Code, Collaboration, and Community: NuttyShell

 

NuttyShell is more than a hacking club; it is a community driven by collaboration and mentorship. Their journey spans intense, multi-hour marathons like the HKCERT CTF, where staying focused meant supporting teammates the moment they got stuck. Senior members stepped up to teach defensive thinking to those with zero blue-team experience, while others used their web development backgrounds to build their Open CTF frontend.

Supported the team’s technical anchor, coach Mr. Hopkins Kong, the team developed vital leadership, communication, and time-management skills. Having benefited immensely from the cybersecurity ecosystem themselves, hosting the annual PolyU Open CTF is their way of giving back—creating real opportunities for others to challenge themselves and fall in love with cybersecurity.

 


FENG student

Mr. ZHAO Bingcheng Leo
Mr. TANG Cheuk Hei Kelvin
Mr. PINO SANGUINETI Jose Manuel
Mr. LUO Junhua Lawrence
Faculty of Engineering
Department of Electronic and Information Engineering

Award:

  • Champion of Open Category, HKCTF CTF Challenge 2025
  • 2nd runner-up of the Tertiary Category, HKCTF CTF Challenge 2025

 

Domain Expertise:

Attack-and-Defense Security Architecture

In live security operations, systems engineers do not just build systems; they must actively defend them. Kelvin and Jose describe the "Attack-and-Defense" format, which mirrors real-world enterprise security. This engineering discipline requires keeping vulnerable systems online while actively monitoring attacks, writing software patches on the fly to close vulnerabilities, and deploying these hot-patches without breaking system availability or functionality.

Lawrence emphasizes this hands-on defense engineering workflow: learning how to analyze incoming payloads, identify system weaknesses under pressure, and apply rapid patches to maintain access controls.

Automated Exploit Engineering

Manual penetration testing is insufficient in high-tempo, automated environments. Jose and Kelvin highlight the engineering necessity of automation in modern security operations. In standard competitions, you solve a challenge once; however, in dynamic environments, engineers must "automate exploitation to get points every tick." This involves writing automated scripts and tools to maintain access, deliver exploit payloads continuously across multiple targeted infrastructures, and dynamically modify exploits to counteract the defenses and patches deployed by opposing teams.

Threat Monitoring

Engineers must establish deep visibility over their systems to detect intrusions. Lawrence details the technical knowledge acquired in telemetry and monitoring using industry-standard tools: "I gained hands-on experience using tools like Grafana to visualize traffic and better understand what was happening in real time." Additionally, the students utilized OSINT (Open Source Intelligence) and external security assessment tools to map network attack surfaces, gather threat intelligence, and evaluate targets from both offensive and defensive perspectives.

Protocol Analysis

Security engineering often requires working with legacy, proprietary, or undocumented software and network structures. Jose describes a scenario involving an unfamiliar industrial communication protocol. To exploit it, he had to perform deep protocol analysis—reversing the system's packet structures, state machine, and data flow to understand how it communicates under the hood. This systematic analysis allowed him to uncover logical or buffer flaws and engineer a precise exploit where only one other participant globally succeeded.

Agentic AI

With the emergence of agentic Large Language Models (LLMs) like Anthropic’s Claude 4.6 in early 2025, security engineering has shifted towards AI integration. Kelvin and Jose discuss the engineering paradigms of using AI for automated code analysis and vulnerability discovery. They highlight how agentic LLMs can now "one-shot" medium-difficulty challenges without human intervention. This requires modern security engineers to learn how to integrate LLMs into active exploitation/defense workflows while designing complex, highly advanced, niche systems to resist automated AI-driven attacks.

 

Lifelong Learning Excellence:

Adaptability and Flexibility
  • Overcoming unexpected infrastructure changes

    During the HKCERT CTF finals, the organizers introduced unexpected infrastructure changes on the competition day that rendered many of the team's automated scripts useless. Jose explains that they had to adapt very quickly by dividing tasks dynamically and utilizing anyone experiencing downtime to improve their tooling.

  • Adapting to technological shifts (LLMs)

    Kelvin and Jose highlight how the emergence of agentic Large Language Models (LLMs) in early 2025 forced the team to pivot. Because LLMs (like Anthropic's Claude Opus 4.6) can now "one-shot" medium or hard challenges, they had to adapt their strategies by integrating LLMs into their workflows for AI assistance and shifting their training focus to highly advanced, niche vulnerabilities that AI cannot easily solve.

  • Adjusting to new competition formats

    Leo and Lawrence mention having to adapt to the "Attack and Defense" format, which required them to transition from standard algorithmic contests (relying on memorized patterns) to thinking on their feet under intense, live pressure to simultaneously attack opponents and patch their own systems.

Project Management and Teamwork
  • Task delegation and morale management

    Jose notes that serving as team president greatly improved his leadership and teamwork skills. He learned how to keep team morale high during long, grueling competitions, motivate members when they hit a wall, and delegate tasks based on individual strengths.

  • Coordinating under pressure

    Lawrence describes fast-paced CTF events (like HKCERT CTF) where team members had to maintain absolute focus for hours, switch tasks rapidly, and support one another whenever someone got stuck.

  • Optimizing physical resources

    Kelvin and Jose highlight the importance of PolyU providing them access to the Information Security Lab (CD514) as their dedicated base. Utilizing this physical space allowed the team to train and participate in online CTFs face-to-face, which made their collaboration and communication smoother and more instantaneous than working online.

Continuous Improvement and Learning from Mistakes
  • Post-competition analysis

    Kelvin demonstrates a strong commitment to learning from failure. He explains that when he fails to solve web exploitation challenges during a competition, he immediately reaches out to others afterward, reads the official challenge solutions, and attempts to solve the challenge again to gradually amass new techniques and understand application weaknesses.

  • Iterative skill development

    Lawrence shares how his coach and senior teammates reviewed their ideas, helping them improve step-by-step rather than leaving them to figure everything out on their own, allowing them to advance their technical skills and competition strategies continuously.

Communication and Presentation Skills
  • Collaborative communication

    Kelvin specifically notes that his soft skills improved upon joining the team because their coach, Mr. Hopkins Kong, taught them how to collaborate better and enhance their communication skills, particularly when assigning specific tasks to teammates under time pressure.

  • Organizing events and community outreach

    Leo points out that organizing public events (such as hosting the PolyU Open CTF to give back to the cybersecurity community) and working through competitions as a unit significantly sharpened his communication and leadership abilities in ways he did not originally anticipate.

Research and Information Literacy
  • Deep-dive technical investigation

    Jose shares an experience during the HKCERT 2025 qualifier where a challenge involved an unfamiliar industrial communication protocol. To solve it, he went down a "deep research rabbit hole," dedicating hours to analyzing how the protocol worked before successfully figuring out how to exploit it.

  • Self-study and external platforms

    To prepare for the unfamiliar defense operations, Lawrence spent extra time training on external platforms like Hack The Box to practice the attack-defense workflow, while Leo engaged in self-study and online labs to build his defensive/blue team knowledge.

  • Learning from senior guides and mentors

    Leo, Lawrence, and Jose explain that they frequently sought advice from their coach, Mr. Hopkins Kong, and senior teammates, who shared technical knowledge, guided their research into new cybersecurity topics, and walked them through defensive thinking.

 


Inspiring Quotes:



Explore More:

The pursuit of knowledge is a lifelong journey! To further expand your knowledge and continue your personal and professional growth. Click and explore the following learning resources:

Domain Knowledge OER

Attack-and-Defense Security Architecture

Automated Exploit Engineering

Threat Monitoring

Protocol Analysis

Agentic AI

Lifelong Learning OER

Adaptability and Flexibility

Project Management and Teamwork

Research and Information Literacy

Continuous Improvement and Learning from Mistakes

Communication and Presentation Skills