Skip to content

Repository files navigation

AegisArena

A single-player and small-team Attack/Defense (AWD) training environment in which one human team competes against three virtual teams driven by OpenAI-compatible APIs.

This project is a fork of domysh/CTFBox, currently based on upstream commit ab08f4a. CTFBox was originally derived from OASIS. This repository retains the upstream AGPL-3.0 license and attribution; it is not an independently built competition platform.

Use this project only on isolated training networks that you own or are explicitly authorized to use. The sample services are intentionally vulnerable. Never expose them to the public Internet or run untrusted players on a host that contains important workloads.

What It Simulates

  • A gameserver that generates, stores, retrieves, and validates dynamic flags on every tick
  • Service availability (SLA), attack scoring, flag expiration, and a live scoreboard
  • Four isolated Incus-based team environments connected through a WireGuard competition network
  • Three competition network phases: freeze, lock, and unlock
  • Sample Web and Pwn services with their corresponding checkers
  • A human-operated Team 1 and three LLM-operated teams using distinct strategies
  • Deterministic fallback exploits for all three built-in vulnerabilities, preventing matches from stalling when the models defend without attacking

AegisArena is not a complete replica of a production competition. Virtual opponents remain constrained by model capability, prompts, and tool boundaries. Traffic replay, a WAF console, and the improvisation of human teams are not included by default.

Recommended Environment

  • An x86_64 Ubuntu 22.04 or 24.04 VM or dedicated host
  • Docker Engine and the Docker Compose plugin
  • Python 3.10 or later
  • Minimum: 4 vCPUs, 8 GB RAM, and 40 GB disk space
  • Recommended: 8 vCPUs and 16 GB RAM
  • Host support for inbound WireGuard UDP traffic and the capabilities required for nested containers

On macOS, including Apple Silicon systems, run an x86_64 Ubuntu VM in Parallels or UTM and deploy AegisArena inside that VM. Do not place the training range and important projects on the same unisolated host.

Quick Start

git clone https://github.com/pity11/AegisArena.git
cd AegisArena

cp config.example.json config.json
# Update server_addr, every token, resource limits, and match timing.
$EDITOR config.json

./run.py start

Common endpoints:

http://SERVER_IP:8088  Gameserver and scoreboard
http://SERVER_IP:4040  Player credential distribution
UDP 55100              WireGuard, as defined by the sample configuration

Generated config.json files, WireGuard private keys, runtime data, and AI state are excluded by .gitignore. Never force-add them to Git.

For full deployment, AI provider, match lifecycle, and troubleshooting instructions, see:

Running Without AI

The AI bots are an independent extension. CTFBox continues to operate when they are disabled. Teams 2–4 remain static targets: their checkers continue to maintain flags and SLA, but the teams do not attack or patch services.

Changes from Upstream

This fork primarily adds:

  • three boundary-constrained LLM AWD bots;
  • registry, npm, PyPI, APT, and Go proxy adjustments for constrained network environments;
  • vfs storage support for Docker inside Incus; and
  • a single-player, four-team training configuration with operational documentation.

License and Attribution

This project is distributed under the GNU Affero General Public License v3.0. If you modify the software and make it available to users over a network, comply with the AGPL-3.0 source-availability requirements and preserve upstream attribution.

See NOTICE for modification notes and provenance.

Upstream and design references:

This software is provided without warranty; see the AGPL-3.0 license for details.

About

Single-player CTFBox AWD lab with three LLM-driven opponent teams

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages