HackTheBox Academy + Certifications
HackTheBox Academy + Certifications
com/en/articles/5720974-academy-subscriptions
Access-based subscription models, such as the Silver Annual or Student plans, grant you access
to all Modules up to a certain tier for as long as you have the subscription. In the case of the
Silver Annual and Student Plans, this would mean you'd have access to all Modules up to and
including Tier 2 for as long as the plan was active.
If you complete a Module with an access-based subscription, you will still have the ability to go
back and review that module, even after your plan ends. Additionally, you are still rewarded
Cubes when you complete Modules with an access-based subscription.
Yearly Plans
Silver Annual
Price: $490/year (USD)
Access Based
• Direct access to all modules up to (including) Tier II
• Direct access to the entire Bug Bounty Hunter job role path
• Direct access to the entire Penetration Tester job role path
• Direct access to the entire SOC Analyst job role path
• Step-by-step Module Solutions
• Unlimited Pwnbox usage
• CPE credits submission
Bonus Benefits:
One exam voucher per year (expires when the subscription does)
Written by Diablo
Updated over a week ago
The Academy role paths will prepare you for one of these Four Certification Exams:
• HTB Certified Penetration Testing Specialist (HTB CPTS)
A highly hands-on certification that assesses the candidates’ penetration testing skills. HTB CPTS
certification holders will possess technical competency in the ethical hacking and penetration
testing domains at an intermediate level. They will also be able to assess the risk at which an
infrastructure is exposed and compose a commercial-grade as well as actionable report.
• HTB Certified Bug Bounty Hunter(HTB CBBH)
The HTB CBBH certification evaluates individuals' proficiency in bug bounty hunting and web
application penetration testing. Those holding this certification will demonstrate intermediate-
level technical competence in these domains. Additionally, they will have the ability to evaluate
the risk exposure of web applications, services, or APIs and generate both commercial-grade
and actionable reports.
• HTB Certified Defensive Security Analyst (HTB CDSA)
Professionals with HTB CDSA certification demonstrate proficiency in security analysis, SOC
operations, and incident handling. At an intermediate level, they exhibit technical competence
in these domains, enabling them to identify security incidents and recognize detection
opportunities that may not be readily evident in the available data. These individuals excel in
thinking creatively, connecting diverse data points, persistently exploring different angles to
assess the full impact of an incident, and producing effective security incident reports.
• The HTB Certified Web Exploitation Expert (HTB CWEE) focuses on building a mindset
around risk mitigation and vulnerability identification, using various advanced and
modern vulnerabilities as demos. This approach not only helps in identifying all of the
covered vulnerabilities in the path but also others that are based on the same concepts
or attack principles.
Subscription
To unlock the desired role path, check the Academy Subscriptions for available options and their
perks. If you want to take an exam, consider getting an Annual subscription, which provides
access to all modules up to a certain tier (depending on the subscription) and includes an exam
voucher. Alternatively, you can opt for a Monthly subscription, where you'll need to unlock each
module individually and purchase the voucher separately.
To be eligible to sit for an exam, you must achieve 100% completion in the chosen role path and
have an exam voucher.
Once you click the button you will get the following to confirm "By entering the exam one (1)
attempt will be consumed. You will have X days to complete the exam and upload the report."
Ensure you start your exams at least 2 months (60 days) before your subscription or voucher
expires. You'll need 7-10 days for the exam and 20 business days for the review of each
attempt. Both attempts must be completed before your subscription expires.
Connecting to the Exam VPN
Once you start the exam the timer will start counting towards the 7 or 10 days depending on
the exam, to connect to the VPN you can use either the Pwnbox or the VPN file, NOT BOTH at
the same time.
Using the Pwnbox
To spawn an instance of the Pwnbox you can choose the VPN server and the region and click
Spawn Desktop, this will give you an instance that you can use to work on the exam.
Using the VPN file
The same steps apply for the VPN file, Select the VPN server with the least load and the
recommended one and download the file.
You can find more information on troubleshooting VPN connections in this article:
VPN Connection Troubleshooting
Taking the Exam
Once you are connected to the VPN you can start the exam instance, it will spawn on the VPN
server you chose and will give back an entry point, this will be your first step into the exam and
it will show on the top right panel.
You can reset or stop the instance at any time and you can add more time to it once it drops
below 100 Minutes(1H:40M).
• CPTS, CBBH, and CDSA require a PDF or ZIP (with no password and a maximum size of
20MB)
• For CWEE the report needs to be in Markdown and zipped using the password as
instructed in the exam. (maximum size of 20MB)
• We don't accept any reports outside the exam platform
In case of failure to get the needed points you will still need to submit a report in order to get a
second attempt. You won't be eligible for a second attempt if you did not submit a report for
the first one.
Getting the results
The review process takes up to 20 business days and the results will be sent to you via email, In
case you fail the first attempt you can start a second attempt right away and use the feedback to
improve.
You have 14 days to start the second attempt from the day you get the feedback. In case you
don't you will lose the second attempt.