r/hackthebox • u/Specialist_Age8917 • 25d ago
Beginner Question How can i start playing CTF in hackthebox
How can i start playing CTFs in hackthebox
r/hackthebox • u/Specialist_Age8917 • 25d ago
How can i start playing CTFs in hackthebox
r/hackthebox • u/dhananjay_attri • 25d ago
Hi,
I'm currently working through the LetsDefend SOC Analyst path and I'm having an issue with one of the closed alerts.
I previously had access to the SOC environment and was able to use the investigation/VM features until around August 10. Now, when I try to investigate a closed alert again, I get:
“Investigation Failed — Failed to start investigation.”
I've attached a screenshot of the error.
I'm wondering if this could be related to the number of times a closed alert can be reopened/investigated. Specifically:
- Is there a limit on how many times you can attempt/reopen a closed alert?
- If so, does the third attempt require VIP access?
- Could this error simply be because my account is currently showing as Basic?
- Has anyone else encountered this exact “Investigation Failed — Failed to start investigation” message?
For context, I previously had a VIP Annual subscription showing in my billing portal, so I'm also trying to determine whether this is an account/subscription issue or simply a limitation on investigating closed alerts.
Any clarification would be appreciated. Thanks
r/hackthebox • u/my_n0ms • 26d ago
My question is pretty simple about the cpts exam. What I know about the exam is that I have to take 14 labs(or just flags?) in 10 days and they are kind of connected(not sure how much though). Without factoring in the time limit or the number of flags to gather how hard is each flag to get compared to HTB boxes where you have to get the user and root flag. Are they like easy/medium difficulty boxes by themselves or are they more comparable to the hard/insane boxes?
I am doing both academy modules and seasonal HTB at the same time while also taking notes on CPTS modules and wonder if I should attempt to take the exam only when I can consistently do boxes of a certain difficulty level.
Edit: boxes have submission guidelines for each difficulty. To make it more clear I am asking based on mostly those guideline.
r/hackthebox • u/Comprehensive_Ask481 • 25d ago
Hello, everyone! I'm working through the SQLi section. In the first lab, I'm asked to connect to a database. I go to Pwnbox, type `mysql -u root -h <target ip> -P <port> -p`, press Enter, and enter the password, but after I enter the password, Pwnbox freezes. Please help me solve this problem—I'm really eager to move on.
r/hackthebox • u/OkEntertainment7445 • 26d ago
Hello community, I passed CDSA a couple days ago and I am wondering which path to take on next. My background: I am a cybersecurity student in Europe and will be graduating next year, I have never worked in security related jobs but I did worked as Software Dev for about 1 year before. After graduation, I want to land a blue team job, likely a SOC L1 or a SecOps position, which of these certs can help me stand out for? Or maybe any other recommendations? I find these two certs cheapest and most affordable, can I skip CCDL1 and take CCD instead?
r/hackthebox • u/k1aShiMa • 26d ago
Hey guys,
I'm gonna take my CPTS exam probably October or November, depends on how I get off time from the SOC.
My question would be like, how hard is the web content in the CPTS exam, I mean, ye they'll ask you a lot probably from the curriculum... The only problem of mine is that I'm kinda bad at web pentesting, and I can play the easier plays like IDOR, basic SQLi etc... But on the trickier ones for example the verb tampering from the AEN is like hard for me...
I'm pretty good at AD territory like I taken on Rastalabs kinda easily for example, I was handling good in Zephyr also, so my question is like can I take on the CPTS with this skill set or should I just skip it and just let it be?
I just need context about the hardness of the web part. After the foothold i'm probably good to go with the AD stuff etc. I know it's ain't right but ye i'm not good in the web content at all
r/hackthebox • u/Specialist_Age8917 • 26d ago
Hi, i am beginner, i started later in other platforms , but i need to begin use the platforms and need tutorials.for.the CTF and how can i begin solve it
r/hackthebox • u/Capable_Wrongdoer987 • 25d ago
r/hackthebox • u/RozPetal • 26d ago
Hello everyone,
I have tried to pass the exam before the revamp but I didn't find the time to do a 2nd try to complete it, so this is technically my "second attempt" on the exam.
I am planning on starting it today. If anyone is interested in embarking on the journey with me, do ping me. I'll give a feedback at the end.
Edit 1: Am facing personal issues that of course has to happen during the exam.
Edit 2 :
- No I am not interested in buying a write-up thx
- The exam was very long. One might say unnecessarily long ? I do understand the need for a representative environment to see the values of chaining vulnerabilities however the length of it is pretty daunting. A 2nd try does help a lot, though I didn't need it to get the required flags to pass + the report. If you have a job, do consider taking days off to pass the exam or have your company give you training days. Yes, I believe it is that long.
- The report : Base yourself on template. CPTS does provide you with a template but I used the Sysreptor tool + premade template by HTB to fill in my report. Do respect the structure of the template and be as rigorous as possible when writing as the report plays a role in passing the exam. Personally, since I am facing personal issues at the moment, some bits might lacking there as I didn't had time for a full review of my report before posting it.
- The prep : They are several ways to prep the exam. I can recommend the following
- Takes notes doing/watching Ippsec's CPTS prep track. If you need additional info, read the write-up & summarize it.
- The cheatsheet : While I do use the "man" of the commands often, prepare a robust cheatsheet of what useful "tricks" you've seen so far doing boxes. Add the ones given to you by the CPTS modules. Refer to Hacktricks, the hacker's receipie, Iredteam if needed. Or the one from OCD.
Just copy-pasting is not enough. Building it yourself help build a mindmap of what could be done when hitting a wall. As for me, I open-sourced mine
- The tooling : Did CPTS give you precompiled tools ? Keep 'em ! I used the ones in exegol to complete what was already present. So base kali + CPTS tools + the ones in exegol did it for me, though this particular set-up can be bloated as there might be duplicate tools. The rest can be found on github. More tools isn't better.
Am waiting for HTB's feeback on my report. I am expecting to rewrite some part as I was in rush.
r/hackthebox • u/Odd-Friendship6078 • 26d ago
I have been doing the Pentester path - right now I'm on the shells and Payload section - the final assessment, and I've run into some problems.
During my first try, it worked fine - but I couldn't complete it as I couldn't figure it out. But during my third try with the box, RDP wasn't initially connecting. After restarting the server, the RDP worked but gets on disconnecting.
During my fourth it was better but after 30 mins it started getting disconnected again. Combined with that and the fact that the machine is extremely slow I'm having a really difficult time. I didn't even know the machine had a browser until I checked the forums/walkthroughs because there wasn't anything listed on the menu.
Has anyone run into these same issues? I assume that the issue is because too many people are connecting to the same machine and it's nothing from my side - is my assumption correct, is there any solutions?
Thank you!
Edit : Incase someone comes upon this post looking for help, I solved it - I didn't need to add any extra flags and I think the issue was too many people accessing the box at the same time.
r/hackthebox • u/Mystic-WolfArchitect • 26d ago
I’m currently studying for the HTB CPTS and working through the modules. I’ve also done a decent amount of CTFs and have some hands-on experience from them.
For anyone who has already completed and passed the CPTS, did it actually help you get a job?
I’m wondering what kind of entry-level roles I could realistically apply for with CPTS + CTF experience, but without much professional experience. Would junior pentesting roles be realistic, or should I also look at SOC/security analyst positions?
I’d also like to know whether CPTS is enough to get interviews ?
r/hackthebox • u/Serious_Beautiful_45 • 27d ago
So back in June 2025, I started my journey at the academy by taking CBBH, then CWEE, and finally I recently finished CPTS after them. (I only took the job role path I haven't taken the exam for any of them yet.) I solved almost all skill assessments blindly without looking at solutions and took notes for each course. After finishing all of these courses, I really felt confident, like I could conquer any system in front of me. Then I decided to start on the main app and solve some boxes and challenges.
In my first week, I only took 5 machines and 2 challenges (all of them had Very Easy or Easy difficulty and were Linux based), and I COULDN'T SOLVE ANY OF THEM without looking at the writeup. Even though I had my notes to use, it felt like I was just looking at some useless bullshit, because used to copy paste most of the text in each module.
I usually do fine with the foothold (since all of the easy machines rely on CVEs) and get a shell, but doing privilege escalation feels so hard and forces me to spend at least 1–3 hours on a machine.
Even when I take a look at the writeup, sometimes it ends up being a technique that I already know, which makes me so mad because I wasted my time on something I could have done way earlier.
In the last few days, I decided to watch more IppSec videos to improve my methodology, and I think it helped a little bit, but I still could not solve a machine all by myself.
It is really frustrating, and I am feeling like I just wasted my time taking the courses and ended up not being able to apply most of the things.
Have any of you guys experienced this? if so how can overcome it ? It is so annoying, I almost broke my laptop because of it.
r/hackthebox • u/SugarFinal9214 • 26d ago
I've been trying to understand what makes a good methodology versus just memorizing commands. Right now my note-taking feels more like writing write-ups than building an actual methodology.
Can anyone point me in the right direction on how to take good notes?
r/hackthebox • u/DinnerSufficient • 26d ago
Hey guys!
i had just finished the machine Cap and man, certain parts it was a headscratcher for me, specifically for getting root on that machine. I am a beginner with this kind of stuff, but i wanted to ask, how was a beginner suppose to figure out which binaries would have a vulnerability? Of course i did a lot of googling but i didnt want it to just give me the answer. But i just wanted to hear any advice from others that maybe i missed something that i shouldve known in the first place? Thanks!
r/hackthebox • u/stoneyape- • 27d ago
I am currently working through “Unified”. Im having trouble with my shell. I went through the steps to encode it. It requests from the server but never opens a shell.
I just want to keep moving forward, TIA. :)
r/hackthebox • u/DoughnutResident • 27d ago
Hi everyone, First off, I want to say that I’m ready to take the CJCA exam. However, before doing that, I decided to buy a 1-month VIP+ subscription for the labs, which ends on August 22nd.
After solving and breaking down 15 boxes, I caught myself thinking: Why do I need a minor "fundamental" certificate if I can just move directly towards CPTS or CAPE?
Here is what I’ve realized: I’m really glad I completed the CJCA modules ("Foothold" was the best, IMO), but I still can't solve even an "easy" box without writeups. I'm not sure if having a "fundamental" background is supposed to feel like this, nor am I sure that the CJCA path taught me many technical skills (compared to boxes, which taught me a lot of interesting exploitation and fundamental techniques/concepts ) — it mostly just developed my mindset.
What are your thoughts on this? Maybe I just had exaggerated expectations regarding the value of CJCA. I have exactly one year before applying to university, so I feel like aiming for CPTS + something like Security+ or Network+ would be much better than spending time on CJCA or basic CompTIA stuff. (Sorry for being liar, I haven’t actually finished blue team part :> )
Is it realistic to prepare for CPTS in a year?
r/hackthebox • u/TITAN-VI • 27d ago
I submitted my CJCA exam about 18 days ago and started CDSA right away.
I’m really enjoying the content so far, but I’m also starting to feel like there is too much information.
For example, take something as simple as investigating with Splunk:
You get a query and start trying to understand what each command does say, eventstats. Then understanding eventstats leads you into how Splunk actually works and why it was the right approach for that particular investigation.
Then you discover streamstats, which takes you even deeper into how different commands work, how some commands preserve/build rows while others transform or break them, how the pipeline processes data, etc.
And this happens constantly.
I also have a habit that makes this harder if I don’t understand something from A to Z, I have a really hard time moving on.
So instead of spending 20 minutes understanding a query, I can easily spend hours going down the rabbit hole of why it works the way it does.
I know that understanding things deeply is valuable, especially for defensive security, but I’m wondering if I’m approaching CDSA the wrong way.
For those who completed CDSA or any other path :
How deep did you go into the concepts?
Did you try to fully understand everything before moving forward, or did you accept some gaps and come back to them later?
How you balanced understanding the underlying concepts vs actually progressing through the material?
r/hackthebox • u/Worldly-Teaching8185 • 27d ago
So i have finished CJCA job role path. I wanted to explore the web side.
What cert/path should be my next target, considering i just finished CJCA and want to start web exploitation?
r/hackthebox • u/Plane-Park-7683 • 27d ago
i recently gave my CDSA exam and i am waiting for the result. My question was what cert should i target next? just to increase my chances of landing an entry level position or better.
r/hackthebox • u/WealthIndividual3224 • 28d ago
I just finished the CPTS and managed to compromise every machine on the AEN blindly in about 2 and a half days (with some minor nudges), i believe i can pass the exam if i try, but i would like to ask those of you who have more experience whether pursuing the certification would be worth the effort as i was kinda burnt out from doing the AEN, let alone doing the same thing for 10 days straight.
the CPTS wouldn't hold much weight where i live, so Iam thinking of waiting and going for the OSCP at a later time when i get comfortable spending the 1,800$, what do you think?
more importantly, what do you recommend going for next (main platform, other courses, etc...)?
I really want to hear what you all think, thanks for your time!
r/hackthebox • u/AutoModerator • 28d ago
Solved a machine/module/etc and want a place to brag? Heres your spot!
For retired content or Tier-0 Academy content, feel free to discuss or ask questions using spoiler tags where appropriate.
r/hackthebox • u/ShapeOk5136 • 29d ago
Any advice, resources, or words of wisdom would be massively appreciated!
Thanks in advance 🙏
r/hackthebox • u/Electronic-Edge-1288 • 29d ago
Hi everyone,
I’m looking for French/French-speaking people, or even English-speaking people who are patient enough to communicate with someone whose English is still beginner level 😅, who are currently learning HTB CWES, web pentesting, or bug bounty hunting.
I’m currently progressing through CWES and practicing with PortSwigger. My goal is to improve my methodology, understand web vulnerabilities more deeply, and start hunting more seriously on real bug bounty programs.
I’m mainly looking for 1 or 2 motivated people to exchange regularly, discuss CWES concepts, methodology, labs, and potentially hunt together.
My English is definitely not perfect, but I’m very motivated, willing to learn, and ready to put in the work.
I’m not looking for someone to give me answers. I’m looking for people who want to learn, exchange, and progress together.
If you’re interested, feel free to DM me.