Changelog

Follow up on the latest improvements and updates.

RSS

We have launched a new medium-difficulty defensive module, Introduction to Detection Engineering, on Hack The Box (HTB) Academy. This module introduces the foundational and advanced concepts required to think and operate like a modern detection engineer.
The sections explain how attackers operate within Windows environments and how operating system telemetry exposes those specific behaviors. Through hands-on tasks, you will simulate real-world attack techniques and design functional detection queries to convert raw telemetry into actionable alerts.
Introduction to Detection Engineering

new

Academy

Enterprise

Offensive

Introducing the new Red Team Mindset module

We have released a new medium-difficulty module on HTB Academy, designed to introduce you to the operational and strategic realities of adversary simulation. The Red Team Mindset module covers the foundational concepts of red teaming, explaining how these engagements differ from traditional penetration testing and how they are executed from kickoff to completion.
You will explore the specific roles and responsibilities of red, blue, and white teams during an engagement. The course also addresses critical ethical boundaries, communication protocols with stakeholders, and how artificial intelligence is shifting the landscape of modern adversary simulation.
1200x630 - Red Team Mindset
We have introduced XP and Activity Streaks directly to the HTB Profile. This update allows you to highlight your continuous learning and hands-on skills to the community and potential employers.
Screenshot 2026-05-18 at 10
Hack The Box (HTB) Academy and Enterprise users undertaking certificate exams can now select Australian VPN servers for their connection. This infrastructure update reduces latency and provides a significantly smoother exam-taking experience for users based in the APAC region, across both individual and enterprise plans.
This new module delivers an in-depth, defense-focused study of Windows credential access. It explains how adversaries steal credentials via dumping and abuse of sensitive stores, then breaks down authentication flows, cryptographic protections, and both live-memory and offline extraction to understand tool behavior and build robust detection rules. It also covers DPAPI, Windows Credential Manager, browser credential stores, including App-Bound encryption, and Credential Guard bypass techniques with their detection opportunities.
a0f5fb40-8904-4719-9944-e89d46a4dc23-1777999911 (1)

new

Labs

Academy

Profile

Account

Badges are now part of your HTB Profile

Your HTB Profile now includes an automated Badges showcase that highlights your achievements across HTB Labs and Academy. Clicking any badge reveals the full artwork, completion criteria, and global rarity statistics. This update helps you track your total progress and provides a public-facing snapshot of your milestones.
image
We have successfully rolled out HTB XP, a cumulative points system that tracks lifetime growth across the entire HTB Labs and Academy platforms.
Key Updates:
Cumulative XP:
XP is now awarded for Machines, Challenges, Academy Modules and Paths. This score is non-deductible and reflects your lifetime activity. More content integration is coming soon.
1.3x Active Labs Multiplier:
Completing Active Labs now grants an automatic 1.3x XP bonus.
New and Expanded Rank Grades:
Climb through 7 new ranks and 3 sub-grades, and more than 100 levels for more frequent rewards, all the way to Grandmaster.
Weekly Streaks:
A streak advances when 200 XP is earned within a calendar week (Monday 00:00:00 UTC to Sunday 23:59:59 UTC).
Streak Savers:
Labs VIP/VIP+ (Monthly and Annual) and Academy Annual subscribers now automatically receive Streak Savers every month (Max 3 held at once).
Blog Visual 1 - HTB COAE (1)
The HTB COAE is a professional certification designed to validate advanced skills in AI red teaming and is now available on HTB Academy and HTB Enterprise plans. It serves as the final assessment for the AI Red Teamer Job-Role Path, which was developed in collaboration with Google.
The certification consists of a 7-day practical engagement where candidates must assess a complex AI-driven infrastructure. The exam evaluates proficiency in adversarial ML, LLM output exploitation, and AI system security. A commercial-grade technical report is required for successful completion.
If you are an individual, you can access the full path and the HTB COAE exam through our Silver Annual subscription on HTB Academy.
For those of you hacking as part of a team, the certification and its accompanying path are available for all Grow and Scale plans on the HTB Enterprise Platform. Want to explore the right plan for your team? Book a demo with us here.
A new
defensive module
, Persistence Tradecraft Analysis, is now available on HTB Academy. This course provides an in-depth look at Windows persistence mechanisms, covering everything from their role in the attack lifecycle to detection and investigation.
Throughout this module, you will explore how adversaries abuse legitimate system features like Scheduled Tasks, Windows Services, and Registry-run keys to ensure that malicious code executes automatically. The content focuses on identifying system artifacts left behind by attackers and translating that knowledge into reliable, effective detection rules for real-world environments.
a0d535b9-23ac-4f3b-9f71-66b1b12432f0-1774287349 (1)

new

improved

Academy

Profile

Introducing public certificate pages

HTB Academy certificate holders now have access to dedicated, public-facing pages for every certification earned. These pages offer a professional, verifiable way to showcase your technical expertise to employers and the community.
How it works:
Users can access these pages directly through their HTB Profile. Clicking on any earned certificate credential takes you to that certificate's dedicated public page.
Key features include:
  • Unique public URL for every earned certification.
  • You can share it on LinkedIn and social media.
  • Verification to confirm the authenticity of your achievement.
image (20)
Load More