CTF Event
A two-round Capture The Flag competition — a 12-hour online Jeopardy preliminary followed by a 24-hour on-site final (Attack & Defence and Jeopardy Defence) for the top 30 teams.
View CTF rounds →
Cybersecurity Event & Capture The Flag
A two-day cybersecurity gathering featuring CTF competitions, expert keynote talks, hands-on workshops, and industrial pitching — organized by FSKM, UiTM Shah Alam.
$ ./start_ihack.sh --event 2026
[*] Loading: CTF, Keynote, Workshops...
[*] Preliminary: 12hr Jeopardy | Finals Attack & Defence + Jeopardy Defence
[+] iHack 2026 — 17-18 November (Tuesday & Wednesday). See you there!
iHack 2026 is an biennial cybersecurity event organized by the Faculty of Computer and Mathematical Sciences (FSKM), Universiti Teknologi MARA (UiTM) Shah Alam. Held on 17–18 November 2026 (Tuesday & Wednesday), the event brings together students, industry professionals, and security enthusiasts for an immersive two-day experience.
Beyond the flagship Capture The Flag (CTF) competition, iHack features a keynote talk from industry experts, three specialized workshops, and an industrial pitching session — connecting academic talent with real-world cybersecurity opportunities.
To cultivate cybersecurity talent, promote ethical hacking practices, and build a vibrant community of security enthusiasts within Malaysia's academic landscape.
iHack 2026 comprises five core components across two days of learning, competition, and industry engagement.
A two-round Capture The Flag competition — a 12-hour online Jeopardy preliminary followed by a 24-hour on-site final (Attack & Defence and Jeopardy Defence) for the top 30 teams.
View CTF rounds →An inspiring session delivered by a leading cybersecurity expert, sharing insights on industry trends, career pathways, and the evolving threat landscape.
Investigate digital evidence through Linux and Windows log analysis. Learn to identify suspicious activities using grep, awk, and SIEM concepts while developing the investigative mindset of a Blue Team analyst.
Harness the power of AI to transform public social media data into actionable intelligence. Explore SOCMINT techniques, web scraping, and Large Language Models (LLMs) to collect, classify, and analyze information with confidence.
An introductory cybersecurity workshop designed for secondary school students, sparking early interest in ethical hacking and digital safety.
Students showcase their Final Year Project related to Cybersecurity solutions to industry player and security community.
Hands-on cybersecurity and data analysis sessions
Learn SOCMINT techniques, scraping, and AI-based sentiment analysis using LLMs.
Hands-on Linux/Windows log analysis using grep, awk, and SIEM concepts.
Proudly supporting iHack 2026 cybersecurity workshops and activities.
Two rounds — a 12-hour online Jeopardy qualifying round, then a 24-hour on-site final for the top 30 teams.
All registered teams compete remotely in a Jeopardy-style CTF. Solve a series of challenges to qualify for the final round. Scoring is based on both correctness and speed of completion.
Finalists compete on-site across two 12-hour phases: Attack and Defence, followed by Jeopardy Defence focused on defensive cybersecurity skills.
Jeopardy-style challenges in the 12-hour preliminary round cover these domains.
SQL injection, XSS, SSRF, authentication flaws, and modern web vulnerabilities.
Disassembly, decompilation, and binary analysis.
Memory dumps, disk images, and digital evidence analysis.
Classical ciphers, RSA, hashing, and encoding challenges.
Buffer overflows, ROP, heap exploits, and memory corruption.
Packet analysis, protocol abuse, and network-based challenge solving.
Smart contract flaws, on-chain analysis, and blockchain security challenges.
NewMisconfigured cloud services, IAM issues, and exposed cloud functions.
NewPrompt injection, LLM abuse, and AI-assisted attack and defence scenarios.
NewThe 24-hour on-site final is split into two 12-hour phases on 17–18 November 2026.
Duration: 12 hours. Teams attack and defend simultaneously — exploit opponents while securing their own systems under live competition conditions.
Duration: 12 hours. Teams solve defensive-focused challenges involving: Active Directory, threat analysis, log analysis, incident response, system hardening, and defensive scripting.
17–18 November 2026
Dewan Mawar Qaseh, UiTM Shah Alam
3–4 Members
RM 50 / team
Top 30 Teams
Undergraduate Students
Participants must provide proof of university enrollment and age during registration:
The competition follows standard online and onsite CTF rules commonly adopted in cybersecurity competitions. Additional technical and operational rules may be provided prior to the competition.
As artificial intelligence tools become increasingly integrated into cybersecurity workflows, the competition aims to balance innovation, fairness, and human skill assessment.
Integrity and sportsmanship are critical components of the competition. Any participant or team found involved in cheating, misconduct, collusion, exploitation outside intended scope, plagiarism, or suspicious activity may be investigated by the organisers.
The organizer reserves the right to make final decisions regarding competition enforcement.
Team registration and payment via the online form.
Final deadline to register for the preliminary round.
12-hour online Jeopardy CTF (RM 50 per team). Top 30 teams qualify for the final round.
Opening ceremony, keynote talk, workshops, and final Phase 1 — Attack and Defense begins (RM 200 per team).
Phase 2 — Jeopardy Defense, industrial pitching, secondary school workshop, and prize ceremony.
CTF and event registration will open soon. Stay tuned for the official announcement — content on this site is not final and will be updated.