What is the HTB CPTS?
The HTB Certified Penetration Testing Specialist (CPTS) is Hack The Box's hands-on, intermediate penetration-testing certification. It tests the skills you use across a real engagement: reconnaissance and enumeration, exploitation, Active Directory attacks, lateral movement, privilege escalation, and writing the report.
You earn it by completing the Penetration Tester Job-Role Path (28 modules, 495 sections, rated Medium) and then passing the exam. HTB estimates the path takes about 42 days at 8 hrs/day (~338 hours), and you have to finish 100% of it before you can sit.
The exam
The CPTS exam is a 10-day practical engagement against a black-box, enterprise-like Active Directory network: you gain an external foothold, pivot internally, move laterally, and work toward Domain Admin across multiple Windows and Linux hosts. There are 14 flags, and roughly 12 (~85%) are needed. Flags alone do not pass you, though.
A commercial-grade penetration test report is a hard pass/fail gate: passers routinely submit 100–150 pages with an executive summary, full attack narrative, and individual findings rated by CVSS. You get 2 attempts per voucher (valid one year).
The 28 modules in order
- Foundations & Process: Penetration Testing Process · Getting Started
- Recon & Enumeration: Network Enumeration with Nmap · Footprinting · Information Gathering - Web Edition · Vulnerability Assessment
- Exploitation Fundamentals: File Transfers · Shells & Payloads · Using the Metasploit Framework
- Credential & Service Attacks: Password Attacks · Attacking Common Services
- Pivoting & Active Directory: Pivoting, Tunneling, and Port Forwarding · Active Directory Enumeration & Attacks
- Web Application Attacks: Using Web Proxies · Attacking Web Applications with Ffuf · Login Brute Forcing · SQL Injection Fundamentals · SQLMap Essentials · Cross-Site Scripting (XSS) · File Inclusion · File Upload Attacks · Command Injections · Web Attacks · Attacking Common Applications
- Privilege Escalation: Linux Privilege Escalation · Windows Privilege Escalation
- Reporting & Exam Prep: Documentation & Reporting · Attacking Enterprise Networks
Top tips from people who passed
- Report as you go. Fill in report sections as things happen, like compromising a host, and keep a separate attack-chain document. (BRM, r3zz)
- Work from checklists. Write your methodology so you could follow it blindly, and enumerate before you exploit, every time. (BRM, CertCrush)
- Learn Ligolo-ng before exam day. It makes pivoting much simpler, and you don't want to be learning it mid-exam. (RadiantSec, Cesar Guillen)
- Keep BloodHound open from your first foothold. Use NetExec to see right away where new credentials work. (RadiantSec)
- Protect your report time. Plan 6-7 days of hacking and 3-4 days of writing, and run AEN blind beforehand to gauge readiness. (CertCrush, BRM)
The full list of tips is at the bottom of the Resource Library tab.
How to use this tracker
- Set your start date at the top. Every day's calendar date and your pace indicator are computed from it.
- Pick a timeline (65/80/105/145/150 days). They all cover the same curriculum, just packed into more or fewer days, and your progress carries across when you switch.
- Tick each task as you finish it. A day is marked complete when all its tasks are done.
- Use the Notes field on each day as a journal for commands that worked, credentials you found, and things to revisit.
- All progress is saved in your browser. Use Export backup regularly to keep a copy.
Report as you go, and don't skip modules. The exam leans hard on Active Directory and tends to find every gap. Build a field manual as you study, do every skills assessment, and treat "Attacking Enterprise Networks" as a blind dress rehearsal. Depth and method matter more than speed.
This is an independent study aid and is not affiliated with or endorsed by Hack The Box. Always confirm current module counts, exam format, and pricing on the official HTB Academy site.
Built on and inspired by mattrfield's coae-study-tracker.