What is the HTB CAPE?
The HTB Certified Active Directory Pentesting Expert (CAPE) is Hack The Box's expert-level, hands-on Active Directory penetration testing certification. It tests whether you can take a full enterprise AD forest from an unauthenticated foothold to domain and forest compromise, and write it up in a commercial-grade report.
You earn it by completing the Active Directory Penetration Tester Job-Role Path (15 modules, 253 sections, rated Hard) and then passing the exam. You have to finish 100% of the path before the exam unlocks.
The exam
The CAPE exam runs for 10 days in a dedicated lab over VPN. You start from an internal foothold with no credentials, work through a real-world enterprise AD network of multiple domains and hosts, and submit flags as you go. HTB's launch blog sets the pass mark at 90 points. Reviewers report 10 flags, with 9 needed to clear the bar, and the exam is open-book.
You also submit a commercial-grade report within the same 10 days, based on HTB's template (the SysReptor HTB template works too), in English, as a PDF or ZIP of 20 MB or less. Submitting it ends the exam. You get 2 attempts per voucher, but the free retake only counts if you submitted a report the first time, and it has to start within 14 days of your feedback. Results arrive within 20 business days.
The 15 modules in order
- Enumeration & Recon: Active Directory Enumeration & Attacks · Active Directory LDAP · Active Directory PowerView · Active Directory BloodHound
- Lateral Movement & Tooling: Windows Lateral Movement · Using CrackMapExec
- Kerberos & DACL Attacks: Kerberos Attacks · DACL Attacks I · DACL Attacks II
- NTLM Relay & ADCS: NTLM Relay Attacks · ADCS Attacks
- Domain Trust Attacks: Active Directory Trust Attacks
- C2 & Evasion: Intro to C2 Operations with Sliver · Introduction to Windows Evasion Techniques
- App & Service Attacks: MSSQL, Exchange, and SCCM Attacks
Top tips from people who passed
- Start the report on day one. Write up each finding as you confirm it, and record why you ran each command, not only the command. (0xhav0c, LazyHackers)
- Recon first, exploit later. Spend the first day enumerating everything, and rerun BloodHound after every credential you find. (LazyHackers)
- Know the protocols, not just the tools. Understand AD authentication deeply, and learn PowerView and dacledit for when BloodHound misses an edge. (Lorenzo Meacci)
- It's a marathon. Take real breaks, fix your VPN latency early, and know when to back out of a rabbit hole. (gatari)
- Drill the hard modules and pivoting. Master DACL Attacks I and II, ADCS, and trusts, and practice Ligolo-ng until multi-hop pivoting is automatic. (Jason Ampoloquio, LazyHackers)
The full list of tips is at the bottom of the Resource Library tab.
How to use this tracker
- Set your start date at the top. Every day's calendar date and your pace indicator are computed from it.
- Pick a timeline (45/55/65/70/75 days). They all cover the same curriculum, just packed into more or fewer days, and your progress carries across when you switch.
- Tick each task as you finish it. A day is marked complete when all its tasks are done.
- Use the Notes field on each day as a journal for credentials you found, attack paths that worked, and hosts still to revisit.
- All progress is saved in your browser. Use Export backup regularly to keep a copy.
Enumerate the whole domain before you exploit anything, and rerun BloodHound after every credential you find. Reviewers say the exam is a marathon of chained AD attacks, so start the report on day one and template it before you connect.
This is an independent study aid and is not affiliated with or endorsed by Hack The Box. Always confirm current module counts, exam format, and pricing on the official HTB Academy site.
Built on and inspired by mattrfield's coae-study-tracker.