Back to Home

Cybersecurity

A five-round practical competition running alongside the eGA RIDC Cybersecurity curriculum. Each stage covers a different skill domain - from Linux scripting and web exploitation to mobile analysis and SOC operations. Scores accumulate across all rounds on a live leaderboard. The individual with the highest cumulative score is declared League Champion.

Areas of Focus

Linux & Scripting

Foundations: Linux environment setup, user/group/permission management, Bash and Python scripting, database automation, and basic reconnaissance. Week 1 focus - worth 10% of overall score.

Mobile Security Assessment

Static and dynamic APK analysis using MobSF, Mobile OWASP Top 10 mapping, risk rating, and professional mobile security report writing. Week 4 focus - worth 20% of overall score.

Network Security & Phishing Awareness

Network scanning with Nmap and Nessus, Active Directory exposure, and controlled GoPhish phishing simulation campaign design and reporting. Week 3 focus - worth 20% of overall score.

SOC / SIEM Operations & Grand Final

Log ingestion, alert triage, threat hunting, and incident response using SEMOTO/Security Onion. Includes a live Grand Final defense of your strongest league work. Week 5 focus - worth 25% of overall score.

Web Application Penetration Testing

OWASP Top 10 vulnerability assessment and exploitation: SQL injection, file upload, XSS, OS command injection, SSRF. Includes professional pentest report writing. Week 2 focus - worth 25% of overall score.

What to Submit
Each stage is a self-contained round with its own themed tasks and deliverables. Stage 1 - Linux & Scripting (10% of total) Provision a Linux VM, manage users/permissions, write Bash + Python scripts, deploy a database, and brute-force your own archive password. Submit: screenshots, all scripts, recovered password with timing, methodology note. Stage 2 - Web Application Exploitation (25%) Deploy a vulnerable web app, exploit at least 5 OWASP vulnerabilities (SQLi, XSS, file upload, command injection, SSRF), capture full evidence, and write a professional pentest report. Submit: scan outputs, exploitation evidence, final PDF report. Stage 3 - Network Security & Phishing Awareness (20%) Run Nmap + Nessus scans on the training network, design a GoPhish phishing awareness campaign (test accounts only), and write an awareness report with recommendations. Submit: Nmap outputs, GoPhish campaign report, awareness recommendations. Stage 4 - Mobile Security + SOC/SIEM & Grand Final (20% + 25%) Static + dynamic APK analysis (MobSF), Mobile OWASP mapping, incident response using SEMOTO, threat hunting, and a live 5-minute Grand Final defense. Submit: analysis outputs, incident report, Grand Final presentation slides. Note: All testing must stay within designated training systems. No testing of public, institutional, or third-party systems is ever permitted.
Ready to Compete?

Register for RIDC PT Innovation Hackathon 2026 and choose this category.

Register Now