The King of the Hill format was popularized by online platform TryHackMe in 2021 in an IT security training context.
It consists in gaining and maintaining access to an IT infrastructure for as long as possible, deploying bots to form a botnet and involves breaking into systems before patching their vulnerabilities.
We’ve created our own version, to be used as a 3 to 4 days training workshop (face-to-face), with the aim of being fun, technically challenging and competitive.
Workshop schedule
Pre-workshop week (Face-to-face or E-learning)
The final KoTH day is preceded by 2 to 3 days of training and exploitation on the infrastructure machines to be used.
Participants will create teams and start discovering and exploiting vulnerabilities on the infrastructure we’ve created for this workshop.
The infrastructure is available in the cloud and can be accessed 24 hours a day.
An exploitation path is proposed in the form of point-earning challenges, and teams can organize themselves as they see fit, according to their availability and corporate preferences.
Note: The entire training can be run on a Windows, GNU/Linux, Android or Mac OS machine, and requires no hardware other than a laptop/smartphone/tablet.
Preparation morning (Face-to-face)
We meet with the teams to complete their final challenges and answer any questions they may have about the workshop and its challenges.
Teams can also use this time to automate operations, using scripting and/or AI in preparation for the King of the Hill event.
Afternoon - Hostilities begin (Face-to-face)
The afternoon is dedicated to the King of the Hill, with teams competing against each other in time-limited sessions.
The team that manages to maintain access to the most machines on the infrastructure for the longest possible time wins the event!
Prerequisites
- Knowledge of networking (TCP, UDP)
- Good level on a scripting language (Python, Ruby, Perl, Shell, PowerShell […])
- Basic programming skills
Scenario
We’re delighted to invite you to an exciting hacking workshop, where you’ll have the opportunity to put your IT security skills to the test.
This unique workshop will plunge you into the exciting world of ethical hacking, with a challenge specially designed to let you explore and reinforce your knowledge of offensive and defensive security.
As a team, you’ll take on CryptoArt, a thriving technology company specializing in the sale of NFTs (non-fungible tokens) in a series of guided challenge-based exploits, before battling it out in King of the Hill mode.