Changelog

Follow up on the latest improvements and updates.

RSS

We are bringing 150+ investigation scenarios from the LetsDefend platform directly to HTB Labs. We are releasing them as 16 new retired Sherlocks every week from the end of August 2026 until October 15th. Each batch of Sherlocks will be free to play for a full month following its release date.
This gives blue teamers and defenders a steady stream of fresh, real-world analytical scenarios to investigate and solve.
Screenshot 2026-09-15 at 16
CTFs now earn you XP
Every CTF you play now contributes XP toward your HTB progression, reflected currently on your HTB Profile. Since CTFs are team efforts, XP is split among the participating team members.
Screenshot 2026-09-15 at 11
Introducing Streak Protocol
Streak Protocol is a new CTF mini-game built for quick, competitive knowledge testing.
Answer cybersecurity questions against the clock, build your streak, and compete with other players on the event leaderboard. The game is powered by 1,300+ questions generated from Marketplace content and is available on both desktop and mobile.
CTF Quiz

improved

new

Labs

Academy

Profile

Mobile

HTB Profile experience updates

We've just refreshed the HTB Profile experience to give you a cleaner, more streamlined way to showcase your cybersecurity achievements.
Updates include:
  • Removed all empty section spaces across public profiles for a cleaner layout.
  • Added embedded social sharing buttons to easily showcase your profile and HTB Academy Certifications pages to your networks.
  • Added a new activity Matrix to display your activity and consistency across the HTB Ecosystem.
Screenshot 2026-09-14 at 4
Your mission started in June..You joined Phoenix task force to save Earth. Now the final ACT begins, and you need to save the mission to Mars.
GNU Day is your first challenge.
Phoenix has intercepted a replacement uplink module destined for Zenium’s orbital ground segment. But before any command can reach Mars, it must pass Phoenix’s authority checks.
Analyze the uplink validation system, uncover weaknesses in its trust chain, bypass the authority controls, and recover the classified mission data before control of the Mars program changes hands.
Catch up on previous Operation Red Horizon scenarios
GNU Day
How far can you take a compromised Azure environment?
Altairus is an advanced Azure offensive lab built for experienced cloud security professionals and red teamers looking to push beyond the fundamentals of Entra ID, Azure RBAC, and hybrid identity.
Step into the environment of Omni Multinational, a global trade management company with a mature Azure footprint connected to its on-premises infrastructure. Starting with no credentials and no prior knowledge, you’ll need to uncover weaknesses in identities, applications, secrets, and trust relationships and turn small footholds into a full-scale compromise. Altairus challenges you to navigate the boundaries between cloud and on-premises infrastructure while putting advanced Azure attack techniques to the test.
Expect to tackle:
  • Azure enumeration
  • Authentication and credential abuse
  • Cloud application and serverless security
  • Secrets and data protection
  • Azure Automation and DevOps security
  • Active Directory privilege escalation and lateral movement
  • Exploitation of cloud misconfigurations
  • Phishing and social engineering
15 Flags. Advanced difficulty.
altairus changelog (1)

new

Enterprise

Offensive

Defensive

New Machine: Nemesis | Operation Red Horizon

The first Enterprise Season closes ACT II: Proxy Crown with Nemesis (Machine).
Arodor is days from launching its Mars rocket. Zenium wants it grounded and you're the one breaking into Arodor's machinery testing facility to compromise their OT controllers.
Nemesis is a Linux machine set in an assumed breach scenario, starting with access to a CCTV portal overlooking Arodor's Evaluation Compound. From there, you'll need to work through industrial control protocols, chain together an unexpected credential leak, and find your way to full control of the OT controller.
Catch up with the previous scenarios of Operation Red Horizon before the final ACT!
Nemesis (1)
Progress just got more rewarding. You can now earn experience points by completing content on HTB Enterprise, build weekly streaks, and reach new levels, ranks, and grades as you develop your skills. XP and Streaks connect your supported activity across the HTB ecosystem into one visible progression journey.
  • Earn
    experience points
    and watch your progress unlock new levels, ranks, and grades across HTB.
  • Build and maintain your
    streak
    by staying active each week, turning consistent practice into visible momentum.
Screenshot 2026-08-26 at 6
The first Enterprise Season continues the ACT II: Proxy Crown with a new Sherlock, Relay of Deceit.
This time, the focus shifts to the software supply chain. Hidden inside what appears to be a legitimate npm package is malicious code designed to evade review, perform host reconnaissance, and quietly exfiltrate sensitive data over DNS.
Players will practice how to:
  • Analyze npm packages safely without executing untrusted code
  • Uncover malicious behavior hidden in JavaScript
  • Investigate covert DNS-based communication
  • Reconstruct attacker activity from network traffic
  • Assess the impact of a software supply-chain compromise
Relay of Deceit
CTF admins can now access scenario writeups directly from the Content Library while building an event. Instead of selecting challenges based only on titles, descriptions, and difficulty, admins can review the intended solution path before adding content, making it easier to understand what each challenge tests and whether it fits the event's goals.
Choose challenges with more confidence and match content to your goals by validating that each challenge tests the right skills for your audience and training objectives.
Screenshot 2026-08-19 at 6
HTB's first Enterprise Season enters its next phase.
Your search for Arodor's proxy network now leads into a compromised settlement environment, where exposed identities and excessive cloud permissions hide a chained privilege-escalation path.
Take on Silent Market Raid, a new AWS Challenge where you'll enumerate cloud resources, abuse IAM trust relationships, and uncover how seemingly harmless disclosures can lead to complete compromise.
Continue the mission and begin Act II: Proxy Crown.
___________________________________
Need to catch up?
Complete the scenarios from Act I: Gridfall Signals.
Silent Market Raid
Load More