Changelog

Follow up on the latest improvements and updates.

RSS

Following the acquisition of LetsDefend, we have massively expanded your defensive security training.
You can now develop and validate defensive capabilities through a broader combination of structured learning paths, hands-on investigations, and realistic SOC simulations across every stage of the cyber workforce journey.
  • Access 232+ Blue Team modules, representing a 632% expansion in defensive learning
  • Investigate with 127 new Sherlocks (70% more investigation scenarios)
  • Build skills across eight Blue Team job roles, with new and expanded coverage in Cloud Security, DFIR, Malware Analysis, Detection Engineering, and ICS.
Lets Defende Academy Releases - 1080x1350 (1)
CertForge is a compromised small company following a public WingFTP foothold.
The incident response team faces a critical security challenge after alerts reveal signs of a coordinated intrusion across public-facing Linux services and the internal Windows domain. They must quickly determine which events represent genuine attacker activity and which are expected administrator or deployment actions.
Your team must defend CertForge by:
  • Triaging alerts and separating genuine compromise from routine administrator and deployment activity
  • Reconstructing the attack chain from the public-facing WEB01 server into the internal Active Directory environment
  • Investigating suspicious Linux, Jenkins, Windows, certificate services, and SMB activity
  • Detecting AD CS ESC1 abuse and unauthorized Administrator access to DC01
  • Identifying credential dumping, DCSync activity, persistence, and sensitive file collection
  • Assessing the impact across compromised systems and escalating high-confidence findings
TdnZDJTJkS4txiDmzVrY5eg7WfRPDTxZUBogv8kN
Defensive players can now level up and maintain active streaks through HTB Labs. We have integrated our Sherlocks defensive investigations into the HTB XP and streaks ecosystem.
What changed:
  • Users now earn XP for every individual task solved within a Sherlock.
  • Completing an entire Sherlock grants an additional XP bonus.
  • All earned XP counts directly toward weekly XP goals and active streaks.
This update rewards incremental learning and provides defensive players with more ways to maintain their platform progression. For a full breakdown of how points and streaks accumulate, read our HTB XP system documentation.

new

Enterprise

Offensive

Defensive

New in Operation Red Horizon: PolarPlunder

The mission continues with a Sherlock.
Following the events of Safety Off (Challenge), Team Phoenix has intercepted new intelligence linked to FrostyGoop, a real-world ICS malware used to manipulate industrial systems through Modbus commands.
What will you learn?
  • Navigate MITRE ATT&CK for ICS to connect adversary techniques, software, assets, detection strategies, and mitigations.
  • Correlate ATT&CK data with vendor threat reports to build a coherent intelligence profile of FrostyGoop/BUSTLEBERM.
  • Explain how Modbus TCP commands can read and modify PLC holding registers, creating potential physical impact in OT environments.
  • Extract and interpret technical intelligence, including malware hashes, dependencies, YARA indicators, Golang binaries, anti-debugging checks, and encryption methods.
Polar Plunder

new

Enterprise

Capture The Flag

Features

Defensive

Threat Range

Threat Range scenarios mapped to Academy modules

This update gives organizations a practical way to support players before and after a Threat Range experience by combining hands-on scenarios with structured learning content.
Admins can use the new Content pane to view the Academy modules related to each Threat Range scenario, and assign this content to their teams' Spaces within HTB Enterprise Platform
Where is this relevant?:
  • Before the scenario, to build the knowledge needed to prepare.
  • After the scenario, to reinforce key concepts and continue developing relevant skills.
  • As part of a broader learning path that connects my team members' individual training with assessments and team simulations.
AcademyModules-ezgif

new

Enterprise

Offensive

Defensive

Operation Red Horizon has began!

HTB's first Enterprise Season is live!
Widespread power outages are being dismissed as routine failures…but the evidence suggests something far more coordinated.
Join a three-month cyber operation where each month’s Challenge, Sherlock, and Machine reveal the next chapter of the story.
Read the announcement to discover how HTB Enterprise Seasons work, meet the key players, and see what awaits you > http://bit.ly/44S49gx
SOC Range is now available on HTB Enterprise Platform for all Enterprise Workforce Development plans.
SOC Range brings process-driven defensive training into a realistic SOC workflow, giving analysts a simulated alert queue where they can claim investigations, triage incoming alerts, identify false positives, navigate SIEM-like tooling, and execute guided playbooks.
  • Manage active alert queues, personal investigations, and closed cases through Alert Backlog and My Investigations.
  • Use integrated SOC tooling for log analysis, endpoint containment, mailbox remediation, and threat intel or sandbox review.
  • Build operational readiness through guided, alert-specific playbooks, artifact documentation, analyst notes, and automatic report generation.
Spaces just got a big makeover.
The (new) Spaces are introducing a unified structure for organizing and delivering enterprise training content. They now support mixed content types in a single learning path, allowing admins to combine Academy Modules, Machines, Challenges, and Sherlocks instead of managing separate Spaces by content type.
Now you can:
  • Combine theory and hands-on practice into one structured training path
  • Use Public Spaces for organization-wide training or Private Spaces for invite-only programs, assessments, and mission-readiness drills
  • Manage visibility separately from license access, with platform-level progress tracking across Spaces
  • Access a dedicated leaderboard and progress metrics based on wholistic knowledge domain completion
This update reduces duplicate setup and learner context switching by moving training organization from content silos to mission-based Spaces.
Spaces2-ezgif
We have launched two new preparation tracks on HTB Labs to help you prepare for the HTB Certified Junior Cybersecurity Associate (HTB CJCA) and Certified Active Directory Pentesting Expert (HTB CAPE) examinations of HTB Academy. These tracks are designed to reinforce the practical skills taught in their respective job-role paths through targeted, hands-on environments.
HTB CJCA Preparation Track
This track helps you practice the core hands-on skills required for the HTB CJCA exam. You will face focused Machines that cover enumeration, exploitation, privilege escalation, and basic security analysis.
HTB CAPE Preparation Track
Built for advanced learners preparing for the HTB CAPE exam, this track features complex Active Directory labs. You will test your skills in advanced enumeration, lateral movement, privilege escalation, and full domain compromise.
Finding what you need in a write-up just got easier.
Professional Lab and Cloud Lab write-ups are now available as downloadable PDFs, making it simpler to search, navigate, and reference scenario walkthroughs as you work.
You can download them directly from the Write-ups button in the Details section.
writeup_pdf_download
Load More