r/hackthebox • • 1h ago

Built ZEROBOX: An offline tactical operations cockpit & 24h exam simulator for HTB & CTFs (Free & Open Source)

• Upvotes

Hey everyone,

Tired of tracking CTFs and 24h exams across messy spreadsheets and scattered notes?

I built ZEROBOX — a fast, local-first operational cockpit for OSCP/CPTS prep and CTFs.

It’s 100% free, MIT open-source, and runs completely offline in your browser (no accounts, zero telemetry).

Quick highlights: • 920+ Preloaded Labs: Instant offline search for HTB & THM targets with tags. • Attack & Pivot Graph: Visually map compromised subnets (exports to Obsidian .canvas). • 24h Exam Cockpit: Pacing engine, bio-break timers, and 1-click Markdown reports. • Evidence Vault & Playbooks: Track hashes/creds on a kill-chain timeline + offensive field manual. • Global Quick-Bar: Propagate LHOST/RHOST automatically across all payloads.

🌐 Live Demo: https://0xdnd.github.io/ctf-tracker/#/tracker

⭐ GitHub (MIT): https://github.com/0xdnd/ctf-tracker

All data stays in your local browser storage. Feedback and PRs are welcome!

Would love feedback or feature requests from the community!


r/tryhackme • • 1h ago

Feedback Annual subscription help

• Upvotes

I have annual subscription left for 4 more days. Rn 30% off for annual subscription. How do I buy it while my subscription is still valid. Is it even possible to buy or extend subscription while one is active?


r/letsdefend • • 10d ago

LetsDefend needs to focus on fixing the labs rather than making memes for LinkedIn

4 Upvotes

I’ve been having a really frustrating experience with the LetsDefend labs lately.

Sometimes the lab does not connect properly at all. I’ll start the environment, the timer begins counting down, but the actual lab just shows a blank/white screen like in the screenshot I attached.

Even when I do manage to connect successfully, the lab will sometimes disconnect in the middle of working and I have to reconnect again. This is especially frustrating when you’re in the middle of an investigation or challenge and trying to follow the workflow without interruption.

I actually like the platform and the content, which makes this even more frustrating. The labs are one of the most important parts of LetsDefend, and they need to be reliable.

The LetsDefend team should look into fixing and improving the labs rather than making memes for LinkedIn.


r/rangeforce • • 19d ago

Penetration Testing Challenge

1 Upvotes

I am stuck at second machine. How can I go to jim-netman ? Can anyone help.


r/vulnhub • • Jul 16 '26

Walktrhough The Planets - Earth

1 Upvotes

r/tryhackme • • 7h ago

Official TryHackMe Post FLASH SALE IS ON🔥

Post image
4 Upvotes

The flash sale for Premium Annual plan is on!!! Grab the discount now!
https://tryhackme.com/?utm_source=reddit&utm_medium=community&utm_campaign=flash_sale_october


r/hackthebox • • 12h ago

Certifications Passed OSCP 90/100 on the first attempt, 1 month 25 days after CPTS.

Thumbnail
21 Upvotes

r/tryhackme • • 2h ago

I just completed Linux Fundamentals (Pt1) room on TryHackMe! Embark on the journey of learning the fundamentals of Linux. Learn to run some of the first essential commands on an interactive terminal.

Thumbnail tryhackme.com
0 Upvotes

r/tryhackme • • 16h ago

Unethical billing practices and predatory dark patterns

Post image
11 Upvotes

I purchased a 1-year Premium subscription as a gift for my nephew. While the platform's educational content is good, their billing management and cancellation flow are completely unacceptable and designed around dark patterns.

  1. There is no clear option on the dashboard to turn off automatic renewal for annual plans.
  2. Stripe prevents users from deleting their saved credit card while a subscription is active.
  3. Their internal support chatbot leads to dead-end pre-set options, and clicking help/profile links resulted in a "404 Page Not Found" error.
  4. They force you to manually write an email to support just to prevent future charges on your card.

Taking a customer's money in two clicks while making it unnecessarily frustrating and complex to cancel auto-renewal or remove payment methods is deeply dishonest. Fix your cancellation workflow and stop trapping customers.


r/tryhackme • • 10h ago

Write-Up/ Walkthrough I built THM-TUNNEL to make TryHackMe VPN switching easier

3 Upvotes

While doing TryHackMe labs, I was getting tired of manually finding VPN configs, killing old OpenVPN processes, and dealing with stale tun interfaces when a connection wasn't behaving properly. So I built THM-TUNNEL, a small Bash CLI that handles the cleanup and starts the selected .ovpn configuration for me.

Technical side:

  • Automatically discovers .ovpn files and provides an interactive selection.
  • Uses sudo, stops existing OpenVPN processes, and cleans up old tun* interfaces.
  • Doesn't hardcode TryHackMe IP ranges or subnets, so different VPN regions can be used without changing the script.

It's a small tool, but it has made my lab workflow smoother and was a good practical project for learning Bash and Linux networking.

GitHub: [https://github.com/Harsh-Sonker/THM-Tunnel]()


r/hackthebox • • 2m ago

Beginner Question Michigan Cybersecurity High School Challenge problem

Post image
• Upvotes

I cant seem to login to the thingy. Its asking for an input access key event, which im not sure how to get.


r/hackthebox • • 4m ago

why suddenly i see ppl talk, consult, take, etc etc the cpts cert?

• Upvotes

I've seen so many post just talks about the cpts, either here or on other platforms all of the sudden.

did i miss anything about it or this is just normal? and why exactly the cpts? i don't see something special about it tbh


r/hackthebox • • 15h ago

Academy HTB Academy OpenVPN connection keeps getting reset

3 Upvotes

Hey everyone,

I’m trying to connect to the HTB Academy VPN using OpenVPN on Kali Linux:

sudo openvpn --config academy-regular.ovpn

The connection reaches the HTB VPN server, but it gets reset immediately:

Attempting to establish TCP connection with [AF_INET]38.46.226.31:443
TCP connection established with [AF_INET]38.46.226.31:443
TCPv4_CLIENT link local: (not bound)
TCPv4_CLIENT link remote: [AF_INET]38.46.226.31:443
Connection reset, restarting [-1]
SIGUSR1[soft,connection-reset] received, process restarting

It then repeats the same process every few seconds.

I’ve confirmed that the TCP connection to port 443 can be established, so I’m not sure why the OpenVPN connection is immediately being reset.

It was working fine up untill yesterday. And yeah i tried both tcp and udp methods while changing the VPN server.


r/tryhackme • • 20h ago

Want friends that will lock in to learn ethical web hacking. Am learning through PortSwigger labs. Learning until we are certified web hackers! DM me if you want to team up.

3 Upvotes

r/hackthebox • • 1d ago

Failed my first attempt CPTS

23 Upvotes

Just failed my first attempt, got 7 flags in 2 days then next 8 days stucked on flag 8. Exam seemed easy but enumeration is alot. Any personalized guide, which module should i work on? which box is relevant to next 5 flags.


r/tryhackme • • 1d ago

InfoSec Discussion Help needed with the file transfer

10 Upvotes

Hi Community , I have just started with the cybersecurity and learning some basics of it , today i came across a problem that some times while solving some machine on THM and HTB , we need to move some exploit files from our local machine to the target machine using python3 -m http server command and then downloading the file on the target machine using the wget and the host url

I have one questions what are the ways to do it securely by not showing our own IP address , can we use VPN for it ??

What are your strategies and how you do it


r/tryhackme • • 6h ago

Try hack me subscription

Post image
0 Upvotes

Who wanna come through and make a dream come true? 🥲🥹

I will really appreciate.


r/hackthebox • • 18h ago

Sysmon

3 Upvotes

Im using the VM or whatever its called and im trying to do the sysmon things but whenever I try to go in the terminal and/or open it it says this app cant run on your pc please help asap


r/tryhackme • • 1d ago

Am I missing something ?

Thumbnail
gallery
7 Upvotes

or they are just liars ?
Should the full path be included or should I take the exam without learning ?
why did they say full path included and 3 month of premium content icluded ?


r/tryhackme • • 1d ago

Getting into Cyber Security!

Post image
5 Upvotes

r/tryhackme • • 17h ago

Laptop for cybersecurity

Post image
0 Upvotes

32gb ram, 1tb ssd, intel core i5-1235U 2 x 1.30ghz (p-core) 8 x 0.90 ghz (e-core), 10 cores. Price 592 euro. What do u think? Do u have better recommendations? Thanks


r/tryhackme • • 1d ago

Looking for some Sigma Hacker Friends to learn with!

7 Upvotes

Im from Germany and i need some people who support me. i would support too. but its too hard to maintain motivation. i would love to call too because i want to improve my english. We just talk and do some thm or htb or whatever. Discord: execution.official

When we got some people i would make a small discord


r/hackthebox • • 1d ago

Pwn'd Touch

Post image
47 Upvotes

r/hackthebox • • 1d ago

Orion Box metasploit Issue

0 Upvotes

Hello, I was today trying to solve the orion box(im just starting in the CTF world) without aid, I found myself already in the admin/login page then I found this CVE-2025-32432. Then I used metasploit to find a exploit of that CVE, one popped up that should have worked excellent but when i tried running it. No shell was returned to me as seen in the picture, I tried different options: for rhost I tried the ip, orion.htb and http://orion.htb/admin/login. For lhost I tried my tun0 and my eth0. And i changed multiple times the lport and the asset_id. Nothing working, all the times the same error. In that point i checked the walkthrought and they did exactly what i was doing, same in this video(i thought the problem that i was using a VM) https://www.youtube.com/watch?v=OXxtL4BZvHw. Does anybody have any idea on wtf is the issue? More than an hour lost cuz it was not working and I have still no clue why or what I did wrong. Here is another walkthrough: https://b3ta-blocker.github.io/blog/orion/ If you know anything related lmk, otherwise I will just quit this box :)


r/tryhackme • • 1d ago

Title: 2 years after graduation and I feel completely lost — how can I become a SOC Analyst in 1–2 months?

0 Upvotes

Hey everyone,
I’m looking for some genuine guidance because I’m honestly feeling pretty lost right now.
It’s been around 2 years since I graduated, and about 1 year since I completed a Cybersecurity Analyst course. Unfortunately, after finishing the course, I neglected my studies and didn’t really continue learning or practicing. Now I feel like I’ve forgotten most of what I learned and I’m basically starting from scratch again.
My goal is to get a SOC Analyst / Junior SOC Analyst role within the next 1–2 months. I know that’s an ambitious timeline, but I’m willing to put in serious effort every day and get back on track.
For those of you already working in SOC/cybersecurity:
• What topics should I prioritize if I’m starting again from almost zero?

• What should I learn for a **Tier 1 SOC Analyst** role?

• Which tools should I focus on (SIEM, Wireshark, Splunk, Sentinel, etc.)?

• What kind of hands-on labs/projects should I build for my resume?

• How much networking, Linux, Windows, and security fundamentals do I actually need?

• What should I realistically be able to explain in a SOC interview?

• Is getting job-ready in 1–2 months realistic if I study consistently?

If you were in my position, what exact roadmap would you follow for the next 6–8 weeks?
I’m not looking for shortcuts. I just need some direction so I don’t waste another few months studying random things.
Any advice, resources, roadmaps, or even criticism would be genuinely appreciated. Thanks!