Participation is limited to teams with at least one member whose current permanent residence is in Denmark.
The Danish competition uses a strict no-AI policy. By participating here, your entire team agrees to follow the AI policy below.
If your team does not meet all these requirements, please play in the open Global competition instead.
Note: The Danish competition has its own separate scoreboard and does not award CTFtime points. If you also want to compete for CTFtime points, you are welcome to create a team on the Global platform and submit your flags there as well. All challenge work must still comply with the Danish no-AI policy.
GO TO GLOBAL COMPETITION →Eligibility
- At least one team member must have their current permanent residence in Denmark.
- Danish citizenship is not required.
- Danish citizenship alone does not qualify a team if no team member currently resides permanently in Denmark.
- Temporary visits or short-term stays in Denmark do not satisfy the residency requirement.
- Your entire team agrees to follow our AI policy.
- To gain access to the Danish competition, open a ticket on our Discord server.
- The Danish competition has its own scoreboard and dynamic scoring. Placement here alone determines the winners of the Danish positional prizes.
AI Policy
Do not use AI for solving, analyzing, researching, brainstorming, inspiration, hints, debugging, code generation, or any other challenge-related assistance.
AI tools are not allowed
- This includes LLMs, autonomous agents, AI-powered coding tools, AI research tools, and other AI systems that generate, analyze, explain, or suggest challenge-related content.
- DO NOT use AI for inspiration, ideas, approaches, hints, or next steps, even if you do not provide the challenge description or files directly.
- DO NOT use AI to analyze source code, binaries, decompiled code, PCAPs, logs, images, cryptographic material, challenge descriptions, or other challenge data.
- DO NOT use AI to generate, modify, debug, explain, or improve scripts, exploits, queries, payloads, code, or solutions related to a challenge.
- DO NOT intentionally use AI-powered search or research features to obtain challenge-related answers or guidance. We realize AI is today embedded into OSes, browsers, search engines, code editors etc. and incidental exposure can be hard to avoid - but please try. Disable where possible.
- Any traditional tools are allowed (normal rules apply)
If a solve is submitted by your team in the Danish competition, all work contributing to that solve must comply with the Danish AI policy, regardless of which BrunnerCTF platform was used to access the challenge.
Enforcement
We will enforce this policy to the best of our ability during and after the competition. We reserve the right to ask any team at any time to provide solve scripts and explain how a challenge was solved during or after the CTF.
If we determine that a team has violated the AI policy, affected solves may be invalidated and the team may be disqualified or banned from the competition.
If you are unsure whether a particular tool or use is allowed, ask us in a support ticket before using it.
CTF Rules
- DO NOT share flags or collaborate with other teams during the competition.
- DO NOT ask for or give help outside your team until the event has ended. This includes asking other teams that have already solved the challenge.
- DO NOT attack, harass, or interfere with other players in any way.
- DO NOT hoard flags or deliberately delay submissions ("sandbagging").
- DO NOT indiscriminately brute-force flags or event infrastructure. Some challenges require limited brute forcing, but broad automated enumeration against our infrastructure, such as with DirBuster, is not allowed unless explicitly stated. If in doubt, open a support ticket on Discord.
- DO NOT create multiple accounts or teams.
- DO NOT discriminate. We have a zero-tolerance policy for discrimination, including but not limited to discrimination based on politics, gender, race, or sexual orientation. Teams or users with discriminatory or political content in their names may be removed or hidden if deemed inappropriate.
- Keep a respectful tone on Discord at all times, both towards organizers and other players.
- Rule violations may result in disqualification. Infrastructure abuse or attempted attacks against event infrastructure will result in an immediate ban and may be reported to the relevant authorities.
- There is no team size limit.
- Admins have the final word.
Information
-
All flags are in the format
brunner{.*}. - Challenges use dynamic scoring, meaning their point value decreases with the number of solves. Onboarding challenges are scored statically.
- The Danish and Global competitions have separate scoreboards and separate dynamic scoring. Solves on the Global platform do not affect challenge values or rankings here.
- You are allowed to ask the organizers for hints for Onboarding challenges in a support ticket on Discord. No hints or information will be provided for any other challenges.
- After the event, you are encouraged to publish writeups and share solutions on our Discord.
Rules may be updated at any time by the BrunnerCTF crew.