Every winter, SANS turns a cybersecurity training range into an 8-bit holiday video game. You walk an avatar around a snowy neighborhood, chat with characters, open terminals, and solve hacking challenges to stop a villain from ruining the holidays. The SANS Holiday Hack Challenge is free, it runs from beginner warm-ups to expert puzzles, and it is one of the friendliest ways to try your first CTF. If you have never captured a flag at all, the five-minute Capture the Flag 101 lab shows you the basic loop in your browser before December arrives.
This guide explains what the Holiday Hack Challenge is, how its challenges and CTF mode work, what the 2025 edition actually asked players to do, what we know about the 2026 dates, how to prepare in six weeks, and how it compares with TryHackMe's Advent of Cyber.
TL;DR: The SANS Holiday Hack Challenge is a free, game-based CTF that SANS releases each holiday season. The 2025 edition opened on November 5 with 15+ micro-challenges of 10 to 15 minutes and 3 to 4 long capstones, and prizes went to players who submitted a write-up by January 5. Beginners can finish the first act with Linux basics, Nmap, and curiosity.
What Is the SANS Holiday Hack Challenge?
The SANS Holiday Hack Challenge is a free online cybersecurity game run by the SANS Institute. Players explore a holiday-themed virtual world and solve hands-on challenges in areas like Linux, networking, web application hacking, forensics, cloud security, and reverse engineering. Each challenge advances a story, and the hardest ones feed into a final write-up that can win prizes.
The game is built by Ed Skoudis, a SANS Faculty Fellow and President of the SANS Technology Institute, together with the Counter Hack team. The tradition is old. The official archive of past challenges goes back to 2010's "The Nightmare Before Charlie Brown's Christmas", and every year since has its own theme:
- 2015 - Gnome in Your Home: the Dosis family's suspicious smart toy, the setting the 2025 game came back to.
- 2018 to 2022 - KringleCon 1 to 5: the game was staged as a virtual hacker conference at the North Pole, with real conference talks alongside the challenges. Many people still call the whole event "KringleCon" because of these years.
- 2023 - A Holiday Odyssey: a tropical island trip.
- 2024 - Snow-maggedon.
- 2025 - Revenge of the Gnome(s): gnome dolls come to life in the Dosis neighborhood to help Frosty the Snowman freeze the world.
According to the SANS press release for the 2025 edition, the game has trained "hundreds of thousands of players worldwide." It is not a recruiting test or a qualifier for anything. You play for the skills, the story, and a shot at a prize.
Why Beginners Should Care
Most CTF competitions throw twenty challenges at you on a Friday night and give you 48 hours. The Holiday Hack Challenge runs for about two months, includes in-game hints, and puts the easiest challenges first. Ed Skoudis summed up the design in the 2025 announcement: "Holiday Hack has always been joyful, practical, and open to everyone." That is not just marketing. The Act 1 terminals explain each concept in plain English before asking you to use it.
How the Holiday Hack Challenge Works
You create a free account, pick an avatar, and land in the game world. Characters (called NPCs) give you a task, and their terminal or web link opens the actual challenge. Solve it and the next part of the story opens up. For 2025, SANS split the work into two tiers:
- Micro-challenges: "15+ bite-sized challenges designed to take 10-15 minutes (or less)," per the official challenge page. These are the on-ramp: a phishing triage tool, an Nmap tutorial terminal, a visual firewall puzzle.
- Capstone challenges: "3 to 4 large, in-depth challenges" that pull the skills together and take hours. These are what the prize write-ups mostly cover.
Traditional Mode vs CTF Mode
The game world is charming, but walking an avatar around to find the next terminal is not everyone's idea of fun. Your in-game badge (in 2025, a snowball around your avatar's neck) lets you switch between two styles:
- Traditional: walk the neighborhood, talk to characters, pick up items, and find terminals in buildings.
- CTF Style: skip the world and avatars and get every challenge, terminal, and file straight from the badge.
Our take: play Traditional for Act 1. The conversations carry the hints and the story context, and part of the fun is stumbling on clues in the world, like a crumpled receipt lying outside a restaurant. Switch to CTF Style later if the walking starts to annoy you.
Hints, Skips, and Cohorts
The badge collects the hints you earn by talking to characters. In 2025, you could also summon a holographic Santa from the badge for gentle nudges that do not give the answer away. If a challenge blocks you completely, a play-through option lets you advance the story without solving it, so one hard puzzle never locks you out of the rest of the game.
Teachers and study groups can create a cohort, which gives them a live scoreboard limited to their own group. If you are in a school club or a company team, this is the easiest way to turn the event into a friendly competition.
What the 2025 Holiday Hack Challenges Looked Like
The official 2025 topic list covered defanging IOCs, sudo, port discovery, forensic analysis, basic networking, firewall basics, Nmap basics, curl basics, IDOR, using proofs of concept, Java deserialization, quantum computing, reverse engineering, SQL injection, Linux privilege escalation, and web app pentesting. Microsoft and Google contributed grand challenges. That range sounds intimidating, so here is what three of the early challenges actually asked for.
It's All About Defang (Phishing Triage)
The very first challenge, given by Ed Skoudis's own character, opens a mock SOC tool with a suspicious email. Your job is to pull every indicator of compromise out of it (sender domains, IP addresses, URLs, phone numbers) and "defang" them so nobody can click them by accident. Defanging just means rewriting an indicator so it stops being live:
https://evil-cdn.example/update.exe -> hxxps://evil-cdn[.]example/update.exe
203.0.113.45 -> 203.0.113[.]45
No hacking tools, just careful reading of email headers. It is a good reminder that half of security work is spotting what does not belong.
Intro to Nmap
This terminal splits the screen in two: instructions on top, a Linux shell below. Each step asks a question you answer with one Nmap command, and the next step appears when you get it right. The first steps look like this:
- Run a default scan (top 1000 TCP ports):
nmap 127.0.12.25 - Scan all 65,535 TCP ports when the default finds too little:
nmap -p- 127.0.12.25 - Scan a range of addresses:
nmap 127.0.12.20-28 - Identify the service behind an open port:
nmap -sV -p 8080 127.0.12.25
The full-port scan is the lesson that sticks. According to the published write-up by 0xdf, the default scan in the game's Nmap 7.80 terminal shows only port 8080, while -p- turns up the real target:
$ nmap -p- 127.0.12.25
PORT STATE SERVICE
24601/tcp open unknown
That is exactly the mistake beginners make on real CTF machines: they run a default scan, see one web port, and never find the service hiding on a high port.
IDORable Bistro (Web IDOR)
In Act 2, you pick up a crumpled restaurant receipt with a QR code. Scanning it opens a payment status page, and your browser's Network tab shows the page loading its data from an API call like /api/receipt?id=103. Change 103 to 102 and the server happily returns another customer's receipt. That is an insecure direct object reference (IDOR): the server trusts the ID you send without checking that the receipt belongs to you.
In practice, this is one of the most common bugs in real bug bounty reports, and the Holiday Hack version teaches the right reflex: always open DevTools, watch which API requests a page makes, and try changing every ID you see. The IDOR Explorer lab drills the same reflex on a document manager that hands out files by sequential ID.
The Hard Part: Acts 2 and 3
The later challenges are a real step up. Write-ups of the 2025 game cover a Tomcat deserialization chain, JWT forgery with a malicious key URL, prompt injection against an AI assistant, CAN bus signal analysis, and decompiling a packaged Python game. Do not expect to finish these in your first year. Getting through Act 1 and part of Act 2 as a beginner is a genuinely good result.
When Is the 2026 Holiday Hack Challenge?
As of October 2026, SANS has not announced dates for the 2026 SANS Holiday Hack Challenge. The best guide is last year's timeline, all taken from SANS's own pages:
- Launch: the 2025 game opened on November 5, 2025.
- Spoilers allowed: players could publish walkthroughs after November 26, 2025, as long as they labeled spoilers.
- Report deadline: write-ups were due by the end of January 5, 2026, in any time zone.
- After the contest: "The cyber range stays open year-round," so the challenges remain playable after prizes close.
Bookmark the official SANS Holiday Hack Challenge page and the game's Discord for the announcement. If the pattern holds, you have about four weeks before launch, and the game then stays open for two months, so a six-week plan fits comfortably.
Prizes and the Write-Up
To compete for prizes, you submit a report on what you solved and how. The rules for 2025 were relaxed: reports could be up to 75 pages, and you did not need to answer every question to be eligible. The 2025 prizes were:
- Grand prize: one SANS OnDemand training course of the winner's choice (certification attempt not included).
- Best technical answer: a six-month subscription to SANS Skill Quest by NetWars.
- Most creative (and technically correct) answer: a six-month subscription to SANS Skill Quest by NetWars.
- Random draw: a Holiday Hack Challenge T-shirt for players who visited all five sponsor booths in the game.
Even if you never win, write the report. A clean write-up of five or six challenges, with commands and screenshots, is a portfolio piece you can link on a resume. Hiring managers read those.
How to Prepare for the Holiday Hack Challenge in 6 Weeks
You do not need to be ready for Act 3. You need to be comfortable enough that the Act 1 terminals feel like practice, not panic. This plan assumes a few hours a week:
- Week 1 - Linux terminal: navigate directories, read files, search with
grepandfind, and understand file permissions. Many terminals drop you into a shell and expect you to find your way around. - Week 2 - Networking and Nmap: learn what a port is, how TCP connections start, and the four Nmap commands from the section above. Then connect to what you find with
ncorcurl. - Week 3 - HTTP and DevTools: read requests and responses in your browser's Network tab, edit a cookie, resend a request with a changed parameter. Most Holiday Hack web challenges start here.
- Week 4 - Common web bugs: IDOR, SQL injection, and command injection. You only need to recognize them and try the basic payloads.
- Week 5 - Linux privilege escalation:
sudo -l, SUID binaries, and writable scripts. Several capstones end with a root step. - Week 6 - Note-taking and write-ups: solve two practice challenges and write each one up in a page. This becomes your Holiday Hack report template.
If you want a structured version of this list with challenges at each step, our CTF for beginners guide explains the categories, tools, and the first platforms to try.
Tips for Your First Holiday Hack
- Read every conversation. Characters drop hints in their dialogue, and your badge keeps every hint you have earned in one place.
- Take notes from day one. Paste every command and answer into a file as you go. Rebuilding them in January for the report is miserable.
- Avoid spoilers until you are stuck for an hour. Then read only the hint or the paragraph you need, not the whole walkthrough.
- Do not skip the easy ones. The micro-challenges are where the game teaches the techniques the capstones assume.
Holiday Hack Challenge vs Advent of Cyber
The other big free December event is TryHackMe's Advent of Cyber. People often ask which one to do. They are built differently:
| Feature | SANS Holiday Hack Challenge | TryHackMe Advent of Cyber |
|---|---|---|
| Cost | Free | Free |
| Format | Explorable 8-bit game world, or CTF mode | One guided room per day, 24 in total (2025) |
| Pace | Everything released together, about 2 months to play | Daily drip through December |
| Guidance | Hints from characters, little hand-holding later | Step-by-step teaching inside each room |
| Difficulty ceiling | Expert-level capstones | Mostly beginner to intermediate |
| Prizes (2025) | SANS course, NetWars subscriptions, T-shirts | Prize draw, $150,000 pool per TryHackMe |
| How you win | Write-up judged on quality and creativity | Each completed room is a draw entry |
Our recommendation: if you are brand new, do Advent of Cyber's daily rooms and play Holiday Hack Act 1 on weekends. If you already have a few CTFs behind you, put your energy into Holiday Hack and its report, because a judged write-up is a better learning exercise than a prize draw.
Neither event lasts all year. When they end, you will want live competitions with a scoreboard, and our list of CTF competitions to join covers the free ones that run through the rest of the calendar.
Legal and Ethical Considerations
Critical reminder: Always get explicit written authorization before testing any system. The Holiday Hack Challenge authorizes attacks only on the challenge targets it gives you.
- Stay in scope: attack the terminals and challenge URLs the game hands you. Do not scan or attack SANS infrastructure, the game servers themselves, or other players. The 2025 game even included a challenge about respecting scope, and it is there for a reason.
- Respect the spoiler rules: in 2025, public walkthroughs were only allowed after November 26, and they had to be labeled as spoilers. Follow whatever date SANS sets for 2026.
- Submit your own work: prize reports must be your own unique write-up. Copying someone else's walkthrough gets you disqualified and teaches you nothing.
- Leave the techniques in the lab: changing an ID in a URL feels harmless in a game. On a real website without permission, the same request can break computer misuse laws in most countries.
Frequently Asked Questions
Is the SANS Holiday Hack Challenge free?
Yes. The SANS Holiday Hack Challenge is completely free to play, including the challenges, the hints, and the prize contest. You only need to create an account. SANS describes it as a free global cybersecurity game, and the cyber range stays open after the contest closes.
Is the Holiday Hack Challenge good for beginners?
Yes, for the first act. The 2025 micro-challenges were designed to take 10 to 15 minutes each and covered basics like Nmap, curl, and firewall rules with step-by-step instructions. The capstone challenges are expert level, so beginners should expect to finish only part of the game.
When does the 2026 Holiday Hack Challenge start?
SANS had not announced the 2026 dates as of October 2026. The 2025 edition launched on November 5, 2025, and accepted prize reports until January 5, 2026. Check the official SANS Holiday Hack Challenge page for the 2026 announcement.
Is KringleCon the same as the Holiday Hack Challenge?
KringleCon was the virtual conference format the Holiday Hack Challenge used from 2018 to 2022, with talks and challenges at the North Pole. Since 2023 the event has used other themes, but it is the same yearly SANS challenge.
Do I have to solve every challenge to win a prize?
No. In 2025, SANS stated that you did not need to answer every question to be eligible. Prizes were judged on submitted reports, with awards for the best technical answer and the most creative answer, plus a grand prize of a SANS OnDemand course.
Can I play past Holiday Hack Challenges?
SANS keeps the latest edition's cyber range open year-round, and the past challenges page links to older games and official answers going back to 2010. Some recent past editions are marked as no longer available, so the current game is the most reliable way to practice.
Last verified: October 2026. Dates, challenge formats, topics, prizes, and report rules checked on the SANS Holiday Hack Challenge page, the SANS 2025 press release, and the official past challenges archive. Advent of Cyber details checked on TryHackMe's 2025 event terms and blog.
Your Next Steps
The SANS Holiday Hack Challenge is the most fun way to spend a December learning security, and the first act is genuinely beginner-friendly. Sign up for the SANS announcement now, play the current cyber range to get used to the badge and terminals, and start the six-week plan so Act 1 feels easy on launch day.
For the prep itself, practice where you get guidance. Run Learning Lab 102 for scanning and privilege escalation, try the IDOR Explorer lab for web logic bugs, and work through HackerDNA's Hacking 101 course to fill in the networking and Linux basics behind both. Start with HackerDNA's free tier - no credit card required, and every lab runs in your browser.