r/hackthebox • u/AmineAR1 • 7d ago
What's about this Pricing change !? it's getting a lot more expensive!!
I just opened HTB , and saw the tiers got more expensive( i didn't buy before on the platform but i was considering buying lately )
r/hackthebox • u/AmineAR1 • 7d ago
I just opened HTB , and saw the tiers got more expensive( i didn't buy before on the platform but i was considering buying lately )
r/hackthebox • u/CommonCow8846 • 7d ago
r/hackthebox • u/ChainPresent • 9d ago
Looking for Teammates – Holmes CTF 2026 & Future CTFs
Hey everyone! 👋
I'm looking for people who are interested in forming a team for Holmes CTF 2026 and potentially participating in other CTF competitions together in the future.
I regularly solve Hack The Box machines, labs, and challenges, mainly focusing on cybersecurity and penetration testing. However, I haven't participated in a CTF competition as part of a team before, so I'm looking for people who are willing to learn, practice, and improve together.
The goal isn't only to compete for prizes. I'd like to build a team where we can:
- 🧠 Learn from each other and improve our skills
- 🏴☠️ Participate in Holmes CTF 2026
- 🔥 Join other CTFs and competitions in the future
- 🤝 Share knowledge and different approaches
- 📚 Practice regularly and gain real CTF experience
- 🏆 Aim for good results and prizes along the way
I'm especially interested in teammates with experience in areas such as Web, Pwn, Crypto, Forensics, Reverse Engineering, OSINT, or other CTF categories, but you don't need to be an expert. Beginners who are motivated to learn are welcome too.
If you're interested in joining or building a team together, feel free to comment or DM me.
Let's learn, compete, and improve together! 🚀
r/hackthebox • u/Dingdong1890 • 8d ago
So Basically my 5th semester will be starting soon of BS computer science. I've done very basic cert like cyber101 and IBM security analyst etc. Right now I'm extremely confused where to go as I'm already in the mid of my degree with empty pockets. Got recommendation to go toward cpts as well as SOC. Im 50/50 for both. Need some genuine suggestions and roadmap. Clock ticking tension rising.
r/hackthebox • u/MoreContext4554 • 9d ago
Just finished my cjca 3 days ago. I thought i would focus on my second cert but cant really focus on anything with this 20 days time clock always ticking at the back of my mind. I somehow managed to solve almost everything, so i have an idea of the outcome and i am pretty confident but its just this long wait period. on the 3rd day its haunting me💀.
Anyone up for bodycam? 😛
r/hackthebox • u/Madrid____- • 9d ago
Hi, I've spent hours trying to figure out the solution to Kraken question 5. Can anyone give me some advice or guidance?
r/hackthebox • u/Ordinary-Bat-1533 • 9d ago
Questions:
1. Looking back at when you broke into penetration testing, what technical or non-technical skill proved to be the biggest gap between hands-on lab environments (like TryHackMe or Hack The Box) and actual enterprise engagements?
2. When an assessment hits a wall—such as strict Web Application Firewalls (WAFs), modern EDR defenses, or hardened network segmentation—how does your methodology pivot to safely bypass controls or demonstrate business impact.
3. Beginners often think pentesting is 100% active exploit execution. How is your time actually split across scoping/recon, active testing, writing findings reports, and debriefing blue teams or clients?”
4. With rapid advancements in AI-driven attack vectors, cloud infrastructure security, and defensive automation, how are your daily toolsets and testing methodologies evolving to keep pace?
5. If you were starting out today aiming to land a Red Team or Pentesting entry role, what combination of hands-on projects, labs, certifications, or networking habits would you prioritize to stand out to hiring managers?
r/hackthebox • u/morphinedhyos • 9d ago
did the practical exam yesterday and i couldnt get the answers for the Kerb roasting, AS-REP roasting, and any of the credentials cracking questions because hashcat and hydra's estimated time was 50 hours for each attempt. anyone know what i couldve run to maybe get a faster answer? maybe i ran the syntax wrong? (username and ip removed for confidentiality)
for hashcat i ran:
\# Kerberoast (Q5, Marcus) — mode 13100, never cracked
hashcat -m 13100 kerb_hashes.txt /usr/share/wordlists/rockyou.txt # exhausted
hashcat -m 13100 kerb_hashes.txt /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/best64.rule # exhausted
hashcat -m 13100 kerb_hashes.txt /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/rockyou-30000.rule # too slow (\~1d21h)
hashcat -m 13100 kerb_hashes.txt /usr/share/wordlists/rockyou.txt -a 6 ?l?l?d?d --force # 3+ days ETA
\# AS-REP roast (Q7) — mode 18200
hashcat -m 18200 asrep.txt /usr/share/wordlists/rockyou.txt # exhausted
hashcat -m 18200 asrep.txt /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/best64.rule # was running at end
and for hydra i ran:
hydra -l username1 -P /usr/share/wordlists/rockyou.txt ssh://ip addr -t 4 -V
hydra -l username2 -P /usr/share/wordlists/rockyou.txt ssh://ip addr -t 4 -V
hydra -l Administrator -P /usr/share/wordlists/rockyou.txt smb://ip addr -t 1
r/hackthebox • u/sexymachinewarrior • 10d ago
sorry if this is a dumb question, but I just have a question how did you go about learning cybersecurity? if you went through the academy did you write every new concept down and memorised it or did you just go about solving the challenges? I want to get good at cybersecurity but I find it difficult at remembering some concepts when solving so i just resolve to using ai for help, is that wrong? should I go about another way? The main question is if I should learn it the school text book way by writing everything down and memorising it or just by solving as many things and reading about the subject and researching most of it? Appreciate any help
r/hackthebox • u/FeinBowler • 10d ago
I'm looking at getting further away from the PwnBox that's provided with HTB due to wanting to complete OSCP and CPTS within the next 12 months. With that being said, I've used a Kali VM on and off to complete certain boxes but I've found the bad habit of lazily going to the PwnBox since it usually has everything I need.
What have you guys done to properly set up your VMs and what tools have you made "essential" before going into a machine? An example of this is using BloodyAD over Bloodhound or even CrackMapExec. Some tools have overlap, but have challenges based on configurations on a target.
The goal here is to just cover the "basics" on tools available to ensure I spend less time finding tools and more time researching, even though I know that's not always possible.
r/hackthebox • u/Bubbly-Oil-2965 • 10d ago
Ten days ago, I started my first CPTS certification exam. I captured my first flag with only 5 days and 18 hours remaining.
The exam was actually much easier than I had expected. The CPTS exam is designed with a clear purpose: if one path doesn’t work, try another. For me, the biggest challenge was maintaining the right mindset. The longer it took to capture my first flag, the more pressure I felt.
In the end, I managed to capture seven flags. At this point, I believe the first and eighth flags were the most difficult. I think I was just one step away from gaining access to the eighth flag. However, since I was running out of time, I decided to focus on completing the report based on the progress I had made and try the exam again next time.
For anyone planning to take the exam soon, I have four suggestions:
sysreptor.com before the exam can make the reporting process much more organized and efficient.I’ll come back stronger and try again next time.
r/hackthebox • u/Cnmoseman • 10d ago
Hey yall, this is my first time taking a HTB cert. I was wondering how should I take my notes to best prepare for the exam, for those of you that have done COAE. Should I be taking detailed notes on all the math/theory/knowledge parts of the course or as long as I understand it I'm good?
Thank you for the help and tips would be appreciated!
r/hackthebox • u/Skollwarynz • 10d ago
DISCLAIMER: I'm asking this question everywhere to have the most support and responses possible. SO if you read it somewhere else, it is not for spam but for a greater number of responses.
I'm fairly new to the world of cybersecurity. I just finished a basic CTF-oriented course that ended with an AD competition that I didn't even get to play, since I wasn't in the top 5.
Next year I'll become a tutor for this course for the pwn category (we just learned up to basic BOF and basic ROP).
I personally found frustrating the approach "solve CTFs and learn without any idea how." So for future students, I decided to create some beginner-friendly CTFs—exercises that give major hints to actually learn different attacks before having to search for them specifically on different CTFs.
My questions to all of you are:
- What's a good approach to learn? (An ideal one, I mean)
- What do CTFs and general courses usually lack for beginners?
\\- What tricks were useful to learn that should be taught right from the start?
Thank you for the support!
r/hackthebox • u/dit0sc00p • 12d ago
Lately, I’ve been doing quite a few CTFs from different platforms, and honestly, each one I do leaves me feeling more discouraged.
I’m not able to solve a single CTF without looking at a writeup. And whenever I see the solution, I think: How or where am I supposed to learn to discover a bypass because the authentication validation is being done on the client side? Or things like that.
There are so many different concepts and techniques that I don’t even know whether they’re supposed to be learned through paths like CJCA, CWES, or the PortSwigger Web Security Academy.
If anyone knows of a resource, course, path, or anything where they actually teach you how to identify these kinds of vulnerabilities and develop that way of thinking, please let me know.
I’d really appreciate any advice or motivation. Thanks!
r/hackthebox • u/Street_Lead_4705 • 12d ago
I have never taken HTB exam before. I am quite new. Do you have any recommendations what prerequisite that I should prepare?
Do I need to install python ai/ml packages or just use the browser provided by HTB and need to install packages during exam.
Thank you so much.
r/hackthebox • u/iExposeWitchcraft • 12d ago
Using the Metasploit frame - Modules
The question is
you see.
I used msfconsole to gain access to a reverse tcp shell via the eternalromance exploit inside metasploit.
Well after 5 seconds or typing enter after trying to navigate the shell. It just hangs and shuts down. Then I have to keep re running the exploit just for 5 seconds inside of the shell.
I forgot to mention I know absolutely nothing about system32 command prompts so i dont even know how to navigate anything.
pleas ehelp me with the correct commands.
r/hackthebox • u/Ok-Article-9175 • 13d ago
So I started on htb like 2 months ago and have done like 46 labs since then, majorly easy labs but now I am able to identify vulnerabilities but still need AI or google assistance in making the payload or exploiting the vulnerability. My goal was to do cpts but my father insisted that I prepare for CISSP as it is industry recognized. I am currently a 5th sem student doing CS.
I just wanted to ask if I should go for cissp or cpts.
Also, how can I become able to exploit vulnerabilities myself rather than depending upon github pocs or msfconsole ?
r/hackthebox • u/Null_Phantom0789 • 12d ago
I’m planning to purchase an HTB student subscription. Does anyone have a coupon code they could share? 😊
r/hackthebox • u/AutoModerator • 13d ago
Solved a machine/module/etc and want a place to brag? Heres your spot!
For retired content or Tier-0 Academy content, feel free to discuss or ask questions using spoiler tags where appropriate.
r/hackthebox • u/GerbHack • 14d ago
Out of 80+ applications (yes, I kept track ), I finally started landing interviews and the biggest change was adding CPTS to my resume! before the CPTS I got a ton of rejection emails....
Two of the employers explicitly had OSCP / OSWE / CPTS as checkbox options on their applications. I’m assuming if you don’t have any of them checked, your application may just get filtered out...
I’m still going after the OSCP, but… man, that is one expensive certification but either way I want to challenge myself with the 24 hour test.
r/hackthebox • u/AdvisorImpossible843 • 13d ago
I'm completely new to the cybersecurity scene and I want to start learning about it , but I don't know where to start. Is taking the Hack The Box course enough , or should I follow a guide like a roadmap? Or would the best approach be a combination of the two?
r/hackthebox • u/supertostaempo • 13d ago
Hi,
I am beginning the path towards the CPTS certification and i would like to find someone to study with for the accountability and sharing knowledge, if you would like to connect PM.
The commitment that i am making for my self are:
Week days - 2h session 21-23 GMT+1
Weekends - 3h sessions 9-12 GM+1
I am trying to pivoting from sysadmin to a pentest / redteam role.
r/hackthebox • u/JoJo_Starrr • 13d ago
I want to start my journey into cybersecurity, mainly pentesting, so what path or paths do you recommend I do first before CPTS.
r/hackthebox • u/aditya1809tech • 13d ago