Justas Kaminskas on what CTF is and how to win it

Capture The Flag (CTF) are cyber security competitions in which tasks are combined with unique, practical challenges. Participants in these competitions must draw on both technical skills and knowledge of current issues in cybersecurity. Justas Kaminskas, a cyber security engineer at NRD Cyber Security, has participated in numerous CTF competitions, most recently winning the SANS CTF EU title. We invited Justas to share why he decided to join cybersecurity competitions, what his journey has been like, and what motivates him to continue participating. We also asked him what advice he would give to those interested in CTF.

Icon
1. Tell us about how you first got into CTF—when was your first competition, how did you end up there, and what got you hooked?

I started in 2019; my first CTF was pico CTF, which was aimed at high school and college students. It was a great way to test my skills. But the process of solving and analyzing problems had been familiar to me for a long time—I have a bronze medal from the International Physics Olympiad. I see many similarities between math and physics Olympiads and CTFs. After graduating from high school, I chose cybersecurity as my career path, so I became more interested in these competitions. In 2024, I participated in my first in-person CTF event in Estonia. Later, my participation in various cybersecurity competitions continued to grow, and I began to win. In 2025, the National Cybersecurity Center (NKSC) selected a national youth team for a competition in Warsaw, and I became the captain of that team. This was the first time Lithuania had ever participated in an international youth competition of this scale.

2. CTFs are certainly popular competitions, but not just anyone can participate in them. What skills and knowledge do you think are necessary to participate in a CTF competition?

3. Which cybersecurity competition did you like the most or found most memorable, and why?

My favorite was the 2024 Hack the Box challenge, Operation Tinsel Trace II: Join the Resistance Against Krampus!, where we had to answer questions about the artifacts provided, which were “released” every few days, and the first person to solve that day’s challenge won. The very last, 6th challenge was the most difficult; it took me 5 hours to solve, and I was definitely feeling exhausted by then. Somehow I pulled myself together and won. Try hack me was also memorable because of the prize we won—together with the NRD Cyber Security team, we received twelve PlayStation 5 consoles.

4. All right, so what does it take to create a good CTF? You yourself created these challenges for the BSides Vilnius conference in 2025 and 2026.

Personally, I like real-world scenarios; for example, when creating a challenge for BSides Vilnius I used an investigation that actually took place in 2012. People enjoy it when they can not only complete a task but also learn something and analyze what happened and how. Most often, there isn’t a single story behind it; CTFs rarely have them – which is a shame, because that makes it much more engaging.

5. How long does it take to create assignments?
6. Does participating in a CTF enrich you in any other way?

7. Let's talk about SANS CTF EU. What made you decide to participate, and what tactics did you use to win (if you're willing to share, of course)?

The NKSC, which is a partner of the SANS CTF EU, shared information about the event. I saw it and decided to participate. The irony is that I might not have even been able to enter this competition at all. I kept putting off registration, and by the time I was ready… I couldn’t register anymore. I didn’t give up, and my third attempt to contact the organisers was successful – they let me participate.

I got very little sleep during the competition itself. I knew that it wasn’t just speed that mattered, but also the number of incorrect answers. I wasn’t among the leaders at any point during the competition, but I armed myself with patience and tried to make as few mistakes as possible and use as few attempts as possible. In the end, I made only one mistake, jumped up 30 spots, and became the winner. There were 300 participants left in the final; about 1,000 people participated in total.

8. A question on a very “hot” topic - artificial intelligence (AI): What challenges does AI pose for both participation in cybersecurity competitions and the creation of challenges? Are there any advantages as well?

It certainly presents many challenges, especially since AI is used to solve problems. Easy problems become even easier to solve, while harder ones become harder – but that’s just the way it is. And if AI can’t solve them, then no one can. So a dilemma naturally arises: is this a competition of cybersecurity knowledge and skills, or a contest to see who can make better and more effective use of AI’s capabilities? Organisers of in-person CTFs try to limit the use of AI, but doing so online is very difficult. That’s why, for example, reflecting on the BSides Vilnius conference, the organising team and I discussed holding next year’s CTF (which took place online this time) in person.

Undoubtedly, AI is becoming a part of our daily lives, both at work and everywhere else, so CTFs shouldn’t be an exception either, and we need to look for ways in which these competitions should and could evolve. When AI is used properly, it makes it easier to track information, follow sequences, and stay on track. This becomes especially valuable during sleepless nights, as it allows you to organise and process information more quickly. Also, AI plays an important supporting role – when you’re stuck, the right query can put you on the path to solving the problem.

9. What advice would you give to those who think CTF sounds like an interesting experience? Where should they start? Where can they find information?

Well, first of all, you need to take a broad interest in the field of cybersecurity, the incidents occurring around the world, and try to understand how they happened, how they are investigated, and how they are resolved. You’ll also definitely need technical skills and knowledge. You can use various online platforms for this, such as pwncollege, where you can learn how to “hack” programs.

Second, you need to give it a try. It’s worth starting with simpler competitions; for example, picoCTF would be a good choice. If you’re still in school, the NKSC organizes the Cyber Marathon (with monthly challenges), where you can test your skills. Also, for young people (up to age 25), the NKSC organizes an annual selection process for the national CTF team called Cyber Sprint, followed by training camps and other events.

There are certainly plenty of opportunities and ways to get involved, so I encourage you to give it a try and join these competitions. I hope the national team will thrive and grow stronger, and that we’ll make a name for ourselves on the international stage!

 

The key CTFs that Justas has participated in

November 2024: Telia Cyber Battle of Nordic-Baltic 2024 – we competed in the finals as a team; we did so-so, but managed to “snag” a few sponsor prizes for solving challenges the fastest
December 2024: HackTheBox, where we were the fastest to solve and win Challenge 6 and received a prize
January 2025: Try Hack Me SOC Simulator Team Competition, we took 1st place
May 2025: LockedShields, DFIR team
May 2025: CyberSprint Stage 2 (held in person, offline) where I won 1st place
May 2025: Organiser of the BSides Vilnius 2025 CTF
October 2025: Team captain at the ECSC (European Cyber Security Challenge), we did so-so, but it was the Lithuanian team’s debut
December 2025: Mārtiņa CTF in Latvia—at the https://mctf.datoriki.org/2025/, our team took first place among the teams participating online
December 2025: I won Trend Micro Nordic XMAS CTF, which was organised for their partners
April 2026: LockedShields, DFIR team
May 2026: Cybersprint participant
June 2026: BSides Vilnius 2026 CTF organiser
June 2026: SANS EU CTF winner

And in October 2026, I plan to participate in the ECSC in Germany again.

Other news and stories

SOCshare: 2026 July cyber landscape review
SOCshare: 2026 July cyber landscape review
In 2025, NRD Cyber Security saw growth in both its project-based activities and ongoing services
In 2025, NRD Cyber Security saw growth in both its project-based activities and ongoing services
SOCshare June 2026: cybersecurity landscape review
SOCshare June 2026: cybersecurity landscape review
The 3rd edition of the Guide for developing a National Cybersecurity Strategy
The 3rd edition of the Guide for developing a National Cybersecurity Strategy
SOCshare May 2026: News in cyber threat landscape
SOCshare May 2026: News in cyber threat landscape
SOCshare April 2026 review : Adobe Acrobat Reader, Claude and phishing
SOCshare April 2026 review : Adobe Acrobat Reader, Claude and phishing
SOCcare March 2026: A “Little Gift” from the photo shop
SOCcare March 2026: A “Little Gift” from the photo shop
Safe4SOC updates: enhancing CyberSOC efficiency through unified alert sharing
Safe4SOC updates: enhancing CyberSOC efficiency through unified alert sharing