AppSec Arena is a competitive attacker/defender application security challenge. Teams of up to two participants select a difficulty tier and are given a vulnerable web application. Participants must identify vulnerabilities, develop working exploits, and submit patches along with proof-of-exploit scripts. Submissions are automatically validated to ensure exploits are reliable and patches block attacks without breaking functionality.
Teams of 2Tiered difficultyAsync + lightning roundLive leaderboard
Break, fix, defend
Unlike traditional CTFs that stop at finding bugs, AppSec Arena evaluates the full security lifecycle: breaking, fixing, and defending. Advanced participants can test their patches against exploits developed by other teams, rewarding resilient fixes and effective attacks.
The event runs asynchronously throughout the conference with a live lightning round near the end, featuring real-time scoring and a leaderboard.
AppSec Arena is run out of the AppSec Community.