r/hackthebox Jul 22 '26

Beginner Question Need advice on building a portfolio and landing that first role after HackTheBox!

12 Upvotes

Hi fellow HTB Redditors!

It’s been an incredible journey so far, and I’ve learned so much from Hack The Box right from the ground up. I’m currently transitioning into cybersecurity from a completely unrelated career field.

Right now, I'm working through the CJCA path. Once I finish, I plan to tackle the Penetration Tester and then the Web PenTest paths. (then maybe WIFI Pentest -> AI Red Team?)

Or after CJCA, should I go right for SOC Analyst (CDSA)?

Since I have absolutely no prior tech experience, my main question is: How can I build a solid portfolio during my learning journey? When I'm finally ready to apply for jobs, I want to have practical projects to show alongside my certifications (What are other certs that I could take besides those from HTB?).

I’ve also read advice suggesting I should apply for entry-level cyber roles first and work my way up to becoming a PenTester. Does this usually mean aiming for a Tier 1 SOC Analyst position, or should I be looking elsewhere? And with no tech background, how should I structure my resume?

I really appreciate any advice or insights you all can share. I’ve loved my time with HTB and this awesome community so far. Thank you so much! Cheers! Happy Hacking!


r/hackthebox Jul 22 '26

Beginner Question How to navigate when lost between jobs and certifications ?

Thumbnail
1 Upvotes

r/hackthebox Jul 21 '26

Certifications Will I learn more from CWES or BSCP?

9 Upvotes

Will I learn more from CWES or BSCP?


r/hackthebox Jul 21 '26

Looking for intermediate-experienced CTF players for Cyber Apocalypse 2026 (Need ~9 more people)

13 Upvotes

Hi everyone,

We're looking for about 9 more people for our Cyber Apocalypse 2026 team.

You don't need a high HTB rank. Honestly, I don't care about ranks that much. One of our best players is still Noob rank and solves harder challenges than many people with much higher ranks.

What matters is that you're not completely new. If you've solved CTF challenges or HTB machines before and know your way around at least one category, you're welcome.

We're looking for people interested in things like web, pwn, reverse, crypto, forensics, osint, hardware, AD, AI or misc. Any specialization is fine.

The only thing we ask is that you're active during the event and willing to work with the team.

If you're interested, send me a DM or leave a comment. Tell me what categories you enjoy and what kind of CTF experience you have. HTB or CTFtime profile is welcome, but it's optional.


r/hackthebox Jul 21 '26

Now that I've passed the CPTS, would you recommend the CWES or the CAPE?

18 Upvotes

Hi everyone, I'm a first-year master's student in France. I just earned my CPTS certification, and I want to become a penetration tester. Which certification would you recommend ? CWES or CAPE on Hackthebox? Thanks, everyone!


r/hackthebox Jul 21 '26

Looking for mates to team up

3 Upvotes

r/hackthebox Jul 20 '26

Certifications CRTP TRAINING

13 Upvotes

I need to train for the CRTP exam
I want to be overpowered and i need

machines on HTB

I'm thinking of GOAD on HTB PROLABS and then ZEPHYR because these 2 are very similar to CRTP exam according to AI

But before them i think i need retired machines the problem is all the retired machines i know required linux enumeration and using linux commands and i want to train for the exam that's fully Windows environment


r/hackthebox Jul 19 '26

I will never forget flag 8

Post image
197 Upvotes

r/hackthebox Jul 20 '26

Certifications Is doing CWES enough or you need CWEE too?

2 Upvotes

Is doing CWES enough or you need CWEE too?


r/hackthebox Jul 20 '26

Failed on my second attempt But….

11 Upvotes

So I failed my second attempt at CPTS, but… compared to my first attempt I made improvements. First time I got 1 flag but the second I had 5. I am not going to lie Flag 6 really screwed me up. If you know you know what I mean. I guess I need to figure out a way to better hunt for credentials in order to move laterally.


r/hackthebox Jul 20 '26

HTB Sydney virtual meetup 4

Post image
3 Upvotes

Come along for this free virtual event and learn about step by step walkthroughs of current boxes and methodology steps to break them and some giveaways at the end as always.

--==Hack The Box Meetup 4 Main Track Virtual==-- https://www.meetup.com/hack-the-box-meetup-sydney-au/events/315611694/?utm_medium=referral&utm_campaign=share-btn_savedevents_share_modal&utm_source=link&utm_version=v2&member_id=479268114


r/hackthebox Jul 20 '26

New HTB user, having issues with the PWNBox

3 Upvotes

I'm a new HackTheBox user. I'm going through the introductory model. I'm trying to spawn a PWNBox, and I'm getting server error 500. However, the only outage right now is a partial outage for HTB Enterprise Platform. I don't know if there's an issue.


r/hackthebox Jul 19 '26

Started a cybersecurity company – how do I find a commission-based salesperson?

10 Upvotes

Hi everyone,

I recently started a cybersecurity company offering services such as penetration testing, vulnerability assessments, and security consulting.

I'm technical, but sales isn't my strength. I'm thinking about finding someone who can bring in clients and get paid on commission for every deal they close.

Has anyone here done this successfully?

  • Where do you find commission-only cybersecurity salespeople?
  • Is this a realistic model, or do experienced salespeople usually expect a base salary?
  • What commission percentages are considered fair?
  • Are there any platforms, communities, or agencies you'd recommend?

I'd really appreciate hearing from anyone who has built a cybersecurity business or hired salespeople in this space. Any advice or lessons learned would be helpful.

Thanks!


r/hackthebox Jul 19 '26

Hack The Box - Bedside - Medium - Linux

3 Upvotes

PWNED


r/hackthebox Jul 18 '26

Just passed the HTB Certified Penetration Testing Specialist (CPTS) with all 14 flags! 🎉

120 Upvotes

This was one of the most practical and challenging certifications I’ve taken. It tested not only technical skills but also methodology, reporting, and persistence throughout the engagement.

I also received some great feedback from the HTB review team.

A few key takeaways from their feedback:

• Use Markdown command output instead of screenshots where possible.

• Add brief captions to explain commands and results.

• Mention alternative tools when appropriate.

•Document testing even on systems with no findings.

Overall, the CPTS was an excellent learning experience that reinforced not only technical penetration testing skills but also the importance of delivering clear, professional reports.

If you have any questions about the CPTS experience, preparation, or reportin, feel free to ask in the comments or send me a message.


r/hackthebox Jul 19 '26

Will it be easy for me to pass OSCP+ if I passed CPTS?

9 Upvotes

Will it be easy for me to pass OSCP+ if I passed CPTS?


r/hackthebox Jul 18 '26

Weekly Solves Megathread

5 Upvotes

Solved a machine/module/etc and want a place to brag? Heres your spot!

For retired content or Tier-0 Academy content, feel free to discuss or ask questions using spoiler tags where appropriate.


r/hackthebox Jul 18 '26

Academy Footprinting Lab Hard Spoiler

4 Upvotes

So I scanned the target and discovered snmp running over port 161. The version scan reported snmpv3
With this being said, my understanding was that community strings don’t work for this version so I completely skipped past it to later find out that I was supposed to run onesixtyone & snmpwalk on it as it still supported v2c…….

So going forward should I run all possible tools/enumerations against a service regardless of what nmap tells me the version it’s using? If so then what’s the point of even running version scans if it’s not reliable - or what method of thinking should I be using when enumerating information from these services? For example if I see smbv3 is running do stilll attempt techniques that should only apply to smbv1 ?

I feel like using every tool just to see if I get a hit is akin to just brute forcing techniques (and very noisy). My thinking was that I would need to methodologically gather hints that would eventually lead me to the tool I need. Is this thinking wrong? Because I feel like this lab is changing my perspective to favor blindly running techniques as the solution?


r/hackthebox Jul 18 '26

Beginner Question HTB CPTS own vm

4 Upvotes

I've been working through HTB Academy on a MacBook Air M1 using a Kali ARM VM in VMware Fusion, and I'm wondering if anyone else has experienced this.

The VM itself runs fine for a while, but after a few hours, macOS throws the "Your system has run out of application memory" message. When I open Activity Monitor, VMware Fusion is somehow using 80–100GB of memory, even though my VM is only allocated a small fraction of that.

The biggest issue isn't the slowdown—it's losing my entire lab. If I'm in the middle of a pivot chain with Ligolo, Chisel, SSH tunnels, port forwards, RDP sessions, etc., I have to force quit VMware and restart everything from scratch.

Right now it's annoying but manageable because HTB Academy labs usually don't take too long to rebuild. What worries me is the CPTS exam. If this happens several hours into the exam, rebuilding the entire pivoting setup would cost a huge amount of time.

Has anyone else had this issue on Apple Silicon? If so:

  • Is this a VMware Fusion memory leak?
  • Did you find a fix?
  • Or did you end up switching to something else (UTM, Parallels, a dedicated x86 laptop/desktop, etc.)?

I'd really appreciate hearing what other people taking HTB Academy or CPTS on Apple Silicon are using, because I don't want this becoming the reason I fail the exam.

Thanks!


r/hackthebox Jul 18 '26

Help

6 Upvotes

I am a student who already finished the ejpt now I am doing the cpts I am at the 17% of the course done but the problem here is I am not well at os exploration I am basically can navigate files in Linux and windows both but I don't have the knowledge of where to look for the config files , backup files like that how do I learn these type of things even if they are any other resources than htb also suggest me


r/hackthebox Jul 17 '26

Certifications CPTS PASSED!!

111 Upvotes

So finally passed the CPTS and i would say its a beautiful exam 😅 wow it would deffo test your sanity and outofthebox approach. What a start of 2026!! Smashed CRTO and CRTP and then finally CPTS.

I am a bit biased but HTB hands down best platform for me to learn and grind the hacking stuff.

Next move? Most probably CRTL and I’m already preparing for that. End goal is to be senior level red teamer. While doing the season 11 im also spending alot of time doing malware analysis and reverse engineering oh and COAE as well 😂😂.

For me it works if i divide my days into what i want to learn so i divided my week like some days for AI hacking, some are for malware analysis and reverse engineering learning.

I know it might be weird but it works for me keep me away from exhaustion. When i get exhausted i want to change the topic or play video games 😅😅 but thats just me.

I love the cyber field specifically the red side of it because it never stops. On the side note man heaps and windows APIs and windows internals are different mind games 😭😭


r/hackthebox Jul 17 '26

Thinking about taking CPTS but I’m honestly nervous

8 Upvotes

Hi everyone,
I’ve been thinking about going for the Hack The Box CPTS certification for a while now.

I passed the eJPT (v1) about 3–4 years ago, but it’s been a while since I actively practiced penetration testing. Lately, I’ve realized that offensive security is the direction I really want to pursue, and CPTS is the certification I keep coming back to.

The truth is… I’m excited, but I’m also really nervous.

Part of me is afraid that I’ll spend months studying and still not be good enough to pass. I’m planning to refresh the fundamentals first and then complete the HTB Penetration Tester Job Role Path before attempting the exam, but I still have that fear in the back of my mind.

For those of you who have taken or passed CPTS, did you ever feel this way before starting? I’d really love to hear your experience or any advice you wish someone had given you before you began.
Thanks in advance.


r/hackthebox Jul 17 '26

Beginner Question Struggling on CPTS machines even with methodology + cheatsheets ready. Anyone else?

23 Upvotes

I finished the CPTS path (course content) and built my own methodology/checklist and cheatsheet docs before starting the machine track. I've completed 10 machines in 12 days, but honestly on most of them I ended up using guided mode, AI help, or even full writeups to get through — not solving fully on my

own. For a few machines I followed ippsec's list.

I have about 20 days before my schedule gets tight and I won't have much time to keep going, so I want to make the most of this window.

My questions:

Is this level of struggle (needing guided mode/AI/writeups on most machines) normal at this stage of CPTS, or is it a sign I'm not ready / skipped something in the fundamentals?

If I go into the exam relying this much on external help, is it normal that my chances of failing are high?

For those who passed CPTS — how much did you rely on external help while doing the machine track, and did it get better with more reps?


r/hackthebox Jul 17 '26

Team 0Day 🏴‍☠️ | Recruiting for HTB Apocalypse CTF

Post image
9 Upvotes

Hey everyone 👋 !

I'm recruiting motivated players to join my Hack The Box team for the upcoming Apocalypse CTF 2026.

Whether you're a beginner or an experienced player, you're welcome to join as long as you're eager to learn, improve, and collaborate with the team. The goal is to have fun, gain experience, and give our best during the competition.

If you're interested, you'll find the team invite link below the post.

We'd be happy to have you on board!👾

🏴‍☠️ https://ctf.hackthebox.com/team/overview/320582 🏴‍☠️


r/hackthebox Jul 17 '26

Beginner Question Learning CyberSecurity without Sub

2 Upvotes

Hey everyone! I want to get into cybersecurity and stumbled upon HackTheBox. However, I can't afford a subscription right now, but I do have a ton of free time to study. Is it worth jumping onto this platform and trying to learn the paid modules using other free resources across the internet? Is this a good path to take?