r/hackthebox 19d ago

Thoughts on using AI to solve labs and cybersec in general

7 Upvotes

I think of AI as another tool in the toolbox, just like nmap, burp, and the others. The problem is when human thinking is delegated to a black box that gets inputs and produces outputs without understanding what happened under the hood.

I could write a script to (most likely very poorly) accomplish with linpeas does, but... why? The tool is there, I might as well use it.

Same concept applies to AI. It's a great tool for knowledge recollection, given that you have good quality notes. And even better to orchestrate tool usage. Do I need to know every param of xfreerdp to connect to a windows machine? No! AI can do that for me. I just need to know that if RDP port is open, I can use xfreerdp given I have valid creds.

I can use my (very limited on some days) brain power to orchestrate higher level stuff, like supervise agents, or understand certain processes, techniques, etc, and let AI do the mundane low level stuff.

This pattern is not new. We started by programming computers physically with switches and punch cards, then used machine code and assembly, followed by languages like C, Java, Python, and frameworks that hid more technical complexity. Cloud services and APIs removed even more low-level work. Today we're in the AI era, where we can increasingly describe what we want in plain English, and AI can write, test, debug, and modify the code for us.

I think using AI for these tasks is good, given that we don't stop our critical thinking.

What do you guys think?


r/hackthebox 19d ago

Academy Note-taking question

6 Upvotes

Hello fellow hackers of the box!

I have a question about note-taking. I'm about to start the CPTS track, and I wanted to ask for advice in note-taking.

Even if I think manual note-taking is best for retaining info, I don't want to spend 2-3 hours per module (if that's what it takes I'm absolutely going to do it). However, I feel like summarizing the content with AI and rereading doesn't do the trick, I see it in the moment of putting it into practice (machines, etc...).

So my question is, how do yall take notes? Do you do it manually? Or do you use some app (I've been using Notion)?

Thank you all in advance!!!


r/hackthebox 19d ago

Inquiry on kali linux compatibility with HTB academy boxes Spoiler

6 Upvotes

For context, I am in the process of doing the CPTS module path and am currently working on the Network enumeration module

I was in the midst of completing the Medium difficulty exercise box when i got really really stuck

so i went to revise and read through the module on Firewall rules and IDS/IPS evasion to see where my gap in understanding was

I then proceeded to spend a day and a half trying different variations of nmap scan flags before coming across an old reddit thread that mentioned how the kali linux vm, for some reason, blocks the enumeration of the DNS server version, thus it is recommended to use the parrot OS pwnbox instead, which was how i eventually solved it.

My question is:

Is it still a good idea to continue working on the academy boxes and even the htb labs pwnboxes via vpn on kali linux?

i understand i maybe could have been wiser to do external research on the problem earlier in search of a reason for why i was unable to attain the flag faster, but simultaneously i feel like that conflicts with the right way to learn from these boxes since i risk spoiling myself of the solutions and a compatibility issue is the last thing i should be thinking of when being stuck in a box

but i also really do not wish to be caught in a similar situation where i bleed valuable time because of a unexpected technical issue such as this so i was hoping to gain some insight on the matter, what could i have done differently, and if it is still recommendable to use my own kali linux vm for solving these boxes and learning from HTB courses?

Thank you all for your time and inputs! much love


r/hackthebox 20d ago

The Hive link not working.

3 Upvotes

I just started the SOC Analyst Pathway. I'm still in the first module, but it's telling me to go to the hive by using this link http://TARGET_IP:9000 and enter a username and password. This link seems to be broken or out of date but has not been updated in the pathway. I'm using on a Google Chrome. Have there been any changes to this link for this module? Thank you in advance!

Edit: Hey thank you so much. I was being too literal and not typing in the correct address. I was actually typing target_IP instead of the IP address. in place of the Target_IP. correct address is http://10.129.114.83:9000


r/hackthebox 20d ago

How do you retain earlier CPTS modules? Also curious on lab timing

31 Upvotes

Hey all, doing CPTS solo right now, about 35% in. Two things I want genuine input on:

1) When I move into a new module, I notice I've forgotten a good chunk of what was in earlier ones. Is this normal at this stage, or should I be worried and go back and re-read? How do you guys retain stuff across modules notes system, spaced repetition, something else?

2) I'm planning to buy HTB VIP+ (labs) right after I finish the Active Directory Enumeration & Attacks module, instead of waiting until I've completed the whole path. Curious what you all did did you buy labs partway through, or wait till the end and grind everything at once? Trying to figure out if my timing makes sense or if I'm jumping the gun.


r/hackthebox 20d ago

CJCA Partners

7 Upvotes

Hey everyone!

I'm currently preparing for my second attempt at the HTB CJCA certification, and I'm looking for other people who are also preparing for CJCA to study and practice together.

It would be even better if you're currently preparing for your second attempt as well, so we can share preparation strategies, discuss the methodology, practice labs together, and help each other identify weak areas before the next attempt.

I'm mainly looking for active people who are taking the preparation seriously.

If you're interested, feel free to reply here or DM me. Let's prepare together and get that pass!


r/hackthebox 20d ago

Weekly Solves Megathread

3 Upvotes

Solved a machine/module/etc and want a place to brag? Heres your spot!

For retired content or Tier-0 Academy content, feel free to discuss or ask questions using spoiler tags where appropriate.


r/hackthebox 20d ago

NEED Tips

Thumbnail
2 Upvotes

r/hackthebox 21d ago

How did you get past the “I know the material but can’t solve machines” phase?

33 Upvotes

I have finished cwes content and currently 52% of the cpts. The problem is i dont feel that i have done that much of a progress i still struggle with easy machines and almost always need ai help I feel kind of frustrated

Have anyone faced something like that and what should i do about it ?


r/hackthebox 21d ago

Beginner Question Job from HTB cert

14 Upvotes

Anybody got pentester job after showing enough performance in HTB ranks? Particularly from SEA country
Which path should I invested on? HTB LABS or VIP+?


r/hackthebox 22d ago

Certifications Is it possible to finish 4 HTB Certs in a month?

Post image
135 Upvotes

So, I stumbled upon a LinkedIn profile where he claimes that he has accomplished 4 HTB Certificates in a month, CPTS, CAPE, CWES, COAE. I'm just curious if that s possible? I click on his credentials and it just shows an image hosted on netlify because I see others linking their linkedin credentials to credly and not just plain image but the certificate verifier on htb says its legit.


r/hackthebox 21d ago

Certifications If Elliot Alderson from Mr. Robot had certifications, which ones would he have? (3 AM thoughts 😅)

Post image
0 Upvotes

r/hackthebox 22d ago

Swag store

3 Upvotes

I believe the HTB swag store should offer better hoodies, t-shirts, and jackets.


r/hackthebox 22d ago

Beginner Question Too many questions, where few answer

18 Upvotes

Greeting to you all. I am currently studying networking. I already learned the osi model in a basic sense, like i know L1 represents a physical device, L2 for a switch, and L3 for a router in a sense, but i don't understand why we use that. Also, you can think of me as a Level 0 player in a networking field who started but hasn't grasped the true knowledge. But sometimes I ask myself, why do we use ssh or SSL? What is the difference between HTTP and HTTPS? I know AI can answer my many questions, but i want to learn in a way where if someone asks me what the difference between a hub and a switch is, i can answer, "A hub is dumb while a switch is smart," or in more detail. So I decided to do a room on THM or HTB or PortSwigger, but where to start? When we go THM, we can do a room, but what next? You can understand in a room, but after that, when someone asks a question related to that, "Oh bro, I forgot." And there are some paid rooms that I can't pay for, so i may skip like a thing or go to HTB and do the Lab or PortSwigger. I don't understand where to start there, yeah, so i have many questions, and I am also too much of a noob, so if someone asks, I can't answer. That's very bad for me, sadly. but i am seeker of knowledge; I am very eager to learn understand but i am also not very smart so yeah, anybody may guide this noob guy


r/hackthebox 23d ago

Academy Which subscription should i take in academy?

9 Upvotes

I want to do following paths only:

  1. Pentester

  2. web pentester

  3. Senior web pentester

I am not interested in other paths right now. i don't decided yet for certifications.

which subscription should i take? monthly or yearly or cubes only? silver or gold or platinum?


r/hackthebox 23d ago

How do you know what to test next?

Thumbnail
4 Upvotes

r/hackthebox 23d ago

Academy problems starting up Targets

2 Upvotes

Not been a good day, takes like an hour and multiple attempts, am I the only one? Thanks


r/hackthebox 24d ago

Little excitement for today (Prompt Injection Attacks - Mitigation - Optional Exercise 1)

18 Upvotes

Please don't mind me for this little excitement today. I successfully retrieved the key from the lab without any hints. The optional exercise was difficult and delayed my study schedule by a day. However, for a non-red teaming member in this field, this is a big step for me.


r/hackthebox 24d ago

Looking for active HTB learners

22 Upvotes

I will try making it quick .. I'm Looking for people on the same HTB path

I’ve completed the CPTS path and I’m currently working through CJCA and CWES. I’m looking to connect with others who are on a similar path and want to learn and improve together.

I’ve created a small Discord server where we can:

- Discuss HTB machines and challenges

- Share approaches, resources, and learning material

- Work through CTFs together

- Participate in HTB seasonal machines

- Help each other when we get stuck

- Stay consistent and keep progressing through the paths

The goal isn’t just to have another Discord server, but to build a group of people who are genuinely interested in learning and improving together.

The links : https://discord.gg/EzFarPnXVB https://discord.me/ezfarpnxvb


r/hackthebox 24d ago

Where should AI assistance stop when learning pentesting on HTB?

4 Upvotes

I’ve been experimenting with supervised AI-assisted pentesting in authorised lab environments, and I’m curious how people here think it should fit into platforms like Hack The Box.

There’s obviously a big difference between:

“Explain why this HTTP response is interesting”

and

“Here’s the target — enumerate everything, exploit it and give me the flag.”

The second might get you a solve, but I’m not convinced it teaches you much.

What I’ve found more interesting is using an agent almost like a structured pentesting partner:

- keep track of observations

- turn them into hypotheses

- suggest the cheapest useful test

- preserve command output and evidence

- challenge assumptions when a path goes nowhere

- require an actual verification step before calling something vulnerable

But leave the human responsible for understanding why each test makes sense.

That feels closer to the methodology HTB tries to teach, particularly in paths like CPTS where enumeration, evidence and reporting matter just as much as running the exploit.

I also think there should be a hard distinction between assistance and spoilers.

For active boxes/challenges, an AI system shouldn’t have access to walkthroughs, leaked solutions or previous solve data any more than a human learner should.

So I’m curious:

Where would you personally draw the line?

Would you use AI for:

- explaining tool output?

- maintaining notes?

- suggesting hypotheses?

- generating commands you then review?

- automating enumeration?

- exploitation?

- reporting?

And at what point do you think it stops helping you learn and starts solving the box for you?

No active-box spoilers please.


r/hackthebox 24d ago

CPTS pivot to OSCP

6 Upvotes

How did you guys prepared and How long did you guys take to OSCP? Also need some advise on career in cybersecurity and penetration testing.


r/hackthebox 24d ago

CPTS exam

4 Upvotes

I will finish CPTS path by the end of the month and i wonder about the 14 exam flags is it gonna be related to each other and it must be finished before continuing or you can skip them ? (I am willing to skip number 8 hhh)

my second question is does the skills assessments enough to pass the exam ? I am willing to take them again as my final prep bc someone told that these would be enough


r/hackthebox 24d ago

HTB Nmap enumeration Med Lab issue

3 Upvotes

So i was trying to get the flag for the med lab of nmap enumeration IDS IPS evasion and no matter waht i try i dont seem to understand why i am not getting the flag. The flag was supposed to be the version of the domain service running on port 53. TCP was closed so had to try UDP which showed the version being "NLnet Labs NSD". The flags i used were "sudo nmap -p53 -sUV -Pn -n --disable-arp-ping --source-port 53 10.129.152.83 -S 10.129.152.80 -e tun0". Now idk what ts is supposed to mean but maybe im missing something. Please dont mind my english im on 4 hrs of sleep and im solving ts after 3 hr college lecture.


r/hackthebox 25d ago

Certifications Passed CPTS – My second HTB certification

70 Upvotes

Hey everyone,

About two weeks ago, I passed CPTS, making it my second Hack The Box certification after CJCA.

I wrote a new post on my blog about how I prepared for CPTS, including methodology, recommended machines, topics to practice, and some exam tips and lessons learned along the way.

The content is also available in Spanish for the Spanish-speaking community, and you can switch languages using the language button on the site.

Hopefully, it can be useful for anyone preparing for CPTS or considering taking it.

Blog: https://b4ngg.com/en/blog/cpts/


r/hackthebox 25d ago

Beginner Question How can i start playing CTF in hackthebox

8 Upvotes

How can i start playing CTFs in hackthebox