
-
Do not create multiple accounts or teams to gain an unfair advantage.
06 DISPUTES & SUPPORT
-
For technical issues or questions, reach out via the official Discord channel.
-
Challenge disputes must be submitted before the competition ends and will be reviewed by the organizers.
-
The organizers reserve the right to modify rules or disqualify participants in cases of severe violations.
07 CODE OF CONDUCT
All participants are expected to maintain a respectful and inclusive environment. Harassment, discrimination, or any form of abusive behavior will not be tolerated and may result in immediate disqualification.
08 AI/LLM/Agent policy
We believe that CTFs should primarily be a playground for humans to challenge themselves, learn new things, and have fun with the CTF community. And in line with that, we don't believe that solving a challenge by letting an LLM do most of the work aligns with that philosophy. With that said, we must recognize that AI, LLMs and agents can be useful tools, are more relevant than ever, and their usage is virtually impossible for us to control in a reliable and fair way.
-
With this in mind, we decided on a few ground rules:
-
Fully or primarily autonomous teams are not allowed and will result in disqualification. While humans are free to use any tools they wish, we believe just answering "yes/no" to an agent prompt reverts the roles between humans/tools.
-
We reserve the right to, at any time during the CTF, ask teams to get in touch with the organizers and talk us through their solutions.
-
The top 3 teams will be asked to submit short writeups for a selection of challenges. These won't have to be polished documents but should at least provide a good description of your reasoning and how you've arrived at the answer. Relevant teams will be notified when approaching the end of the competition.
-
These rules are intended to reflect the values of the CTF community, and preserve the fun and environment that CTF challenges provide for both players and authors. This policy was not created in a vacuum and we must thank the previous efforts by the organizers of Kalmar CTF, RITSEC CTF, DEFCON CTF, amongst others, for their exploration of AI policies in CTFs.
FEATURED SPONSORS













.png)
.png)



