Changelog
Follow up on the latest improvements and updates.
RSS
new
Academy
Enterprise
Offensive
Advance your Wi‑Fi pentesting skills with two new Academy Modules
The
Wi-Fi Penetration Testing Tools and Techniques
module introduces you to a range of Wi-Fi pentesting tools, each selected to demonstrate techniques suited for different environments and stages of an engagement. You’ll have the opportunity to work through practical examples that feature the wide variety of technologies, protocols, and security configurations encountered in the field, allowing you to gain hands-on experience in choosing and applying the right tools for your engagement.Key learning outcomes:
- How to conduct reconnaissance with Airodump-ng, Kismet, LinSSID, WifiDB, and Sparrow WiFi
- Using tools such as WiGLE to conduct Open Source Intelligence
- In-depth understanding of automated attack frameworks such as H4rpy, Wifite2, and Fern WiFi Cracker
- How to gather and crack passwords using Pyrit, Aircrack-ng, and Pmkidcracker

The
Attacking Corporate Wi-Fi Networks
module incorporates a simulated Wi-Fi penetration test from start to finish, emphasizing hands-on techniques that reflect real-world engagements. It involves conducting scoped reconnaissance, assessing wireless configurations, and evaluating common attack surfaces across WPA2, WPA3, and Enterprise deployments. The environment culminates in a demonstration of internal network pivoting, including Active Directory access, all performed within a controlled, simulated environment and in adherence to strict legal and ethical boundaries.Key learning outcomes:
- Reviewing rules of engagement and scope to prepare for authorized Wi‑Fi assessments
- How to conduct reconnaissance, abuse guest networks, and compromise WPA2, WPA3, and Enterprise Wi‑Fi environments
- Skills for executing advanced attacks, including Karma, Mana, router exploitation, and internal pivots
- Understanding how how to enumerate Active Directory, escalate privileges, move laterally, and compromise the domain

new
Academy
Enterprise
Offensive
Introducing the Wi-Fi Penetration Tester Job Role Path
The Wi-Fi Penetration Tester Job Role Path is built for professionals and aspiring security practitioners ready to master the art of assessing and securing corporate wireless networks.
Included in this path are 10 hands-on modules that put you in the attacker’s seat evaluating Wi-Fi security, breaking modern authentication and encryption protocols, and simulating real-world threats like rogue access points, man-in-the-middle attacks, and credential harvesting.
As you progress through the material, you’ll gain practical experience with industry-standard methodologies while learning how to pinpoint vulnerabilities, exploit misconfigurations, and deliver impactful countermeasures.
Upon completing the Path, you'll have the skills and confidence to perform authorized Wi-Fi penetration tests and strengthen the wireless security posture of enterprise corporate environments.

new
Enterprise
Offensive
Defensive
New Exclusive content available on Dedicated Labs
New exclusive content has been released on Dedicated Labs which features WSUS vulnerabilities in enterprise environments as well as HTB's first Sherlock that allows players to experience the full remediation process.
CyrptidCode | Exclusive Sherlock
In this Sherlock players will utilize logs to track the exploitation of a website and then work through the full remediation process on the site to fix the vulnerabilities.

Suspect | Exclusive Machine
This Very Easy Machine demonstrates CVE-2025-59287, a critical unauthenticated remote code execution vulnerability affecting Microsoft Windows Server Update Services (WSUS).

new
Labs
Enterprise
Defensive
HTB Certified Defensive Security Analyst (CDSA) Preparation track
The HTB Certified Defensive Security Analyst (CDSA) Preparation track equips you to build real-world defensive expertise through 11 engaging, hands-on scenarios spanning from Very Easy to Hard.
Every scenario is crafted to sharpen the core skills and methodologies you’ll need to succeed in the HTB Certified Defensive Security Analyst exam, from security analysis and SOC operations to incident handling.
As you progress through realistic environments and practical challenges, you’ll develop not only full exam readiness but also the confidence and capability to detect, analyze, and respond to security incidents with precision.

improved
Enterprise
Features
Experience streamlined Skills & Frameworks reporting
HTB Enterprise Platform admins are now able to report on skills mapped to key industry frameworks more quickly and easily than ever before.
With this release, HTB Skills have been separated from NIST/NICE and MITRE ATT&CK using a new secondary picker. Now, when you select a framework, you’ll only see the data that’s truly relevant to it.
This update gives you:
- A cleaner, more accurate view of how team training aligns with each framework
- A clearer separation between HTB’s internal skill taxonomy and industry standards
- Easier reporting conversations
In addition, admins will now see an “Express Interest” option on the Reporting page which can be used to tell us which frameworks you want to see full-scale coverage for to help us prioritize what to work on next!

new
Academy
Enterprise
Defensive
Conduct digital forensics on Linux systems with new Academy Module
The
Introduction to Linux Forensics
module covers techniques for conducting digital forensics on Linux systems prevalent in enterprise servers and cloud infrastructures. This includes an in-depth overview of the steps included in the forensics process, what scenarios require an investigation, becoming familiar with open-source and command-line tools, what types of artifacts are examined, and how to create a detailed timeline.Key learning outcomes include:
- In-depth understanding of digital forensics principles and maintaining chain of custody for Linux systems
- How to locate and collect key Linux artifacts such as /var/log, bash history, cron jobs, and filesystem MACb timestamps
- Practical skills development using Systemd Journal, Auditd, Sysmon for Linux, AVML, and Volatility 3 to avoid tampering with evidence
- Deeper understanding of how to document and present forensic findings in a clear, reproducible, and legally defensible format


Thinking about testing new skills before your next hands-on engagement or certification? Of course you are. Good news: Hack The Box (HTB) has reloaded our stock of Pro Labs with new scenarios to build confidence in your ability to succeed, and with a big discount for the annual plan running until the end of November.
Get access to 26+ Pro Labs and 25% discount on the annual plan using this code on checkout:
NOVPROLABSANNUAL25OFF
. Offer valid until 30 November 2025, 23:59 EET.
If you are interested in knowing more about Pro Labs and the new additions, read all about it here →

Kickstart your certification journey with the Silver Annual subscription on HTB Academy. Now, we're including an extra HTB CJCA exam voucher, so you can learn the basics of cybersecurity and then proceed to the certification of your choice!
This extra voucher is also available on the Gold Annual plan.
The HTB CJCA certification was designed to help beginners break into cybersecurity with practical, hands-on training. By including it in our annual plans, we’re making it easier to go from zero to pro, all within Hack The Box.
Now, one annual subscription supports your entire certification path:
- Kickstart your journey with HTB CJCA
- Climb higher with our core and specialized certifications
It’s more value, more progress, and more recognition, all rolled into your HTB plan.
P.S. If you bought your Silver or Gold Annual subscription recently, don't worry! We are also adding this extra voucher for annual plan purchases after September 1, 2025.
improved
Labs
Features
Discover relevant Labs faster than ever
Exploring Labs just got a lot easier!
Our new improved search functionality helps you find what you’re looking for based on content relevance, not just content names. Now, if you type Active Directory, you’ll instantly see all related challenges and machines rather than guessing and scrolling to find what you were looking for.
This update makes it easier to:
- Discover new content connected to your learning goals
- Quickly find Labs aligned to specific topics or frameworks
- Spend less time searching and more time playing

new
Capture The Flag
Offensive
Defensive
Build your forensics and blockchain skills with two new CTF packs
Two new CTF packs have just dropped, designed to build hands-on expertise in forensics and blockchain.
Cyber Defense Analyst – Essentials
Featuring nine new challenges (with one more coming soon!) for entry-level cyber defense analysts, this pack includes a diverse set of forensics challenges designed to emulate real-world attack scenarios across network, memory, and host-based evidence. Players will investigate complex, multi-stage intrusions ranging from CVE exploitation and phishing to memory-based evasions and malware persistence.
Blockchain Essentials
Complete with 10 challenges built for entry-level penetration testers and security-minded developers, this pack introduces players to the fundamentals of Ethereum smart contracts, transaction mechanics, and on-chain investigation through a progression of realistic, hands-on challenges. From basic account and RPC interaction to reading contract storage and interacting with deployed contracts, participants will learn how blockchain primitives and common Solidity patterns work in practice and how insecure designs can be abused.


Load More
→