In this guide, you'll find a step-by-step walkthrough on how to opt in as a UGC author, submit a new User-Generated Content (UGC) lab in the OffSec Portal, and view the status of your submission.
You’ll learn:
- How do I opt in and access the UGC submission page?
- What will I see on the UGC page?
- Tiers and limits
- The UGC Wishlist
- How do I submit a new UGC machine (field-by-field)?
- How can I view my submission and its status?
- What should I do after submitting?
- Need faster support?
How do I access the UGC submission page?
- Log in to your OffSec Portal with your account credentials.
- In the upper-left corner of the screen, click the three horizontal lines (menu icon).
- A left-hand navigation menu will open.
- Scroll down to the Resources section.
- Click on UGC.
The first time you reach the UGC section, you'll be asked to opt in as a UGC author. This applies to all authors, new and returning. You'll be asked for:
- How did you hear about this opportunity?
- Discord name
- Discord ID
This is a one-time step , once you've opted in, you won't see this prompt again on future visits.
If you're a returning author, opting in doesn't reset anything: your full submission history still shows under the Lab Creator Dashboard afterward.
Once you've opted in, you'll land on the UGC page, where you can create and track your UGC machine submissions.
What will I see on the UGC page?
On the UGC page, you'll see a dashboard-style view built around:
Lab Creator Dashboard
This is where you can see all your submissions and their current state:
- Drafts
- In Review
- Changes Requested
- Rejected
- Approved
UGC Wishlist
UGC Wishlist: labs to prioritize this quarter
See The UGC Wishlist section below for the full guide on browsing, claiming, and submitting against wishlist items.
Labs Published
Shows how many of your labs are live in our portal.
Learner Reach
Shows the feedback and future rating of your machines.
Tiers and Limits
Your weekly/concurrent submission limit depends on your Creator tier: Learn more about Tiers and limits
| Tier | Submission Limit |
|---|---|
| New Author (No approved labs yet) | 3 submissions per week |
| Tier 1 | Up to 6 concurrent submissions |
| Tier 2 | Up to 10 concurrent submissions |
| Tier 3 | Unlimited submissions. Also unlocks the private wishlist. |
|
Important Your tier is based on the highest tier you have achieved on a monthly basis across your account history. It does not show the tier you are currently on. Keep this in mind when planning how many labs you can have in flight at once. | |
The UGC Wishlist
Vectors we're actively looking for, ordered by priority. Click a row for the full brief and reference notes. The wishlist is a creative starting point , pick any item that sparks an idea and shape it into a lab.
How to read the wishlist
A contributor reference guide, not a rulebook.
Treat every casefile as a creative starting point. The wishlist points at what we want to cover, but the exact details of the lab is up to you as the author.
What you can adjust
- For Grimoires:
- Investigation question wording, ordering and count.
- Point allocations across questions, as long as the total stays reasonable for the difficulty.
- Artifact sets: swap, add or trim files so the investigation flows.
- Per-proof and overall difficulty ratings.
- Scenario details, characters, hostnames, IPs and the surrounding contexts.
Claiming and duplicates
- First come, first served. One accepted submission per wishlist item.
- If two concepts are submitted in close succession , the reviewer may flag the later one as a duplicate if the initial one is accepted - this process will happen at the reviewer’s discretion. There is no automatic lockout while you draft.
Who can see what
- Most wishlist topics are open to all authors.
- Rows marked "Trusted creator only" are reserved for Trusted Creators. Trusted Creator status is granted to authors with 20 or more approved labs, or assigned manually by OffSec.
Quality reminders for Grimoires
- Keep timestamps internally consistent across logs and artifacts.
- Use neutral, in-world filenames. Avoid giveaways like flag.txt or solution.pdf.
- Add enough realistic noise that the answer is found, not handed over.
- Verify proofs and walkthrough on a clean redeploy before submitting.
Questions on a specific casefile? Reach out for clarity in the creator channel before you go deep on the build.
Claiming, working on, and releasing a wishlist item
1. From the UGC Wishlist list, review the Topic, Description, Difficulty, and Bounty for each row, then click Claim on the item you want.
2. A confirmation dialog explains how claiming works before you commit:
- Your claim starts the countdown immediately.
- When you claim a topic, you're reserving it to start work within a limited time.
- If you don't submit in time, the topic may reopen for others to claim it.
- If you need more time, you may be able to request an extension.
- If a topic reopens, you may need to wait before claiming it again.
3. Once claimed, the item is added to your labs as a draft tagged "WISHLIST TOPIC," and shows a countdown until it reopens.
4. If you no longer want to pursue the topic, click Release Claim and confirm. This makes the item available for other authors to claim again.
Note: your draft is kept after releasing , you can continue working on it, but it's no longer reserved to you, and another author may claim and submit the same topic in the meantime.
5. When you submit a lab built from a claimed wishlist item, it's submitted the same way as any other UGC machine (see the next section) , just make sure your claim is still active first. If your claim has lapsed or been released, submission will be blocked until you are able to reclaim the item.
Sample submission package
When you're ready to start creating, please familiarise yourself with the submission format and quality OffSec is expecting. A Download Sample Package button is available on the submission page - use it to download a complete example package (walkthrough, build scripts, data, and build guide) for the lab type you've selected.
How do I submit a new UGC machine?
- From the UGC page, click Submit your lab (or start a new draft from the Lab Creator Dashboard).
- You will see a submission form with required and optional fields. Complete the form as described below.
Required & key fields
-
Lab Type*
Choose the type of lab you are submitting (for example: VM or Grimoire) -
Kind of Lab*
Select the format that best fits your lab (for example: Single or Chain). This determines the lab's structure and is required. -
Submission Type*
For example: Attack or Defend.
This policy has already been announced and shared with UGC authors. As of this update, we are only accepting:
- Chained-host Offensive VM Labs
- Grimoire Labs
- All Defensive VM Labs
- CVE Labs - Defensive Only
AI-Resistant (AI-R) requirements are now incorporated into the submission guidelines. Single-host offensive VM labs are not currently being accepted , plan your Kind of Lab / Submission Type selection accordingly.AI-Resistant (AI-R) requirements are now incorporated into the submission guidelines - except for CVE labs. Single-host offensive VM labs are not currently being accepted , plan your Kind of Lab / Submission Type selection accordingly.
-
Lab Type*
Enter a clear, descriptive name for your lab.- This is how learners and internal teams will refer to your machine.
- Avoid overly generic names; choose something that reflects the theme, technology, or scenario.
- Is this a CVE-based lab?* Yes/No.
If you select Yes, you'll be asked to enter the CVE ID. The system checks this against our database and lets you know if that CVE has already been submitted, so you don't accidentally submit a duplicate.
Uploading your submission archive
At the bottom of the form, you will be asked to upload your lab package:
-
Upload Submission Archive*
- Upload your complete lab archive in a compressed format.
- Recommended: ZIP.
- Accepted formats typically include: .zip, .7z, .tar.gz, .rar, .tar (up to 10GB).
- Once you select a file, the upload will usually start automatically.
Make sure your archive includes the following five files:
- autopwn
- build guide
- walkthrough
- artifacts
- README
Need a starting point? Use the Download Sample Package button on the submission page for a complete example package.
Note: Payment will be processed after your submission is reviewed and approved.
Accepting the Terms and Conditions
Before you can submit:
- You must confirm: “I have read and agree to the Terms and Conditions.”
Make sure you review any linked terms or policies so you understand the submission, review, and payment process.
Once all required fields are completed, your archive is uploaded, and the Terms and Conditions checkbox is selected:
- Review your information for accuracy and completeness.
- Click Submit at the bottom of the form.
Your machine will then be sent to the UGC team for review.
How can I view my submission and its status?
After you submit your machine, you can track its progress in the portal:
- Open the Lab Creator Dashboard from the UGC page (Resources → UGC, if you're not already there).
- You will see a list of all your UGC submissions, including:
- Machine / lab name
- Date of submission
- Current status
Status descriptions:
- Approved , Your submission has passed review and has been accepted. Payment processing and release will follow according to the program's timelines.
- Rejected , Your submission did not meet the requirements or review criteria and will not move forward in its current form. Where possible, you may receive notes or feedback to help you understand why, which you can use to improve future submissions. Please do not resubmit the same concept.
-
Changes Requested (previously "Blocked") , Your submission needs updates before it can proceed.
- This usually means the review team has identified issues that must be addressed for example:
- missing files
- policy conflicts
- unclear scenarios
- technical problems
- or incomplete content.
- You should review the feedback from the team, update your lab accordingly, and resubmit.
- Once you resubmit with the requested changes, the review process can continue but is not guaranteed to culminate in an approval.
- This usually means the review team has identified issues that must be addressed for example:
What should I do after submitting?
-
Monitor your status:
Check the Lab Creator Dashboard periodically to see when your machine moves to Approved, Rejected, or Changes Requested. -
For Approved submissions:
No further action is typically required from you unless the team requests clarifications. Payment and release will follow the normal process. -
For Rejected submissions:
Use any feedback you received to refine your ideas and improve future labs. You can always submit new concepts that better align with the requirements. Please do not resubmit the same rejected concept. - For Changes Requested submissions: Carefully read the review team's feedback, make the required changes to your archive or lab details, and resubmit so the review can continue.
- Submitting against the Wishlist: If your lab matches a UGC Wishlist item, it gets priority review (within 3 days), and approved labs earn a 25% rate uplift.
-
Clarify if needed:
If anything about your status or feedback is unclear, reach out to OffSec Support or the designated UGC contact channel (such as Discord or email) for clarification.
Need faster support?
When submitting a support ticket, please include your Discord name and ID. This allows our team to reach out to you directly in Discord for instant assistance.
Since Discord name and ID are now collected during author opt-in, this information is already on file for opted-in authors , but including it in your ticket still helps our support team route things quickly.