Changelog

Follow up on the latest improvements and updates.

RSS

improved

Capture The Flag

Defensive

Threat Range

Configurable SLAs & Dispatch pacing for Threat Range events

Threat Range events are now more flexible.
Admins and Event managers can now customize alert dispatch pacing and response-time SLAs, making it easier to tailor exercises to different team skill levels, operational workflows, and event durations.
What's new?
  • Configure how quickly alerts are dispatched throughout an event.
  • Customize response-time SLAs for both alerts and tickets.
Use HTB's recommended defaults or align timings with your organization's internal SLAs and operating procedures.
threat range
AI models do not operate in isolation. An agent consists of the model paired with host-side code that validates tool proposals, communicates with external systems, and controls when the execution loop terminates. Relying strictly on system prompts for security leaves systemic vulnerabilities that attackers can exploit.
In this new Medium-difficulty module available on HTB Academy and HTB Enterprise, you will construct that host-side orchestration code yourself. You will learn how to enforce safety decisions there, not in the prompt.
1200x630 - AI Literacy - Agents
Administrators can now control the sequence of content assigned to a Space, making it easier to build structured workforce development programs that guide learners through deliberate, role-aligned skills journeys.
From the Space’s Content tab, open Assigned Content. Enter
Reorder
mode to drag and drop content cards or update their numeric position fields, then make sure to Save your order selection.
Create deliberate learning paths across modules, challenges, labs, and Sherlocks.
Untitled (Sat Jul 25 2026) (2)
We integrated 191 modules from LetsDefend into the HTB Academy library to expand our defensive and foundational cybersecurity curriculum. This launch increases HTB Academy's defensive content by more than 500%, making comprehensive blue team skills accessible under Tier 0 and Tier 1 access.
Key Updates:
  • 191 Modules Added: Includes 16 Tier 0 modules and 175 Tier 1 modules (166 defensive and 25 general security modules).
  • 3 New Skill Paths: Added dedicated paths for CompTIA Security+ Preparation, Programming for Cybersecurity, and Google Cybersecurity Certificate Preparation.
  • New Badges: We've also included new content completion badges for these modules to make sure all your effort is recognized.
  • Subscription Integration: All new content is made accessible through standard HTB Academy subscription plans without requiring separate add-on subscriptions.

new

Enterprise

Offensive

Defensive

Operation Red Horizon continues with Zeek

A compromised mission operations environment has exposed weaknesses across cloud infrastructure, application security, and containerized workloads.
Deploy into Zeek, a new Linux Machine where you'll enumerate AWS resources, investigate LocalStack services, exploit a vulnerable Lambda function, and pivot from cloud access to full host compromise through Docker.
Continue Act I: Gridfall Signals and uncover the next piece of Arodor's campaign.
Zeek
Following the acquisition of LetsDefend, we have massively expanded your defensive security training.
You can now develop and validate defensive capabilities through a broader combination of structured learning paths, hands-on investigations, and realistic SOC simulations across every stage of the cyber workforce journey.
  • Access 232+ Blue Team modules, representing a 632% expansion in defensive learning
  • Investigate with 127 new Sherlocks (70% more investigation scenarios)
  • Build skills across eight Blue Team job roles, with new and expanded coverage in Cloud Security, DFIR, Malware Analysis, Detection Engineering, and ICS.
Lets Defende Academy Releases - 1080x1350 (1)
CertForge is a compromised small company following a public WingFTP foothold.
The incident response team faces a critical security challenge after alerts reveal signs of a coordinated intrusion across public-facing Linux services and the internal Windows domain. They must quickly determine which events represent genuine attacker activity and which are expected administrator or deployment actions.
Your team must defend CertForge by:
  • Triaging alerts and separating genuine compromise from routine administrator and deployment activity
  • Reconstructing the attack chain from the public-facing WEB01 server into the internal Active Directory environment
  • Investigating suspicious Linux, Jenkins, Windows, certificate services, and SMB activity
  • Detecting AD CS ESC1 abuse and unauthorized Administrator access to DC01
  • Identifying credential dumping, DCSync activity, persistence, and sensitive file collection
  • Assessing the impact across compromised systems and escalating high-confidence findings
TdnZDJTJkS4txiDmzVrY5eg7WfRPDTxZUBogv8kN
Defensive players can now level up and maintain active streaks through HTB Labs. We have integrated our Sherlocks defensive investigations into the HTB XP and streaks ecosystem.
What changed:
  • Users now earn XP for every individual task solved within a Sherlock.
  • Completing an entire Sherlock grants an additional XP bonus.
  • All earned XP counts directly toward weekly XP goals and active streaks.
This update rewards incremental learning and provides defensive players with more ways to maintain their platform progression. For a full breakdown of how points and streaks accumulate, read our HTB XP system documentation.

new

Enterprise

Offensive

Defensive

New in Operation Red Horizon: PolarPlunder

The mission continues with a Sherlock.
Following the events of Safety Off (Challenge), Team Phoenix has intercepted new intelligence linked to FrostyGoop, a real-world ICS malware used to manipulate industrial systems through Modbus commands.
What will you learn?
  • Navigate MITRE ATT&CK for ICS to connect adversary techniques, software, assets, detection strategies, and mitigations.
  • Correlate ATT&CK data with vendor threat reports to build a coherent intelligence profile of FrostyGoop/BUSTLEBERM.
  • Explain how Modbus TCP commands can read and modify PLC holding registers, creating potential physical impact in OT environments.
  • Extract and interpret technical intelligence, including malware hashes, dependencies, YARA indicators, Golang binaries, anti-debugging checks, and encryption methods.
Polar Plunder

new

Enterprise

Capture The Flag

Features

Defensive

Threat Range

Threat Range scenarios mapped to Academy modules

This update gives organizations a practical way to support players before and after a Threat Range experience by combining hands-on scenarios with structured learning content.
Admins can use the new Content pane to view the Academy modules related to each Threat Range scenario, and assign this content to their teams' Spaces within HTB Enterprise Platform
Where is this relevant?:
  • Before the scenario, to build the knowledge needed to prepare.
  • After the scenario, to reinforce key concepts and continue developing relevant skills.
  • As part of a broader learning path that connects my team members' individual training with assessments and team simulations.
AcademyModules-ezgif
Load More