Post

King of the Hill Competition by SWIFT

King of the Hill Competition by SWIFT

This time, SWIFT hosted a King of the Hill (KoTH) competition, and it was a completely different experience from the usual red-team or CTF-style events.
Instead of just attacking vulnerable machines, we had to attack and defend at the same time, which made every second intense and unpredictable.

The competition environment consisted of multiple Linux and Windows hosts running on AWS, and every competitor received a unique flag they needed to plant in the designated flag.txt files.
The scoring engine continuously checked those files, so the longer your flag stayed in place without someone removing it, the more points you gained.


Attacking and Defending at the Same Time

For this event, I primarily focused on the two Debian machines, and the gameplay felt like a constant back-and-forth battle with other competitors.
There were moments where I gained a foothold, escalated privileges, and finally planted my flag — only to have someone else swoop in, remove my persistence, and lock me out a few minutes later.

On two separate occasions, I found myself in direct conflict with other players on the same box:

  • We were overwriting each other’s scripts.
  • Killing each other’s processes.
  • Replacing each other’s flag.txt contents.
  • Trying to disable the other person’s service modifications without breaking the scoring engine.

It was basically live red vs. red chaos, and I loved it.

I also managed to get initial access on one of the Windows targets, but access closed off quickly after login issues were resolved across the environment.


Building Services, Breaking Services, Fixing Services

One of the coolest parts of this KoTH was learning how to properly set up and maintain services under pressure.
It wasn’t enough to just exploit a machine — you had to:

  • stabilize access
  • repair or restart misconfigured services
  • maintain scoring-critical components
  • defend the machine without breaking rules
  • keep competitors from regaining control

This was easily one of the most realistic parts of the event and pushed me to think like both an attacker and a defender simultaneously.


The Environment

All machines were accessible through a bastion host on AWS, and we had to use SSH port forwarding to interact with different internal services.
Because of the mix of Linux and Windows targets, it really felt like navigating a mini-enterprise network:

  • propane1 & propane2 — Debian
  • hankcore — Red Hat
  • DC, CA, FS — Windows Server 2022

Managing tunnels, pivoting, and monitoring system behavior while other competitors were constantly making changes added a layer of realism I haven’t experienced in most CTFs.


What I Learned

This KoTH taught me things I wouldn’t have learned from a traditional competition:

  • Compromising a machine is only the first step — keeping it is the real challenge.
  • Service hardening matters when the scoring engine depends on it.
  • Thinking defensively while acting offensively builds a more complete skill set.
  • Expecting other attackers forces you to stay adaptable and creative.
  • Rapid response and recovery are essential when your foothold gets disrupted.

Overall, the KoTH format pushed me into a high-pressure, adversarial environment that was extremely fun and packed with learning moments.
It felt like a condensed simulation of real-world offensive and defensive operations happening at the same time.

I definitely walked away with new skills, new habits, and a better understanding of live adversarial engagements — and I’m excited to jump into the next SWIFT competition.


This post is licensed under CC BY 4.0 by the author.