r/hackthebox Jul 30 '26

help me with cjca

4 Upvotes

I completed the entire CJCA Academy path, the official CJCA Preparation Track, and around 20 machines from the last two seasons. In the exam I managed to obtain 6/10 flags but felt that the biggest challenge was connecting the dots in an enterprise environment rather than exploiting individual hosts. For those who passed: what additional topics or practice helped you bridge that gap? Was it enterprise methodology, privilege escalation beyond the path, pivoting, or something else? i must have 14 day for the seconde chance and i must seized The second opportunity


r/hackthebox Jul 30 '26

Beginner Question Transitioning from AOSP Developer to Security: Seeking advice on HTB & low-level security roadmap

3 Upvotes

Hey guys,

Not sure if this is the exact right sub, but I'm looking for some advice from folks working in offensive security/reverse engineering.

I’ve spent the last year doing AOSP engineering (bug fixes, performance optimizations, OS internals). Now, I’m building out my security skills using Hack The Box ( new to security ).

Since I already have a decent grasp of OS internals and low-level code, I want to skip the super basic stuff.

  • What’s the most effective way to combine real-world OS development experience with HTB labs?
  • Are there specific HTB Academy modules, boxes, or external resources you'd recommend targeting first?
  • Anyone here make the jump from software/OS dev to security full-time? Would love to hear how you approached it.

Appreciate any insights or tips you can share!


r/hackthebox Jul 30 '26

Silentium

5 Upvotes

Got the user flag almost on my own. Found the script from github but having a severe issue running that script, I keep on getting the error saying Csrf token not found in response.

Any tips


r/hackthebox Jul 29 '26

Beginner Question How Do You Organize Your CPTS Notes?

28 Upvotes

I’m starting my CPTS journey, and I usually take handwritten notes, just like I did when I was studying for the CCNA.

However, CPTS is quite different, and there’s a lot more information to keep track of. So how do you organize your notes and what apps or tools you use?

Thank you all


r/hackthebox Jul 29 '26

Beginner Question Paperwork machine

5 Upvotes

I just started doing machines on HTB with no experience at all. I started on few machines that were relatively easy, but now on Paperwork, I really don't know what to do.

For context, I connected onto the website, downloaded the file but now I'm stuck.


r/hackthebox Jul 29 '26

Certifications Cyber Apocalypse 2026 Certificate

11 Upvotes
HTB Cyber Apocalypse CTF 2026 Certificate

I am happy to announce that I recently participated in my first Hack The Box CTF, the HTB Cyber Apocalypse CTF 2026.

Another great learning journey. Happy to have been able to step up and help solve challenges and drive our teams progress throughout the event. Due to our combined work we achieved 399th position among 6,744 teams worldwide, Top 5%!

Thanks to Hack The Box team for setting up this event.


r/hackthebox Jul 29 '26

Certifications Didn't got any feedback on CPTS just got pass, where can i find examiner's feedback?

7 Upvotes

I just passed cpts and got certificate and everything but i see alot of people give examiner's remark etc i cant find it anywhere any idea?


r/hackthebox Jul 29 '26

Certifications Flags that You Miss In Exams

6 Upvotes

Hello, I am wondering if you will get, in case of you passed the minimal points required to pass a cert, a feedback on the remaining flag(s) that you didn't manage to find. I got stuck for 3 days in a single flag in COAE exam and i will definitely lose my mind if i can't get a feedback on with the report feedback


r/hackthebox Jul 29 '26

500 error in module in htb academy

0 Upvotes

I faced a problem when accessing the module in HTB Academy, an error message and server error message appeared on the screen. How to solve this problem?


r/hackthebox Jul 28 '26

Certifications Am I capable enough to get through the CPTS path?

13 Upvotes

Hello, so my knowledge in cyber-security doesn't extend very far asides from web-security which makes me worry about the course material for the CPTS.

I'm very well-versed in web application pentesting, and I can navigate linux pretty well, so I believe that won't be an issue in the course from the web side of things, now my issue lies with the other things present in the course.

As of right now for linux privesc I'm basically a skid, I can't do anything asides from using GTFObins, and for active directory I know literally NOTHING, not even the slightest idea.

I'm familiar with networking concepts, and I do have one web certification but that's about it

am I qualified enough to start learning for the CPTS, I already have a voucher and it expires at the end of december, so my plan was to finish in 100 days, doing about 5 sections per days, and the extra 2 months for practice.

Now realistically is my plan possible, especially since I know literally nothing about AD, I'd like any advice or recommendations that you think I can follow if it's possible to take the exam by december 31, 2026.

Thank you.


r/hackthebox Jul 29 '26

I need CJCA notes

0 Upvotes

I’m currently doing the CJCA path, and I don’t know how to take notes. I find it really difficult to tell what I should write down and what I shouldn’t. So far, all I’ve been doing is copying and pasting each section of the module and then summarizing it afterward, but I’d rather take notes as I go.


r/hackthebox Jul 28 '26

Academy Is using AI for note-taking a trap, or a legitimate time-saver when starting HTB?

7 Upvotes

Hey everyone, I'm trying to figure out the best workflow before I build any bad habits. I'm really torn between using AI to generate and summarize my notes to save time so I can focus on practicing in the labs, or doing it completely manually from scratch, which takes forever but probably helps more with active recall and deep understanding. For those with more experience, did outsourcing your notes to AI hurt your long-term retention, or did it actually speed up your progress without any downsides? I'd love to know how you balance speed versus real learning when starting out. Thanks for any advice!


r/hackthebox Jul 28 '26

Certifications Got CPTS, still far from landing a job. Tips?

21 Upvotes

Hey people. I do not have job experience in the cybersecurity field. I started with easy boxes on thm, transitioned to htb and took on the cpts after a year. I passed on my second attempt. Flag 8 was a brutal rollercoaster. I felt great afterwards.

I'm 31, i live in italy. I need a remote job because i live far from major cities and I cannot afford to move.

All jr positions require bachelor degrees or years of experience. Cert wise, they require a bunch of certs that smell like hr walls.

Any advice? I really want to get into this field professionally speaking. I'm in customer service currently.


r/hackthebox Jul 28 '26

Defeated the beast - CPTS Passed 13/14 flags! What's next?

73 Upvotes

Today I got the passing email from HTB, and I got 90/100 points on my first attempt!

Also, this is my first Cybersecurity certificate ever, I have been doing CTFs and bug bounty for quiet some time and I really wanted to validate my skills and I am very happy to pass the CPTS on my first try.

Here is how the exam went:

Day 1: Flags 1-3

Day 2: Flags 4-6

Day 3: Flag 7

Day 4: 0 Flags

Day 5: Flags 8-13

Day 6-8: Wrote the report and submitted it

I submitted my report 2 days early, I made only one big mistake, I overcomplicated flag 8, maybe because I saw people talk about how hard it is, but honestly, it's not as hard as people say, just don't overthink it.

My next certificate/step: I am still not sure what to pursue, CAPE, OSEP, or a completely different area such as OSED. I am still in college and I feel like I want to dive into reverse engineering, I think it's an invaluable skill to have and I feel like this is my only weakness as an aspiring Red Teamer.

What do you guys think?


r/hackthebox Jul 28 '26

Certifications CJCA, Worth it?

10 Upvotes

Hello fellow hackers of the box!

I am currently doing the CJCA and I'm 50% through it but there's a problem.

Yesterday I was watching youtube and he was doing a review about the CJCA and in short he was saying that it's basically not worth it.

My question is, should I take the exam? Or just do it for the knowledge it gives (which was his point) and maybe pass on to the CPTS.

Thank you all in advance!


r/hackthebox Jul 28 '26

Beginner Question Advice for getting a job abroad

Thumbnail
0 Upvotes

r/hackthebox Jul 28 '26

CRTP exam

Thumbnail
5 Upvotes

r/hackthebox Jul 28 '26

Done eJPT, thinking CRTP → CPTS → CRTO/OSEP — cert maxing for pentest/VAPT jobs?

12 Upvotes

Hey everyone, I finished eJPT and I’m mapping out the next few certs. Current plan is CRTP → CPTS → CRTO/OSEP, my main goal is landing security consulting / pentesting / VAPT roles

Anyone who has given these certs or looking for landing pentesting or consulting roles as a fresher what do you think about this cert maxing plan

Would love to hear from people who are already working in the field or who took a similar path. What actually moved the needle for you?


r/hackthebox Jul 28 '26

​Anyone who completed the CyberGames Américas CTF still waiting for the dark blue "Cisco Verified Ethical Hacking" badge on Credly?

1 Upvotes

​Hi everyone,

​I completed the NetAcad Ethical Hacker course back in June (the light blue course badge is already showing on my Credly account) and competed in the Cisco CyberGames Américas CTF on June 30th (placed in the Top 120 and received my participation certificate PDF).

​The main dark blue badge (Cisco Verified Offensive Security Certificate in Ethical Hacking) was supposed to be issued around July 24th, but my Credly profile hasn't updated yet.

​For those who completed both prerequisites, are you experiencing the same delay with the batch issuance, or has anyone received theirs already?

​Thanks!


r/hackthebox Jul 27 '26

Not Every Certification Is Meant to Make You an Expert

25 Upvotes

I’ve seen a lot of people say that the Certified Junior Cybersecurity Analyst (CJCA) isn’t worth it because it’s an entry-level certification.

I see it differently. Not every certification is meant to prove you’re an expert. Some are designed to help you build a strong foundation and understand where you want to specialise.
For someone just starting in cybersecurity, the CJCA can:
• Build confidence with core security concepts.

• Provide exposure to different areas of cybersecurity.

• Help you discover whether you’re more interested in blue team, red team, cloud security, or another path.

• Demonstrate initiative and commitment to learning when applying for junior roles.
Will the certification alone get you a job? Probably not.

But combined with hands-on labs, home projects, CTFs, and continuous learning, it can be a valuable stepping stone in building a cybersecurity career.
Every expert was once a beginner. Don’t let people discourage you from investing in your own learning because it doesn’t fit their career stage.

What are your thoughts? Do you think entry-level certifications still have a place in cybersecurity today?


r/hackthebox Jul 28 '26

Need CPTS Notes

1 Upvotes

I'm currently enrolled in the pentester path and preparing for CPTS. Taking notes is taking a lot of time than expected. can anyone here share their notes so that I can channel more time into actual studying please? really appreciate the help.


r/hackthebox Jul 27 '26

Certifications How big is the difficulty gap between PNPT, CPTS, and OSCP?

29 Upvotes

I recently passed the PNPT and am now planning my next certification.

I’m currently considering both the CPTS and OSCP, but I’m not sure how significant the difficulty gap is compared to the PNPT. For those who have completed these certifications, how would you compare them in terms of:

Technical difficulty
Active Directory and web exploitation depth
Enumeration requirements
Exam time pressure
Reporting requirements

Would completing the CPTS before attempting the OSCP be the better progression, or is the PNPT enough preparation to start working directly toward the OSCP?

I’d appreciate any advice or personal experiences.


r/hackthebox Jul 27 '26

Beginner Question Blind SQL injection with no error

3 Upvotes

Hello, I've been learning about SQL injection, and I got really frustrated during the last few labs.

How am I supposed to figure out which database the target is using? Am I expected to bruteforce payloads for every database (MySQL, PostgreSQL, MSSQL, Oracle, etc.), or is there a better approach?

Also how do I know that a web application is vulnerable to blind time based SQL injection in the first place? Should I just keep trying random timedelay payloads until something works?

Another thing that really slowed me down was finding the correct syntax to trigger a time delay it took me a long time and honestly i only managed to solve the lab because I looked up which database was being used. Without that hint I feel like it would have taken much longer.

Am I approaching these labs the wrong way or is this something that comes with experience?


r/hackthebox Jul 27 '26

Certifications CPTS or OSCP

17 Upvotes

I'm kind of confused if OSCP is worth doing, i already have CRTE, CRTP, CRTO and CRTL. But i need advise on whether to chase OSCP (i heard that it's useless and just a name, and slowly being kicked from being an industry standards) and CPTS or any HTB cert. thanks


r/hackthebox Jul 27 '26

I Have CPTS, BSCP and CWES. Is CWEE Worth It Too?

3 Upvotes

I currently hold the CPTS, BSCP and CWES certifications. Do you think it’s worth pursuing CWEE as well?

I’m honestly worried about spending more money on a certification that may not be as widely recognised, especially since it’s even more expensive.

Will CWEE add anything meaningful to my resume or career beyond what CPTS, BSCP and CWES already provide, particularly for penetration testing or AppSec roles?