What is the HTB CDSA?
The HTB Certified Defensive Security Analyst (CDSA) is Hack The Box's intermediate, hands-on blue team certification. It tests whether you can investigate real attacks with SIEMs, logs, network traffic, and forensic artifacts, and then write them up in a professional security incident report.
You earn it by completing the SOC Analyst Job-Role Path (15 modules, 167 sections, rated Medium) and then passing the exam. You have to finish 100% of the path before the exam unlocks.
The exam
The CDSA exam runs for 7 days in a dedicated lab over VPN. You get a letter of engagement and investigate two security incidents, one in Splunk and one in Elastic, submitting flags for the first. HTB's exam report template sets the pass mark at 85 points (17 of 20 flags) on Incident 1, plus a commercial-grade report covering both incidents.
The report is due within the same 7 days. It has to be a commercial-grade security incident report in English, with an executive summary and a thorough technical analysis for each incident that covers every kill chain stage, uploaded as a PDF or ZIP of 20 MB or less. Submitting it ends your lab access. You get 2 attempts per voucher. The free retake has to start within 14 days of your feedback, and you only get it if you submitted a report the first time. Results arrive within 20 business days.
The 15 modules in order
- Incident Handling & SIEM: Incident Handling Process · Security Monitoring & SIEM Fundamentals
- Logs, Hunting & Splunk: Windows Event Logs & Finding Evil · Introduction to Threat Hunting & Hunting With Elastic · Understanding Log Sources & Investigating with Splunk
- Windows Attacks & Defense: Windows Attacks & Defense
- Network Traffic & IDS: Intro to Network Traffic Analysis · Intermediate Network Traffic Analysis · Working with IDS/IPS
- Malware & Detection Rules: Introduction to Malware Analysis · JavaScript Deobfuscation · YARA & Sigma for SOC Analysts
- Forensics & Splunk Detection: Introduction to Digital Forensics · Detecting Windows Attacks with Splunk
- Reporting & Exam Prep: Security Incident Reporting
Top tips from people who passed
- Investigate the incident, not the flags. Work out what happened from start to finish, and build a timeline of events from the first minute. (Jeffrey Bencteux, Jamie Dumas)
- The report decides the result. Flags alone won't pass, so write the report as you go and give the Incident 1 write-up real time before you start Incident 2. (Vladyslav Borodavka, Jeffrey Bencteux)
- Follow the Security Incident Reporting module. Model your report on its real-world sample and cover the executive summary, root cause, IoCs, and a technical timeline. (Yazeed Allabadi, W4tson)
- Save every query and screenshot. Keep a log of the SIEM searches that worked and screenshot everything important, since the report needs each step. (W4tson, Yazeed Allabadi)
- Practice on Sherlocks and BOTS. Work retired Sherlocks and Splunk BOTS data, and write at least one full practice report before the exam. (Yazeed Allabadi, Jamie Dumas)
The full list of tips is at the bottom of the Resource Library tab.
How to use this tracker
- Set your start date at the top. Every day's calendar date and your pace indicator are computed from it.
- Pick a timeline (30/40/50/55/60 days). They all cover the same curriculum, just packed into more or fewer days, and your progress carries across when you switch.
- Tick each task as you finish it. A day is marked complete when all its tasks are done.
- Use the Notes field on each day as a journal for queries that worked, event IDs, IoCs, and things to revisit.
- All progress is saved in your browser. Use Export backup regularly to keep a copy.
Build a timeline from the first minute of the exam and write the report as you investigate. Reviewers say flags alone won't pass. The incident report decides the result, so write a practice one on a Sherlock before you book the exam.
This is an independent study aid and is not affiliated with or endorsed by Hack The Box. Always confirm current module counts, exam format, and pricing on the official HTB Academy site.
Built on and inspired by mattrfield's coae-study-tracker.