athena-proxy
Cross-platform CLI that gives every Athena CTF challenge instance a plain TCP address on localhost, so netcat, pwntools, and any socket tool reach it without speaking TLS.

Project Details
Client
AstraQ Cyber Defence
Year
2026
Role
Developer
Status
Open source
Ownership
Sole author
Technologies
The Challenge
Athena routes every challenge instance by TLS server name at a shared gateway on port 443. That keeps instances private per team, but most exploitation tooling expects a raw TCP socket.
The Solution
Built a Go daemon that serves one loopback listener per registered hostname. Each connection opens exactly one TLS connection to the gateway with SNI set to that hostname and pumps bytes both ways. Targets can be added and removed while the daemon is running, through a loopback control port. Signed release archives with build provenance attestations cover Linux, macOS, and Windows on x86-64 and ARM64, with one-line installers.
Highlights
- One TLS connection per local connection, with no pooling or multiplexing
- Daemon accepts new targets live, without a restart
- Versioned releases with SHA-256 checksums and GitHub build attestations