30 Days of CTF: Winter Break 2026

A structured 30-day sprint to sharpen my CTF fundamentals, practice independent problem-solving, and document what I learn each day.

Project goal

This winter break, I am dedicating 30 days to polishing the core skills used in Capture the Flag competitions. The focus is not just collecting flags. I want to improve how I enumerate problems, test assumptions, use unfamiliar tools, recover when an approach fails, and explain a solution clearly afterward.

Each session is designed to take 60–90 minutes:

  • 10–15 minutes learning
  • 45–60 minutes solving
  • 10–15 minutes documenting the session
  • Extra picoCTF challenges from the day’s category if I finish early

End target

  • 60+ completed levels, labs, or challenges
  • 10–15 written solutions
  • One complete beginner machine
  • One simulated or live CTF
  • One specialty selected for deeper study next month

The sections below track the plan and link to a separate writing space for every day.

Training journal

Open a week to view its schedule and daily writing spaces.

Week 1 7/7 complete

Linux and general CTF skills

Build command-line fluency through Bandit, picoCTF fundamentals, SSH, Git, networking, and basic enumeration.

Open week 1
Week 2 7/7 complete

Web exploitation

Practice finding and exploiting common web vulnerabilities with TryHackMe, PortSwigger Academy, and unseen challenges.

Open week 2
Week 3 4/7 complete

Crypto, forensics, reversing, and pwn

Broaden into specialist categories through focused crypto problems, file and network forensics, reversing, and binary exploitation.

Open week 3
Week 4 0/7 complete

Independent CTF solving

Apply the month’s skills with limited hints, complete a beginner machine, repair weak areas, and begin a timed CTF.

Open week 4
Finale 0/2 complete

CTF closeout and retrospective

Finish the timed event, reproduce missed solutions independently, and choose the next specialty to pursue.

Open finale