SANS Holiday Hack Challenge™ 2024

Join the global cybersecurity community in the most festive and challenging event of the year! The SANS Holiday Hack Challenge offers FREE, high-quality, and super fun hands-on cybersecurity challenges designed for all skill levels. Play to learn or practice your skills and stand a chance to win exciting prizes for the top entries.

Holiday Hack Challenge 2024: Snow-maggedon

Whether you're a first-time player or a seasoned participant, this year’s Holiday Hack brings exciting new features you won’t want to miss! We’ve introduced a new dynamic for this year: challenges will be gradually released* in sync with the story, keeping the experience fresh and immersive. See challenges release dates and new features included.

  • November 7........Prologue
  • November 11......Act 1
  • November 18......Act 2
  • December 2........Act 3

Skill Levels: Every challenge will offer two modes: an easy mode and a harder mode. Players can choose either mode to solve the challenge, depending on their skill level or preference.

Challenge Skipping: Each challenge will include a “play-through” mode, allowing players to advance the storyline without solving the challenge immediately. You can skip a challenge and return to it later.

Share Solutions: For the Prologue, Act 1, and Act 2, participants can post answers or livestream their solutions starting one week after each section's release. This allows others to learn from shared solutions and progress in the game. However, for Act 3, players must wait until after the competition ends before sharing their answers or solutions.

Scoreboard and Cohorts: Track your progress on a live scoreboard of all players, plus a separate scoreboard dedicated to a cohort exclusively for your organization or group of friends, allowing you to have a friendly competition with peers.

*Sign up below to be notified when new challenges are released.

Now Open!

The SANS Holiday Hack Challenge 2024: Snow-maggedon is here! Listen to Ed Skoudis, Chief Holiday Officer, in the Welcome and Game Orientation video to make the most of this cyber range. Join us on Discord to chat with other players, share tips, and connect through text or voice channels. Follow us on X for the latest updates. And if you're up for it, enter the contest for a chance to win one of the coveted Holiday Hack Challenge prizes!

Holiday Hack Challenge TM 2024 Now Open!

2024 Challenge Topics

  • Ransomware Reverse Engineering
  • Hardware Hacking
  • Web App Hacking with MQTT and Video Feed Manipulation
  • Video Game Hacking
  • Threat Hunting with KQL
  • SIM/SEM Analysis
  • Mobile App Penetration Testing
  • OSINT via Drone Path Analysis
  • Web Exploration with cURL
  • PowerShell for Cyber Defense

Enter The Contest for Grand Prizes!

If you'd like to enter the contest for a chance to win a prize, please submit a report with a description of how you solved each objective via email or on this Google form (https://forms.gle/mE8GAee2fSCxED1M7).
  • Reports should be submitted by the end of the day on January 3, 2025*. Alternatively, if you'd rather not use the Google form (https://forms.gle/mE8GAee2fSCxED1M7), you can email your answers to SANSHolidayHackChallenge@counterhack.com.

    You DO NOT have to answer all questions to be eligible to win a prize. All reports must be 75 pages or fewer in length.

    From all submitted entries, we'll pick three winners, according to the following plan:

    1. One random draw answer whose user has clicked on each of the five vendor booths (Google, Microsoft, RSAC, SANS.edu, and Holiday Hack Swag Store):
      1. HOLIDAY HACK CHALLENGE T-SHIRT
    2. The best technical answer:
      1. ONE SUBSCRIPTION TO NETWARS CONTINUOUS for FOUR MONTHS
    3. The most creative (while technically correct) answer:
      1. ONE SUBSCRIPTION TO NETWARS CONTINUOUS for FOUR MONTHS
    4. The best overall answer, our GRAND PRIZE WINNER:
      1. ONE SANS ONDEMAND TRAINING COURSE**

    Remember, even if you can't answer one or more of the questions, please do submit an answer of any kind to be entered in our random draw. Seriously, if you get 50%, 80%, or 98% of the answers, you'll still be eligible to win.

    The very best overall answer earns our Grand Prize - a complimentary SANS OnDemand course of your choice! The winner will choose from any of SANS' 30+ Online Courses, and will complete SANS training at their own pace from anywhere on the internet.

    Feel free to post answers from Prologue challenges after Act 1 launches (Nov. 11, 2024).  You can likewise post Act 1 challenges after Act 2 launches (Nov. 18, 2024).  And, you can post Act 2 answers after Act 3 launches (Dec. 2, 2024).  We kindly ask that you refrain from publicly publishing any answers, write-ups, or walkthroughs for Act 3 until after the competition ends on our submission deadline of January 3, 2025. Once that passes, please feel free to publish!

    Happy Holidays!

    --Counter Hack and Friends

     * Any time zone on planet Earth will do.

     ** SANS will choose only one winner for the Grand Prize. These prizes are not transferable to another person or event and do not include a certification attempt. Only one course will be awarded per category, regardless of how many people contributed to a winning submission. No substitutions are allowed. For any of these prizes, SANS is not responsible for lost, late, or unintelligible entries, lost connections, miscommunications, failed transmissions, reindeer attacks, or other technical difficulties or failures.

SANS Holiday Hack Challenge 2024 Winners and Answers

A shout-out to the players for a job well done figuring out difficult cybersecurity challenges.

Press Play for Music While You Play the Holiday Hack Challenge

Immerse yourself in the festive spirit of the SANS Holiday Hack Challenge, where talented musicians create awesome albums each year. Sing along and make your learning experience even more jolly! Also available on Apple Music, Amazon Music, and YouTube Music.

Expand to meet the 2024 Holiday Hack Challenge Team:

  • Producer:

    Ed Skoudis

    Challenge Wrangler:

    Mark Devito

    World Builder Builder:

    Evan Booth

    World Builders:

    Evan Booth

    Thomas Bouve

    Kyle Parrish

    Eric Pursley

    World Wranglers:

    Jared Folkins

    Vince Valenti

    Story Concept:

    Ed Skoudis

    Narrative and Dialogue:

    Kyle Parrish

    Eric Pursley

    AI Wranglers:

    Tooling: Evan Booth

    Dialog Creation: Kyle Parrish & Eric Pursley

    NPC Voice Tooling and Creation: Thomas Bouve

    Programming:

    Evan Booth

    Mark Devito

    Chris Davis

    Chris Elgee

    Jared Folkins

    Charlie Goldner

    Janusz Jasinski

    Kevin McFarland

    Torkel Opsahl

    Kyle Parrish

    System Builds & Administration:

    Jared Folkins

    Vince Valenti

    Artwork:

    Evan Booth

    Thomas Bouve

    Chris Davis

    Janusz Jasinski

    Kevin McFarland

    Eric Pursley

    Annie Royal

    Colton Slesser

    Voice Artists:

    Jason Blanchard

    Evan Booth

    Thomas Bouve

    Ch33r10

    Isabel Davis

    Chris Elgee

    Christy Elgee

    Emma Elgee

    Josh Elgee

    Prathika Gonchigar

    Kat Hessman

    Phoebe Jasinska

    Janusz Jasinski

    Joshua Jasinski

    Jeff McJunkin

    Jai Minton

    Kyle Parrish

    Divya Pursley

    Eric Pursley

    Lila Regas

    Ed Skoudis

    Johannes Ullrich

    Paddy Verberne

    Mark Walken

    Mark Walken (pitched)

    Challenge Development:

    Elisha Angeles

    Paul Beckett

    Evan Booth

    Thomas Bouve

    Chris Davis

    Mark Devito

    Chris Elgee

    Jared Folkins

    Charlie Goldner

    Tom Hessman

    Janusz Jasinski

    Simeon Kakpovi

    Kevin McFarland

    Torkel Opsahl

    Eric Pursley

    Maurice Wilson

    Josh “MSFT” Wright

    Sound Design:

    Eric Pursley

    Soundtrack:

    Ninjula, Ed Skoudis, and Josh Skoudis

    Website Design:

    Jared Olson

    Concierge Wranglers:

    Patrick Chapman

    Lynn Schifano

    Discord Coordinator (Dis-Coordinator?):

    Chris Elgee

    Swag Designer and Implementer:

    Colton Slesser (Designer & Implementer)

    Bel Valente Lucas (Implementer)

    Lynn Schifano (Implementer)

    Testing and Feedback:

    Evan Booth

    Thomas Bouve

    George Callow

    Chris Davis

    Mark Devito

    Michael Dopheide

    Chris Elgee

    Jared Folkins

    Vlad Grigorescu

    Tom Hessman

    Phoebe Jasinska

    Janusz Jasinski

    Joshua Jasinski

    Chet Kess

    Kevin McFarland

    Sam Oehlert

    Torkel Opsahl

    Eric Pursley

    Lynn Schifano

    Ed Skoudis

    Maurice Wilson

    Marketing Project Manager:

    Bel Valente Lucas

    Marketing Operations:

    Brett Snyder

    Cecilia Eklund

    Colton Slesser

    Debra Gawet

    Elissa Rodrigues

    Elizabeth Glomb

    Jared Olson

    Jay Bhalodia

    Jennifer Elston

    JR Santiaguel

    Katie Thomas

    Lacee Santos

    Laura O’Connor

    Michelle Petersen

    Sarah Wilson

    Sid Haase

    Tatyana Goldman

    Tober Corrigan

    Coin Design:

    Colton Slesser

    Sponsors:

    Google (Platinum)

    Microsoft (Gold)

    Amazon (Silver)

    RSA Conference (Silver)

    Extra Special Thanks To...

    The SANS Institute

Special Thanks To Our Sponsors

Practice Now | Explore the Legacy of Past Challenges

As you wait for the 2024 game to open, why not revisit the epic adventures of past Holiday Hack Challenges? Practicing with past games will prepare you to take on whatever this year's challenges throw at you!