FUEL FRENZY
A Percival Engineering CTF Event
JUNE 7-8, 2023
Visionist's Unrefined Hackers
Team 7
Parsons!
compete. hack. secure. learn.
About
Critical infrastructure systems are increasingly becoming targets for cyber attacks, and it's up to us to protect them! This CTF is designed to help raise awareness about the importance of protecting critical infrastructure from cyber threats while also supporting the development of skills and knowledge in the cybersecurity community.
A Capture the Flag (CTF) competition is where teams must solve a series of challenges to obtain flags for points. In Fuel Frenzy, teams will be tasked with various fuel-related challenges: securing fuel supplies, interrupting fuel transportation, protecting fuel-related assets, and disrupting fuel critical infrastructure.
Fuel Frenzy is a FREE event open to Government, Industry, and Academia
Must be a U.S. Citizen to Participate
Registration is Now Closed
Please review FAQ prior to registering & check back here regularly for updated information!
Day one: Pre-CTF Training
WED | JUN 7 | 9:00AM - 4:30PM | VIRTUAL ONLY
Online pre-event training focusing on tactics, techniques, and tools relevant to the CTF.
Link to live stream: https://www.youtube.com/watch?v=xI-NzPQ0zQM
Time | Topic | Description | Facilitator |
9:00 | Intro | Welcome to Fuel Frenzy! | Percival |
9:30 | ICS/SCADA Systems 101 | Intro to ICS/SCADA | Mr. Henry Budris (Percival) |
10:30 | ICS/SCADA Enumeration | Tools: GRASSMARLIN & NMAP | Ms. Kayla Hoffman (Percival) |
11:15 | BACnet: Building Automation & Control Networks Protocol | BACnet Usage & Capabilities | Mr. Connor Bluestein (Percival) |
12:00 | Break | ||
12:30 | Network Packet Captures (PCAPs) | Using Wireshark (Network Analyzer/Packet Capture Tool) to Analyze ICS/SCADA Traffic | Mr. Nicholas Jackson (Parsons) |
1:00 | Password Cracking Tools | Using John the Ripper or Hashcat to Break Encryption Using Wordlists | Mr. Vince Wolterman (Clear Ridge Defense) |
1:30 | Siemens S7 Network Protocol | Communication, Analysis, & Interfacing | Mr. Ian Swasing (Percival) |
2:15 | Reverse Engineering Tools | Ghidra | Mr. Mike J. Bell (BlueHalo) |
3:15 | Programmable Logic Controllers (PLC) | Reverse Engineering PLC Programming Ladder Logic | Ms. Kayla Hoffman (Percival) |
4:00 | Wrap-Up | Closing Remarks | Percival |
**agenda subject to change
MEET THE TRAINERS
Mr. Henry Budris, Percival Engineering: Mr. Budris joined Percival full-time in 2022 where he works on the team developing emulators for embedded devices. He works closely with various hardware components and reverse engineers their capabilities in an effort to emulate their functions in QEMU. Mr. Budris thoroughly enjoys sharing his cybersecurity knowledge through tech talks, helping teach classes at UMBC, and contributing to CTF events. He earned his B.S. in Computer Science and is pursuing a Masters Degree in Computer Science from University of Maryland Baltimore County.
Ms. Kayla Hoffman, Percival Engineering: Ms. Hoffman joined Percival in 2018 where she works hands-on with various ICS/SCADA systems. Her knowledge and expertise includes reverse engineering, network protocol analysis, and vulnerability research. She earned her B.S. in Computer Engineering from University of Maryland Baltimore County.
Mr. Connor Bluestein, Percival Engineering: Mr. Bluestein is currently interning at Percival while pursuing his undergraduate degree at Virginia Tech. He is a junior majoring in Computational Modeling and Data Analytics with a specialization in Cybersecurity and Cryptography. At Virginia Tech, Mr. Bluestein holds the position of Vice President in the Cybersecurity Club and serves as the Executive Officer for the Virginia Tech Corps of Cadets Cyber Team. He has actively participated in numerous CTF competitions and other challenges, honing his skills in areas such as forensics, data analysis, cryptography, and penetration testing.
Mr. Nicholas Jackson, Parsons: Mr. Jackson is a VP at Parsons, a Parsons Fellow, and has more than 19 years of experience supporting cyber operations, engineering, and development for the U.S. Department of Defense and Intelligence Community. Mr. Jackson has regularly shared his cyber thaumaturgy skills and expertise over the years via tech talks, large-scale interactive training sessions, and Capture the Flag events and trainings.
Mr. Vince Wolterman, Clear Ridge Defense: Mr. Wolterman leads both internal and external cybersecurity efforts for Clear Ridge Defense. He is a retired Army Chief Warrant Officer who brings technical and tactical expertise to bear for both our company and our clients. Mr. Wolterman has authored and disclosed multiple ‘0-day’ vulnerabilities and has participated in U.S. Government bug bounty programs. He earned his bachelor’s degree as a 2010 graduate of American Military University’s Homeland Security program, and holds a Master of Science, Cybersecurity and Information Assurance through Western Governors University. Formally trained and certified by the DoD Cyber Crime Center’s Cyber Training Academy, he also possesses over 20 additional technical certifications related to cybersecurity: most notably the Offensive Security Certified Expert (OSCE) certification. Mr. Wolterman understands a variety of adversarial decision-making processes due to his time with the 780th Military Intelligence Brigade and time spent overseas in support of U.S. operations in Iraq and Afghanistan. He brings this knowledge to bear when both leading Clear Ridge Defense’s Red Team on engagements and Clear Ridge Defense’s Blue Team in incident response.
Mr. Ian Swasing, Percival Engineering: Mr. Swasing joined the Percival team in 2020, after graduating with a Bachelor of Science in Electrical Engineering from Pennsylvania State University. With a passion for solving technical problems, Ian spends a lot of his time utilizing his experience in software development and network protocol analysis.
Mr. Mike J. Bell, BlueHalo: Mr. Bell has worked in the intelligence community for 23 years on a wide variety of projects and domains, and currently serves as an engineer at BlueHalo. He spent eight years helping to develop Ghidra, NSA’s Software Reverse Engineering (SRE) tool, and played a key role training analysts of all levels how to use Ghidra across the agency. Over the course of his time on Ghidra, Mr. Bell was involved in the design of many of its features, including the Function Graph, Version Tracking, Function ID and the Java Sleigh Compiler, as well as maintaining such processor models as x86, ARM, MIPS, 680x0 and PowerPC. Outside work, he enjoys spending time with his wife and two sons.
Day Two: Fuel FrenZY CTF
THU | JUN 8 | 9:00AM - 5:00PM | VIRTUAL & IN-PERSON
CTF Participant Platform Link: https://cyberskyline.com/events/fuel-frenzy
Teams are not auto-populated in the Cyberskyline CTF Platform. When you join the event, a team code will be generated for you. Use one team members code as the primary team code and have everyone else on the team transfer to the team using the team primary code.
For additional help, visit Cyberskyline at: https://docs.cyberskyline.com/team-management/manage-team-members
In-person participants please arrive between 8:00am to 8:30am to ensure you have enough time to sign-in and set-up
Time | Topic |
8:30 | Sign-In & Set-Up for In-Person Participants @ Percival Lite breakfast will be served for in-person participants |
9:00 | Intro/Welcome |
9:30 | CTF Phase One |
12:00 | Working Lunch Lunch will be served for in-person participants |
1:00 | CTF Phase Two |
4:00 | Break & Wrap-Up |
4:30 | Awards |
5:00 | Post-CTF Social All participants (in-person & virtual), sponsors, and trainers invited to attend Hors d’oeuvres and cocktails will be served |
CTF Communications & Virtual Participants
Discord will be used for all communications and virtual participation
Fuel Frenzy Discord Server: https://discord.gg/Ry45SMK9dx
Visit FAQ for more information on Discord
In-Person Participants
Percival Engineering
6220 Old Dobbin Lane, Suite 100, Columbia, MD 21045
FAQ
TRAVEL
Fuel Frenzy Event Location
Percival Engineering
6220 Old Dobbin Lane, Suite 100
Columbia, MD 21045
Park Outside Building Main Entrance
Suite 100 is 2nd Door on Left
Accommodations
While we are not partnered with any specific hotels for this event we can provide some recommendations based on proximity to event location:
Extended Stay America - Columbia Gateway Drive
Airports
Airports & Travel Time to Columbia, MD