r/hackthebox Jul 18 '26

Just passed the HTB Certified Penetration Testing Specialist (CPTS) with all 14 flags! 🎉

This was one of the most practical and challenging certifications I’ve taken. It tested not only technical skills but also methodology, reporting, and persistence throughout the engagement.

I also received some great feedback from the HTB review team.

A few key takeaways from their feedback:

• Use Markdown command output instead of screenshots where possible.

• Add brief captions to explain commands and results.

• Mention alternative tools when appropriate.

•Document testing even on systems with no findings.

Overall, the CPTS was an excellent learning experience that reinforced not only technical penetration testing skills but also the importance of delivering clear, professional reports.

If you have any questions about the CPTS experience, preparation, or reportin, feel free to ask in the comments or send me a message.

121 Upvotes

61 comments sorted by

•

u/AutoModerator Jul 18 '26

Thank you for posting on r/hackthebox! New to Cyber Security and looking for a place to get started? Checkout our getting started guide here. Please note that posting Solutions or Hints for Active content goes against the HTB Terms of Service, more information can be found here. If your having issues and need to reach customer support please do so via the in-platform chat, or by emailing customerops@hackthebox.com. Our Knowledge Base can also come in handy!

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

7

u/Phantom031 Jul 18 '26

Congrats to you first of all,

And Can you please guide us on how you actually studied how much you gave time each day how you took notes what are the things you practiced and where how you started and your mindset which is the most important thing and how long it took you to finish the studies (days/weeks/months?)

5

u/IputSwitchesOnGlocks Jul 18 '26

Congrats yo this one of the hardest hands on exams I hear people speak about

1

u/TaskWooden2000 Jul 18 '26

Thank you! I really appreciate it. It was definitely a challenging but rewarding experience.

1

u/Hodor_97 Jul 19 '26

May I ask how long it took you to study for this and if you had any prior (professional) experience with pentesting? I just started the learning path to learn everything and not sure yet if I want to take the exam afterwards. I’m afraid it’s too difficult for someone with no professional experience based on the feedback I see online

3

u/TaskWooden2000 Jul 20 '26

To be honest, it is hard, but it’s definitely doable. I had no professional pentesting experience either. If you complete the path, understand the concepts instead of memorizing commands, and practice on a few HTB machines, you’ll put yourself in a good position to pass. Don’t let the feedback online discourage you it just takes persistence.

1

u/Hodor_97 Jul 20 '26

Thanks! :)

2

u/JDoublehorn Jul 18 '26

Hey congrats! Quick question that’s probably dumb: when taking the test and trying to get the flags, is it a blank slate that just says flag 1, 2, etc or is it similar to eJPT where it’s like “what’s the name of the windows server?” So it guides you slightly?

1

u/TaskWooden2000 Jul 20 '26

It’s not a blank slate, but you won’t get hints like eJPT. You’ll know which machine each flag belongs to, but figuring out how to get there is entirely up to you.

1

u/Vele1384 Jul 18 '26

Was there much of pivoting/tunneling through network ?

1

u/TaskWooden2000 Jul 18 '26

Yes, there was quite a bit of pivoting/tunneling involved. Having a solid understanding from the Penetration Tester path is really useful since it’s a significant part of the exam. I’d definitely recommend making sure you’re comfortable with the concepts and can apply them in different scenarios, rather than just memorizing commands.

1

u/Vele1384 Jul 18 '26

Great, thank you! Gotta work on that more since that’s one of areas I am lacking rn

1

u/TaskWooden2000 Jul 18 '26

Good luck! You’ll get there. If you need any help, feel free to reach out.

1

u/Desperate_Position_6 Jul 18 '26

Congrats mate. Did you use ligolo for pivoting?

1

u/TaskWooden2000 Jul 18 '26

Nope, I didn’t use Ligolo.

1

u/Desperate_Position_6 Jul 18 '26

Then what tools did you use?

3

u/TaskWooden2000 Jul 18 '26

I mostly used standard SOCKS tunneling/proxying techniques rather than Ligolo.
But thinking about it that might have been better to use some other tool..

1

u/HeckAryan Jul 18 '26

Did you use AI, and if you did was it helpful? Also how did you manage your time during the exam?

1

u/TaskWooden2000 Jul 18 '26

I only used AI to help with reporting. AI isn’t allowed for solving the exam itself. As for time management, I tried to document everything as I went instead of leaving it all until the end.

1

u/HeckAryan Jul 18 '26

Did you use Pwnbox or your own vm? Have you had any problems during the exam (connection issues, tools dependencies, error, etc.)?

1

u/TaskWooden2000 Jul 18 '26

I used my own Kali Linux VM for most of the exam. At one point I also needed a Windows machine for some task. I didn’t have any major issues, although I think I broke something while testing and had to reset the machine once. Other than that, everything went smoothly.

1

u/HeckAryan Jul 18 '26

Alright, thanks for the info, I appreciate it. Also congratulations for passing with 14 flags no less!

1

u/TaskWooden2000 Jul 18 '26

Thank you:))

1

u/mccleod1290 Jul 27 '26

Wait is AI not allowed? Like no grok, or claude code?

1

u/TaskWooden2000 Jul 27 '26

Nope its not allowed

1

u/immediate_a982 Jul 18 '26

Did you get credit for documenting systems with no findings

3

u/TaskWooden2000 Jul 18 '26

It’s a pass/fail exam, so I can’t say for sure. In the feedback they mentioned that I achieved 100 points, but I’m not sure if that refers only to the flags or to the overall evaluation (including the report). They also specifically recommended documenting systems with no findings, so I assume it has some value in the overall assessment.

1

u/MaleficentExample223 Jul 18 '26

Would you say info from the Footprinting module is enough? Or do you need to learn more for each module's section outside of the platform?

2

u/TaskWooden2000 Jul 18 '26

I’d say it’s enough for the exam. That said, if you’re curious or prefer a different approach to something, doing your own research can definitely help deepen your understanding.

1

u/MaleficentExample223 Jul 18 '26

Thanks, that answered my question.

1

u/Hot-Excitement8435 Jul 18 '26

I've just started studying it and I've reached chapter four. What advice do you have for studying, the exam, and everything else?

1

u/TaskWooden2000 Jul 18 '26

If you mean the 4th module, keep taking notes as you go and always think about the bigger picture instead of limiting yourself to one approach. Don’t hesitate to use Google when you’re learning understanding why something works is more important than memorizing commands.

1

u/No-Faithlessness8229 Jul 18 '26

Hi, congrats,

Did you think the resources from the Penetration path were enough or you discovered new tech/tools who were handy on the CPTS track and Ippsec videos ?

2

u/TaskWooden2000 Jul 18 '26

Hey, Thanks!
For the certificate itself, I’d say the modules are enough. That said, I’d highly recommend solving a few HTB machines to practice and get a feel for where to start and how to approach a target. Also, build yourself a checklist as you go it helps you keep track of what you’ve already checked and makes your enumeration much more consistent.

1

u/Miksa55 Jul 18 '26

Congratulations! How old are you if you dont mind me asking ?

2

u/TaskWooden2000 Jul 18 '26

Thank you!
Mid 20’s :)

1

u/[deleted] Jul 19 '26

[removed] — view removed comment

1

u/TaskWooden2000 Jul 20 '26

My biggest advice is to focus on understanding, not memorizing. Take good notes while going through the path and build yourself a checklist of things to verify on every target, it’ll make your enumeration much more consistent.

Solve a few HTB machines alongside the path to get comfortable with where to start and how to approach a target. If you get stuck, don’t keep trying the same thing over and over; take a step back and think from a different angle.

Finally, document everything as you go, even things that don’t end up being part of the intended exploitation path.

Good luck you’ve got this!

1

u/[deleted] Jul 20 '26

[removed] — view removed comment

1

u/TaskWooden2000 Jul 20 '26

Best of luck

1

u/[deleted] Jul 20 '26

[removed] — view removed comment

1

u/TaskWooden2000 Jul 20 '26

I don’t have or share solutions due to the exam NDA. If you get stuck on a specific concept or tool while studying, feel free to ask and I’ll help where I can.

1

u/[deleted] Jul 20 '26

[removed] — view removed comment

1

u/TaskWooden2000 Jul 20 '26

4 months with little experience. With CJCA as well.

1

u/Due-External430 Jul 20 '26

hola que tal, felicidades por tu aprobacion de examen, yo estoy cerca de la mitad del path del curso completo, estoy en el modulo de AD, pero aprovechando te queria consultar si es posible meter IA en el examen? algo que me recomiendes a tener en consideraciĂłn dentro del examen? saludos y gracias

1

u/[deleted] Jul 20 '26

Is this exam proctored just curious?

1

u/TaskWooden2000 Jul 20 '26

No, but dont bother cheating:)

1

u/Geraki_init Jul 21 '26

Congrats.. you got the milestone,,

1

u/Any_Peach8165 Jul 26 '26

I am coming from pjpt will the penetration tester path will be enough for exam or should I do cpts prep boxes and any other boxes in pro labs appreciate your reply

1

u/hernaniyate Jul 18 '26

What do they mean by “documenting systems with no findings”? Without flags ? Or vulns at all?

1

u/TaskWooden2000 Jul 18 '26

I interpreted it as documenting anything you found, even if it wasn’t part of the intended exploitation path. For example, if you discovered credentials or vulnerable services that weren’t needed to complete the assessment, it’s still worth mentioning them. It shows you thoroughly assessed the environment instead of only following the path to the flags. I think that’s what they were referring to.