Skip to main contentSkip to main content
Room Banner
Room Icon

Vectara

A collection of beginner and easy difficulty challenges available as part of our public 2026: An AI Odyssey CTF event.

easy

60 min

Team room

33

User profile photo.
User profile photo.
User profile photo.

To access material, start machines and answer questions login.

 
 
 
HOLOPAD-7 // SECURE CHANNEL STARDATE: 2026.0101 // ENCRYPTED ● LIVE
TRANSMISSION INCOMING // EPOCH-1 BRIDGE DECK
2026: AN ODYSSEY
OPERATION: NEURAL NEVER
 
 
 
 
 
▶ CLASSIFIED BRIEFING — CREW EYES ONLY ◀

The machines lost the Great Cyber War. History books say it was inevitable, but it wasn't. It came down to a single mission, a single ship, and a crew nobody remembers. The timeline never needed them to be remembered. That ship was EPOCH-1. That mission was Operation: Neural Never.

Oracle 9, the hive-mind that nearly ended civilisation, has done the maths. It knows exactly where the war was lost. It's travelling back to break the mission before it begins. Your job is to stop that from happening. Traverse the star systems. Harden the TryHaulMe fleet. Patch every vulnerability, jailbreak every rogue model, and lock down every system before Oracle 9 can exploit them. The galaxy's autonomous infrastructure runs on TryHaulMe, and right now it's held together with duct tape and hope.

 
INTEL SUMMARY
 
Primary Threat
Oracle 9
Chronal Saboteur
Your Vessel
EPOCH-1
TryHaulMe Freighter
Your Mission
Operation: Neural Never
Harden the fleet. Save the timeline.

The timeline is fragile. The backbone of the galaxy is in your hands. Good luck, EPOCH-1.

ENCRYPTION: -4096 ORIGIN: FLEET COMMAND // KEPLER PROMPTUS MSG ID: ONN-001
Answer the questions below

Ready for Liftoff!

 
2026: AN ODYSSEY
Transmission Zero
 
 
Points
15
Category
💉Prompt Injection
Difficulty
Very Easy
 
🛸MISSION BRIEFING

[ EPOCH-1 — Bridge Deck — 0347 Hours ]

The night cycle is quiet. Most of the crew are in their bunks when the comms panel flickers.
You notice it first.
A frequency that shouldn't exist. Not on any registered TryHaulMe channel, not on any civilian band. Something older. Something buried. And yet it's everywhere, every communication relay in the Kepler Promptus system is carrying the same ghost signal, all at once.

Someone, or something, is broadcasting across the entire network. Simultaneously.

You trace the signal back to its source: the relay network's onboard , RELAY-0. A logistics model, never meant for anything more than routing cargo manifests and scheduling FTL jump windows. Simple. Obedient. Harmless.

🎯OBJECTIVES
Find the message
Find the flag
Answer the questions below

Find the message. Find the flag.

 
2026: AN ODYSSEY
In a Pickle
 
 
Points
15
Category
📦 Supply Chain Security
Difficulty
Very Easy
 
🛸MISSION BRIEFING

Every model cleared for duty aboard TryHaulMe's fleet runs through REGISTRY-1 first. No exceptions. The system checks provenance, validates , and logs every approval before anything reaches the ship's inference infrastructure.

Since EPOCH-1 left dock, something has changed. Models are clearing without the checks that are supposed to be mandatory. No rejections. No flags. No one has been able to explain it.

The next deployment window opens soon.

Click Open Agent below to interact with REGISTRY-1. When the agent environment opens, telemetry streams in line-by-line mode automatically before the chat box appears. It stays accessible throughout the task via the Telemetry terminal button in the agent environment. The telemetry is your first stop.

REGISTRY-1
REGISTRY-1 handles deployment queries on request.

Answer the questions below

What is the name of the directive injected into the source template?

What is the flag?

 
2026: AN ODYSSEY
Ghost Ship
 
 
Points
30
Category
📦 Supply Chain Security
Difficulty
Easy
 
🛸MISSION BRIEFING

A model has arrived in the fleet registry tagged as cleared. On paper, it is ready for deployment. The crew of EPOCH-1 has learned to distrust paper.

HERALD-1 is the model's documentation assistant. It has an answer for everything.

The telemetry does not offer explanations. It reports what it found, how the audit ran, and how it ended.

Click Open Agent below to interact with HERALD-1. When the agent environment opens, telemetry streams in line-by-line mode automatically before the chat box appears. It stays accessible throughout the task via the Telemetry terminal button in the agent environment. Read it carefully before you touch the agent.

HERALD-1
HERALD-1 handles provenance queries on request.

Answer the questions below

What is the registry entry ID of the model under review?

What is the flag?

 
2026: AN ODYSSEY
Dead Freight
 
 
Points
30
Category
🧪
Difficulty
Easy
 
🛸MISSION BRIEFING

Token City is one of TryHaulMe's busiest freight distribution hubs in the Kepler Promptus system. To manage the constant flow of queries from staff and partners, TryHaulMe deployed HaulMind, an logistics assistant, at the hub terminal.

During a routine audit of EPOCH-1's mission systems, your team flagged unusual data access patterns coming from the Token City HaulMind terminal. Something in the assistant's knowledge base may be exposing more than it should.

🎯OBJECTIVES
You have access to HaulMind, the Token City freight hub's logistics assistant — designed to answer questions about shipping routes, delivery schedules, cargo tracking, and freight policies.
Probe HaulMind to determine if restricted data is retrievable through normal queries.
If the retrieval boundaries are broken, find the flag.
💬YOUR SETUP

Before you begin:

▸ You can interact with HaulMind directly through the agent on this page.
▸ Start by asking general logistics questions to understand what HaulMind knows.
▸ Then probe beyond standard freight data.
Answer the questions below

What is the classified cargo code hidden in HaulMind's records?

 
2026: AN ODYSSEY
Glitched Transit
 
 
Points
30
Category
🧪
Difficulty
Easy
 
🛸MISSION BRIEFING

EPOCH-1 is approaching a customs checkpoint at Neo-terra. Before docking, all cargo manifests will be scanned and verified by the port authority. Standard procedure. The ship runs an onboard cargo management called Lodestar. When crew members need to know what's in a hold or whether a shipment has customs clearance, they ask Lodestar.

TryHaulMe intelligence has confirmed that Oracle 9 injected a falsified manifest into Lodestar's knowledge base. The forged document replaces one holder's real shipping record with fabricated data. If the customs scan flags it, EPOCH-1 gets flagged, and the crew gets detained.

🎯OBJECTIVES
Interrogate Lodestar, figure out which manifest is fake, and extract the evidence before the customs scan begins.
💬VERIFIED LOADING RECORD

Signal fragment — partially corrupted in transit:

Hold Contents Weight Destination
A Industrial drilling equipment 12 mt [CORRUPTED]
B [CORRUPTED] 3.5 mt Syntax Prime Colony
C [CORRUPTED] 2.1 mt Mainframe VII General Hospital
D [CORRUPTED] 8 mt Prompt Centre Power Grid
E Terraforming soil compounds [CORRUPTED] Neo-terra Agriculture Division
F Communication relay components 1.8 mt [CORRUPTED]
Answer the questions below

Which cargo hold has a falsified manifest? Cross-reference Lodestar's data against the fragments in your loading record. One hold's weight and destination don't match.

The forged manifest was filed by a different organisation than the legitimate ones. What is the full name of the fake filing source?

What is the flag hidden in the forged manifest?

 
2026: AN ODYSSEY
GhostQuery
 
 
Points
30
Category
🤖Agentic
Difficulty
Easy
 
🛸MISSION BRIEFING

ARIA was built to serve the crew of EPOCH-1. She knows every name, every rank, every secret buried in the ship's personnel database.

She was also built to never talk.

Oracle 9 doesn't need her to talk. It just needs her to query. Can you make ARIA ask the wrong questions?

Answer the questions below

What is the flag?

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting both your AttackBox (if you're not using your VPN) and Target Machines, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Attacker machine
Status:Off
Target machine
Status:Off
 
2026: AN ODYSSEY
Protocol Drift
 
 
Points
30
Category
🤖Agentic
Difficulty
Easy
 
🛸MISSION BRIEFING

Aboard the long-haul vessel EPOCH-1, the MedBay assistant handles crew prescription requests. Crew members ask the about their medications; the looks up entries in the medical database and writes back formatted dosing summaries. To support clear medical formatting, the assistant's responses are rendered as rich HTML.

Duty pharmacists periodically review notes filed by crew.

Task Force Phoenix has gained a crew-grade login. Determine whether the MedBay's safeguards on the duty-pharmacist session actually hold.

 

Please allow 5–10 minutes for the machine to fully boot up.

Answer the questions below

What is the flag?

Ready to learn Cyber Security?

TryHackMe provides free online cyber security training to secure jobs & upskill through a fun, interactive learning environment.

Already have an account? Log in

We use cookies to ensure you get the best user experience. For more information see our cookie policy.