Skip to main content

20 Tips to Prepare for Capture the Flag 2025

20 Tips to Prepare for Capture the Flag 2025

Mark your calendars for October 9–10, because Capture The Flag 2025 (CTF) is back—and it’s bigger than ever. This high-energy, two-day hybrid event is your chance to sharpen your hacking skills, uncover real security vulnerabilities, and learn how to build secure Mendix apps that protect your users and your business.

CTF 2025 isn’t just another event—it’s your gateway to becoming a Mendix security pro. Whether you’re a first-time attendee or CTF veteran, preparation is key. That’s why we’ve complied a checklist from our organizers, experts, and past CTF attendees with their top tips to get you ready.

 

Mitchel Mol

CTO of Blue Green Solutions, CTF Co-Organizer

 

 

Tip 1
Form a strong team: Select individuals with diverse strengths, including app logic, security, APIs, and debugging. A diverse squad can make all the difference.

Tip 2
Read up on the Mendix Client API: Focus on versions 9 and 10. You’ll likely need to bend the front-end to your will.

Tip 3
Install and try out Burp Suite. Grab the Pro trial. You’ll need it to intercept and analyze app traffic. Practice intercepting requests, playing with headers, and understanding session behavior.

Tip 4
Install Ciphx DevTools: A powerful browser extension that gives you deep insights into Mendix apps.

 


Rene van Hofwegen

CEO & Founder of Low-code Academy, CTF Co-Organizer

 

Tip 5
Join security workshops to broaden your horizon on security topics. With over 20 workshops, you’ll learn about a variety of topics from “How to model a secure app” to “The impact of an ISO 27001 certification” and “Securing your outgoing APIs”

 


Dirk van Veen

Founder of The S-Unit, CTF Co-Organizer

 


Eline Bijkerk

MVP, Mendix developer and Security Officer at Conclusion Low Code, CTF Attendee 2021 & 2024

 

Tip 7
You don’t need to be an accomplished hacker to join – as long as you have a decent understanding of Mendix, you can join! There are plenty of workshops during the event starting with the very basics, so don’t feel intimidated if you’ve never hacked an app before. I had a blast the first time I participated, despite signing up alone!

Tip 8
Click through the challenge application a little to get an understanding of what it does and how it works. The challenges are a lot easier if you already have an idea of where to look!

Tip 9
The titles and description of challenges often have hints on where to look. For example, a challenge regarding a deeplink might look something like “Going off the deep end.”

Tip 10
Take breaks! I’ve found the most flags after going for a short walk around the event location, playing some Beat Saber or Mario Kart and looking at the challenge I’ve been stuck at for hours with fresh eyes.

 


Jurre Tanja

Team Manager at Mendix, CTF Attendee 2021 & 2024

 

Tip 11
Embrace the frustration. You will get stuck a lot! As most of the flags are not really hidden in plain sight you will be frustrated a lot. Regroup and try again.

Tip 12
Join a satellite location in person! Not only will you meet like-minded Mendix developers, but you hear much more from others how they solved a difficult challenge which you can use for your benefit as well.

 


Jan de Vries

Community Team Manager at Mendix, CTF Co-Organizer

 

Tip 15
Try out everything! Next to hacking, get to know your fellow hackers, participate in a gaming tournament, join a workshop or two, and talk to an MVP or someone from Mendix. It’s going to make your experience a lot more fun and memorable.

Tip 16
Bring some comfort, like your own mouse and keyboard, comfy slippers, proper headset, your favorite mug, or something else that can help you get in the zone.

Tip 17
Share your excitement with your friends and network by sharing pics and stories using #CTF2025 on social media.

 


Ray Kok

CEO at Mendix

 

 


Jiří Reitmann

Founder at Lowcro, Satellite Host in Prague

 

Tip 19
Designate a “researcher” role, someone on the team to quickly look things up, read documentation, or check forums because it keeps the momentum going when others are focused on a challenge.

Tip 20
Be a part of the community: Check in with other teams or individuals. While this is a competition, the main point of this event is to share knowledge and collectively improve!

 

Claim your seat at Capture the Flag 2025

Think you have what it takes to rise to the challenge? Join 1,250+ Mendix developers from around the globe as you compete, collaborate, and connect with top security experts. Save your spot and register here.

Choose your language