Skip to content
Back to skills

Kanxue Kctf Workflow

ASecurity

Fast triage and solving workflow for 看雪 KCTF / CTF对抗 writeups,题面, archives, and challenge binaries. Use when analyzing KCTF HTML articles, RAR/ZIP attachments, Windows key checkers, Linux pwn/ELF REPLs, or anti-analysis / VM puzzles, and when you need a reproducible local replay or solver.

  • 271 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 23, 2026
businessgo

Security analysis

A100/100

Pro scans all 5 files and shows the line behind each finding

Scanned September 23, 2026

npx -y skills add manyuegong33/r0crawl_skills --skill kanxue-kctf-workflow --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Kanxue Kctf Workflow?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Kanxue Kctf Workflow
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/manyuegong33-kanxue-kctf-workflow/badge)](https://www.skillsdirectory.com/skills/manyuegong33-kanxue-kctf-workflow)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: kanxue-kctf-workflow
description: |
  Fast triage and solving workflow for 看雪 KCTF / CTF对抗 writeups,题面, archives, and challenge binaries. Use when analyzing KCTF HTML articles, RAR/ZIP attachments, Windows key checkers, Linux pwn/ELF REPLs, or anti-analysis / VM puzzles, and when you need a reproducible local replay or solver.
---

# Kanxue Kctf Workflow

## Purpose

Use this skill as a KCTF overlay on top of generic reversing skills. The goal is to
turn a看雪题目 folder into: artifact inventory, challenge type, baseline run, verified
success condition, and a reusable replay command.

## Workflow

1. Read the article title, rule number, attachment names, hash, and success string.
2. Split artifacts into: article HTML, attachment archive, runnable binary, solver, and
   extracted support files.
3. Extract the smallest runnable sample first.
4. Run a baseline:
   - Windows checker: no args, bad input, then the writeup's known-good key.
   - Linux ELF / pwn: file, mitigation check, prompt capture, then local VM or Linux host.
   - AntiAI / VM puzzle: confirm fixed input length, state size, and the first immutable
     constants before solving.
5. Record the exact command, input, output, and file hash that prove the result.
6. Save the replay command and solver together.

## KCTF patterns

### Windows key / serial checker

- Look for `Key`, `Enter your key`, `verify success.`, `verify failed.`, or a fixed-length
  hex input.
- Treat checksum, lookup table, RSA, and big-int stages as separate gates.
- Prefer a direct replay before building a full solver.

### Linux pwn / REPL / VM

- Record architecture, mitigation, prompt, and I/O contract.
- Separate parser, dispatcher, leak, and overwrite stages.
- If the binary is ELF64 with PIE / RELRO / canary / NX, validate in Linux or VM rather than
  assuming Windows execution.

### AntiAI / anti-analysis / arithmetic VM

- Derive input length, state size, and debug / integrity checks first.
- Build an integer model from the article and confirm it on one local sample.
- Do not brute force until the fixed constraints are captured.

## Reuse

- Read `references/corpus-map.md` for routing by challenge family.
- Read `references/corpus-notes.md` for the validated replay example and local notes.
- Run `scripts/kctf_scan.py <folder>` to inventory a new KCTF bundle quickly.

Files in this skill

  • SKILL.md2.3 KB
  • agents/openai.yaml344 B
  • references/corpus-map.md1.6 KB
  • references/corpus-notes.md933 B
  • scripts/kctf_scan.py4 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…