← back to homepage
plfanzen logo

plfanzen CFT

What originally started as a joke at DHM has now evolved into a CTF with chall authors from all across the DACH region, and more :)

The CTF is aimed at more experienced players, but will (probably) also contain a few intro challenges, and some zaje, maybe even both :)

Plfanzen CTF is a team event for teams of any size. You can also participate on your own!

View results

Join us on Discord!

clanker policy

As I'm sure everyone is aware, over the last couple months, especially with rather recent models, LLMs have reached a point where they can autonomously (or near autonomously) solve most of what would have previously been difficult and interesting CTF challenges.

While LLMs are undoubtably becoming a core tool in many disciplines of cybersecurity, many of the challenge types now deemed "lost" still test very relevant skillsets, or teach techniques and patterns, which are still very relevant for a modern security professional or enthusiast to understand.

It is also incredibly discouranging for us challenge authors, for "our work" to be "slopped open", without any human in the loop...

Our goal with plfanzen CTF was to share some interesting/fun findings through CTF challenges, while also allowing a place for teams to compete with more difficult challenges across most categories all of misc (yea idk, deal with it).

We believe that we have multiple challenges which should pose a challenge for even the strongest LLM setups (e.g. windows kernel pwn). However we are also aware that some/most of our challenges are likely trivially solveable using LLMs (this used to not be the case like a month ago 😭😭😭).

Rather than butchering our challenges in an attempt to make them "LLM proof", we decided to include them as is, and let teams decide to what extent they wish to use LLMs in their CTF process.

We really liked the KalmarCTF 2026 Low-LLM policy, and are also providing a seperate, opt-in bracket for "human" teams; we heavily reccomend playing this way, instead of throwing money at big slop.

For the "human" (low LLM) bracket, consider the following guidelines on LLM usage:

We reserve the right to disqualify teams from the "humans" bracket if we find evidence of LLM usage that violates the rules, or to disqualify teams from the writeup prizes for the same reason.

applying for the "humans" bracket

Have your team captain / representative email us at vorstand@plfanzen.lol with a filled out version of the form. Opt-in for the "humans" bracket will apply to your whole team. We may disqualify teams from the "humans" bracket if we find evidence of LLM usage that violates the rules.

sponsors

We would like to thank our sponsors for supporting us and making this event possible:



PWND Labs GmbH is a cybersecurity company, founded by past and present ECSC and DEF CON Finals players, specializing in application security. We offer source code audits and secure software development consulting.


OtterSec secures critical blockchain infrastructure — from custom compilers to novel virtual machines, we review a wide range of difficult targets. Our team consists largely of CTF players that enjoy solving hard problems. If that sounds like you, please apply through our careers page.

prizes

placement

writeups