Changelog

Follow up on the latest improvements and updates.

RSS

This path is designed to help cybersecurity professionals prepare for the Google Cybersecurity Certificate and is now available on HTB Enterprise platform as part of the LetsDefend acquisition!
By completing this path, you'll gain the knowledge and hands-on experience needed to succeed in the Google Cybersecurity Certificate. Throughout the modules, you'll explore cybersecurity best practices, Linux and scripting fundamentals, threat and vulnerability management, and the use of SIEM technologies in modern security operations.
Modules included in this path are:
  • Network Packet Analysis
  • Incident Response on Windows
  • Incident Response on Linux
  • SOC Fundamentals
  • SIEM 101
  • Linux for Blue Team
  • Introduction to Cryptology
  • Network Log Analysis
  • Job Hunting
  • Network Fundamentals
  • Network Fundamentals II
  • Network Protocols
  • Security Solutions
  • Security Solutions -2
  • Cybersecurity Incident Handling Guide
  • Secure Network Design
  • Network Design and Security Products
  • Network Security
  • Bash Scripting for Blue Team
  • Introduction to Python
  • Python for Blue Team
  • Vulnerability Management
  • Security Audit and Testing
  • Introduction to Bash Scripting (LetsDefend)
Copy of Paths Templates - 1080x1350 (1)
We have introduced a range of AI-powered tools built to help you navigate complex cybersecurity content on HTB Academy.
Key updates:
HTB Coach.
Get contextual technical explanations, summaries, and quizzes based on the specific section you are currently reading.
Multilingual translation.
Dynamically translate module content into Hindi, Arabic, Spanish, French, Chinese, Greek, and Japanese while preserving the correct code blocks and commands.
This is our first step into AI-augmented learning, designed to reduce learning burnout and help you level up faster.
These features will soon also be live for HTB Enterprise teams.
Expand your training with a new exclusive Machine and Sherlock.
PandorasBox
| Exclusive Machine
Target an LLM-integrated system and train on modern attack techniques such as prompt injection and SSRF in this Medium difficulty Linux machine. Manipulate the LLM to access internal services, exploit a backup system for remote code execution, and escalate privileges through command injection in a system management script.
IncipientBreeze-3
| Exclusive Sherlock
Complete the IncipientBreeze investigation series by analyzing the TINYSHELL backdoor used by UNC3886. Apply what you learned on IncipientBreeze-1 & 2 to reverse the malware, decrypt the network traffic and uncover what the attacker did and if they exfiltrated any sensitive files.
Copy of HTB Enterprise Platform Content Releases Templates - 1080x1350
Three new CTF packs have landed, giving you the ability to assess your team’s skills across emerging AI threats, aerospace cyber operations, and industrial control system security.
  • OWASP Top 10 Agentic AI Security takes players through 10 realistic scenarios covering the latest OWASP Top 10 for Agentic Applications 2026 risks, including prompt injection, identity abuse, agent supply chain attacks, and unexpected code execution.
  • Integrated Air Defense challenges players to assess aviation control systems through realistic aerospace scenarios involving RF protocols, avionics buses, AFDX cross-domain controls, and surveillance systems.
  • ICS Security Essentials introduces the fundamentals of securing industrial environments, with scenarios covering industrial protocols, PLC security, OT network analysis, and common weaknesses across critical infrastructure.
Agentic AI_ ICS packs
We have launched a new medium-difficulty defensive module, Introduction to Detection Engineering, on Hack The Box (HTB) Academy. This module introduces the foundational and advanced concepts required to think and operate like a modern detection engineer.
The sections explain how attackers operate within Windows environments and how operating system telemetry exposes those specific behaviors. Through hands-on tasks, you will simulate real-world attack techniques and design functional detection queries to convert raw telemetry into actionable alerts.
Introduction to Detection Engineering

new

Academy

Enterprise

Offensive

Introducing the new Red Team Mindset module

We have released a new medium-difficulty module on HTB Academy, designed to introduce you to the operational and strategic realities of adversary simulation. The Red Team Mindset module covers the foundational concepts of red teaming, explaining how these engagements differ from traditional penetration testing and how they are executed from kickoff to completion.
You will explore the specific roles and responsibilities of red, blue, and white teams during an engagement. The course also addresses critical ethical boundaries, communication protocols with stakeholders, and how artificial intelligence is shifting the landscape of modern adversary simulation.
1200x630 - Red Team Mindset

new

Enterprise

Capture The Flag

Defensive

New Threat Range Scenario - Cash Credentials

Cash Credentials simulates a real-world breach that begins when an insider threat sells valid VPN credentials on an underground marketplace. Inspired by compromises attributed to the BlackSuit ransomware gang, this investigation challenges defenders to uncover subtle indicators of compromise, trace attacker activity across the environment, and respond before a ransomware deployment impacts the organization.
Together with your team, you will collaborate to:
  • Triage alerts
  • Investigate suspicious activity
  • Investigate forensic evidence
  • Identify the impact to your organization
By completing this scenario, you will gain hands-on experience investigating credential access techniques, tracking attacker movement through Active Directory environments, identifying data theft activity, and responding to a ransomware attack from initial access through impact.
z2GmC7G5xTTGgQPZ80ebNYhnlC5VbxGcW9wFyEAB
Within HTB Enterprise Platform, you can now preview and monitor Academy and Dedicated Lab Spaces' progress from a single page, making it easier to track training activity across multiple Spaces without relying on external reports or jumping into each Space to preview team activity.
With Space Reporting, you can now get an overview that helps identify which Spaces are progressing well and which may need attention. From there, you can drill down into user progress within a specific Space to review individual training status and spot users who may be falling behind.
Make sure to use the date parameters and search tab to narrow down your search. You can find this page within your reporting tab.
Screenshot 2026-05-27 at 1
New exclusive content has been released on Dedicated Labs featuring AI supply chain exploitation, malware analysis, identity governance abuse, and a new Satellite Challenges category.
Augment | Exclusive Machine
Augment is a medium-difficulty Linux machine centered around emerging AI application vulnerabilities, including RAG abuse and ML supply chain attacks. Exploit a poisoned vector database to achieve RCE through unsafe markdown processing before abusing a malicious GGUF model validator to escalate privileges and gain full root access.
IncipientBreeze-2 | Exclusive Sherlock
IncipientBreeze-2 continues the Medusa rootkit investigation series and challenges players to deepen their malware analysis and threat hunting capabilities. Using Elastic SIEM and forensic investigation techniques, you will analyze the Medusa rootkit’s behavior, persistence mechanisms, and operational footprint while building on concepts introduced in the first Sherlock of the series.
Ghost Claims | Exclusive Challenge
Ghost Claims explores weaknesses in identity governance and access management within an enterprise approval platform. Players must move beyond the limited public-facing portal to uncover hidden operator functionality, bypass restrictions, and access sensitive administrative capabilities.
New Satellite Category
A brand-new Challenge category has landed on HTB, blending cybersecurity with aerospace engineering. These challenges place you in realistic satellite incident response scenarios where precise calculations and problem-solving are critical to restoring mission operations and preventing catastrophic failures.
  • Elementary:
    Learn about the Cartesian to Keplerian conversion.
  • Impulsive Thoughts:
    Perform a 2D orbital maneuver from a GTO to GEO (Hohmann Transfer).
  • Not So Plane:
    Perform a 3D maneuver from GEO to IGSO (plane change).
  • Kicked Out:
    Perform a maneuver to escape Earth's velocity and reach a specific target, predicting the time of flight.
May 2026 Exclusive Content
May 2026 Exclusive Content
Threat Range Event Management is now available, introducing a self-service workflow for creating, hosting, and managing defensive cybersecurity simulations directly on the HTB platform.
This enables you to deploy on-demand SOC and DFIR simulations using the same streamlined workflow as standard CTF events.
Now you can:
  • Create and manage defensive simulation events directly from the HTB CTF platform.
  • Launch SOC and DFIR drills on demand through a familiar event workflow.
  • Reduce operational delays by eliminating dependency on external setup support.
Scheudleeventthreatrange-ezgif
Load More