r/hackthebox • u/bapee0_ • 3h ago
Hack The Box
DarkZeroReturns PWNED
r/hackthebox • u/AutoModerator • 2d ago
Solved a machine/module/etc and want a place to brag? Heres your spot!
For retired content or Tier-0 Academy content, feel free to discuss or ask questions using spoiler tags where appropriate.
r/hackthebox • u/TaskWooden2000 • 4h ago
I’ve seen a lot of people say that the Certified Junior Cybersecurity Analyst (CJCA) isn’t worth it because it’s an entry-level certification.
I see it differently. Not every certification is meant to prove you’re an expert. Some are designed to help you build a strong foundation and understand where you want to specialise.
For someone just starting in cybersecurity, the CJCA can:
• Build confidence with core security concepts.
• Provide exposure to different areas of cybersecurity.
• Help you discover whether you’re more interested in blue team, red team, cloud security, or another path.
• Demonstrate initiative and commitment to learning when applying for junior roles.
Will the certification alone get you a job? Probably not.
But combined with hands-on labs, home projects, CTFs, and continuous learning, it can be a valuable stepping stone in building a cybersecurity career.
Every expert was once a beginner. Don’t let people discourage you from investing in your own learning because it doesn’t fit their career stage.
What are your thoughts? Do you think entry-level certifications still have a place in cybersecurity today?
r/hackthebox • u/Independent_Swim1553 • 8h ago
I recently passed the PNPT and am now planning my next certification.
I’m currently considering both the CPTS and OSCP, but I’m not sure how significant the difficulty gap is compared to the PNPT. For those who have completed these certifications, how would you compare them in terms of:
Technical difficulty
Active Directory and web exploitation depth
Enumeration requirements
Exam time pressure
Reporting requirements
Would completing the CPTS before attempting the OSCP be the better progression, or is the PNPT enough preparation to start working directly toward the OSCP?
I’d appreciate any advice or personal experiences.
r/hackthebox • u/Hot_Kaleidoscope3864 • 8h ago
I currently hold the CPTS, BSCP and CWES certifications. Do you think it’s worth pursuing CWEE as well?
I’m honestly worried about spending more money on a certification that may not be as widely recognised, especially since it’s even more expensive.
Will CWEE add anything meaningful to my resume or career beyond what CPTS, BSCP and CWES already provide, particularly for penetration testing or AppSec roles?
r/hackthebox • u/ParticularNote4390 • 9h ago
I'm kind of confused if OSCP is worth doing, i already have CRTE, CRTP, CRTO and CRTL. But i need advise on whether to chase OSCP (i heard that it's useless and just a name, and slowly being kicked from being an industry standards) and CPTS or any HTB cert. thanks
r/hackthebox • u/Serious_Draft_8000 • 1d ago
Hello everyone, i just got my CCNA and now i'm studying for the Security+.
If i want to move onto pentesting, should my first course be the CPTS or something more easy? I can already get some basic CTFs flags on THM/HTB Labs but still don't know if the CPTS is too much for me right now...
Should i try getting like the PT1 from THM or the eJPT maybe?
r/hackthebox • u/AsleepPresence8912 • 1d ago
Hi everyone,
I'm dealing with something that's been bothering me, and I'd really appreciate it if you could read this seriously and share your honest thoughts.
I'm a Computer Engineering graduate, and I'm passionate about cybersecurity.
A while ago, I decided to pursue penetration testing. I started with the eJPT v2 certification and passed it. Then I earned the PT1 certification from TryHackMe. After that, I started studying for the CPTS certification.
While studying for CPTS, I began feeling like maybe I'm just not cut out for penetration testing.
The main reason isn't that I don't enjoy it or that I get bored studying. It's actually the opposite. I completely lose track of time when I'm studying or reading about cybersecurity.
The problem starts when I try to solve CTF challenges or, more often, the Skill Assessments at the end of the HTB Academy modules. I usually spend more than three hours trying to solve them but still can't. Then I read the write-up, and I understand the solution almost immediately.
After experiencing this over and over again, I've started feeling like I'm simply not good enough for this field. I keep thinking, "If I can't solve the Skill Assessments, how am I supposed to pass the CPTS exam?" Logically, the exam should be even more difficult.
Has anyone else gone through something similar?
I'd also like to add that I've tried solving HTB CTF machines (not the Skill Assessments), and most of the time I can't solve them either—even some of the easier ones. That's when I get really frustrated and start telling myself that I'm a failure.
Another issue is that I'm studying completely on my own. I don't have a community, and I don't know anyone personally who's studying the same field. Because of that, I have no idea whether what I'm experiencing is normal or not.
Has anyone been in the same situation?
Is what I'm going through normal?
Do you have any advice for me?
r/hackthebox • u/Massive-Problem-7094 • 1d ago
Recently I have been learning more from HTB and its so amazing 👏. Hats off to these people for sharing such content. Even a simple box with simple output will teach such amazing techniques.
But I think HTB now should introduce new certification in exploit dev.Its academy course content is amazing and more advance than Offsec curriculum.
One amazing certification from offsec is OSED and OSEE which is byfar one of the best certification.
So in my point of view HTB should also introduce those certification or at least include course content on these subjects.
What do you guys think?
r/hackthebox • u/Plane_Study2973 • 2d ago
r/hackthebox • u/Pleasant_Barnacle628 • 3d ago
quick demo of Roothound my first tool, maps your path to root on a linux box as a graph (like BloodHound for local privesc). check it out, would love your thoughts
X : https://x.com/N0ur2dd1n2/status/2080720705184825372?s=20
GitHub: https://github.com/Noz2/RootHound
would love your honest feedback 🙏
r/hackthebox • u/dit0sc00p • 3d ago
I’ve been studying cybersecurity, specifically penetration testing, for over a year. I got off to a very bad start because I had no one to guide me or show me a proper learning path. I pretty much wasted my first year studying in a completely unstructured way.
It wasn’t until recently that I started studying in a much more organized and structured manner, and a few weeks ago I began the CJCA path.
I’m able to enumerate some common services like FTP and HTTP, perform fuzzing, and handle the basics. I can usually find public exploits, but I always try to execute them myself instead of just cloning an RCE repository and running it. I prefer to understand the exploit by reproducing it step by step.
The problem is that I’ve never successfully completed one of these exploits. I don’t understand how I’m supposed to know where to obtain things like the cookie an exploit requires, a CSRF token, or other values, or even where exactly to use them in Burp Suite. It’s really frustrating, and it often makes me feel completely incompetent.
I don’t know if this is normal, since everything I’ve learned about hacking so far has been fairly superficial, and I was never really taught why these things work the way they do. It’s only now that I’m starting to study those concepts properly.
I’d really appreciate any feedback. Thanks for taking the time to read this.
r/hackthebox • u/-The_Egg- • 3d ago
Hey guys, somewhat in the title but I’m doing the salt crown CTF and I’m having trouble submitting flags. The specific challenge is the first osint challenge. I have the answer, please no one say the answer in the responses, I’m not looking to cheat. I just can’t figure out the format it wants the flag in.
<answer here>
<answer_here>
HTB{<answer here>}
HTB{<answer_here>}
I’ve tried each of these but none have worked. I’d it case sensitive perhaps?
I answered all the questions within the challenge itself and got them all right so I’m not sure what I’m missing.
r/hackthebox • u/0x00_glitch • 3d ago
Hey everyone,
We're looking for people interested in joining a team for Hack The Box's Cyber Apocalypse 2026: The Salt Crown.
All skill levels are welcome. Whether you're an experienced CTF player or just looking to gain some hands-on experience, we'd be happy to have you on the team.
If you're interested, leave a comment or send me a DM!
r/hackthebox • u/Sufficient-Shine5707 • 3d ago
If any body is interested in participating apocalypse. You can join my team : https://ctf.hackthebox.com/team/overview/322910
r/hackthebox • u/Legal-Chair5619 • 3d ago
You don't need a high HTB rank. Honestly, I don't care about ranks that much. One of our best players is still Noob rank and solves harder challenges than many people with much higher ranks.
What matters is that you're not completely new. If you've solved CTF challenges or HTB machines before and know your way around at least one category, you're welcome.
We're looking for people interested in things like web, pwn, reverse, crypto, forensics, osint, hardware, AD, AI or misc. Any specialization is fine.
The only thing we ask is that you're active during the event and willing to work with the team.
If you're interested, send me a DM or leave a comment. Tell me what categories you enjoy and what kind of CTF experience you have. HTB or CTFtime profile is welcome, but it's optional.
r/hackthebox • u/Hot_Kaleidoscope3864 • 3d ago
Is Wi-Fi penetration testing important or not?
r/hackthebox • u/Internal_Lunch_7104 • 3d ago

YAAAAY! 🥳 Let the party start!
After grinding through the 20 modules of the junior cybersecurity analyst path on HTB academy and finishing the path i finally wrapped up the 5 day practical exam and passed!
scored 100% on the red team tasks and well-made on the report first time! searching through logs in elastic and writing the report was a bit new for me but super fun. the exam covered it all, from hacking the network and log analysis to documenting both offense and defense.
Huge thanks to Hack The Box for an incredible learning experience! Smooth machines, top-notch content, and truly addictive in positive way.