rea.run

← Showcase

case-study 2026-10-09 ctfchallengeauthorized

DownUnderCTF-style challenge: agent-assisted RE under contest rules

CTF reverse tasks are a classic authorized sandbox: the organizer ships a binary or package and defines what “solve” means. Agents with REA can speed up inventory, but the contest rules still own the engagement.

Source meta

— GitHub stars (snapshot)

Language: —

License: —

Updated: —

GitHub source: —

rea.run rating

3/5 — CTF-framed orientation

Quality. Useful contest-rules framing for agents.

Evidence. Orientation only — no attached binary case.

Limits. No dedicated public reconstruction repo on this card.

For. CTF teams using REA under event rules.

Pattern. Download the challenge artifact from the event, keep it offline as required, and ask the agent for entry points, suspicious strings, and the function that gates the flag check — with citations.

Where humans stay. Validate that suggested patches or keygens are in-scope. Many contests forbid sharing full solutions during the live window; your agent is a lab partner, not a broadcast channel.

What to practice. Writing tight prompts (“show the comparison that accepts the flag”), demanding unresolved edges, and translating Evidence into a short write-up you could defend to a teammate.

Out of scope on rea.run. We do not republish live flags, cracks, or DRM circumvention. Treat every CTF case as time-boxed authorization from the organizer.

Takeaways

  • Contest rules = your authorization boundary.
  • REA accelerates inventory; you still verify and write the story.
  • Never launder CTF habits into attacking production software you do not own.

More on-site cases