HackTheBox Certified Penetration Testing Specialist (HTB CPTS) Guide and Review
Guide and my experience on HTB CPTS exam with tips
HackTheBox Certified Penetration Testing Specialist (HTB CPTS) Guide and Review

Introduction
Hello everyone, It's me, Chicken0248, again, and in this blog I’ll be talking about how to prepare for the CPTS exam from HackTheBox, the most popular professional cybersecurity certification from one of the most well-known cybersecurity platforms out there.
Coming from a blue team / DFIR background, this certification is not something to be taken lightly, as it requires a completely different set of skills. Without further ado, let’s jump right in.
Exam Preparation

In order to take the CPTS exam, you need to complete its job-role path first, which is the Penetration Tester path. It consists of 28 modules and will cost around 1,970 Cubes.
- 7 x Tier 0 = 70 Cube
- 4 x Tier I = 200 Cube
- 17 x Tier II = 1700 Cube
On top of that, upon completing all modules, you will get 450 Cubes back and approximately 70% completion progress on the Web Penetration Tester path.
Let me tell you, each module is no joke. They contain a wealth of information that is directly required for the exam itself, and on top of that, every single one of them gave me new ideas about possible attack surfaces and privilege escalation paths that may not be very well known to blue teamers.

Before diving into the exam preparation in detail and which modules to pay close attention to, let’s visit the exam page first to see the knowledge domains covered. To sum it up, the exam covers the following:
- Web application attacks
- Linux & Windows privilege escalation
- Active Directory attacks
- Pivoting & Lateral Movement
- Post-exploitation
And I can guarantee you, they did it justice. You will be tested thoroughly, and sometimes you will doubt yourself if you go into the exam unprepared.
Now let’s take a look at the path again, and here are the modules that I recommended spending your time on to understand every detail.
- **Footprinting** — In this module, you will learn how to enumerate many network protocols such as FTP, SMB, NFS, DNS, SMTP, SNMP, MySQL/MSSQL, and so on. which is very important foundation knowledge for penetration testing.
- **Information Gathering — Web Edition** — in this module, you will learn how to conduct web recon including DNS enumeration, web crawling, analysis of web archives and HTTP headers, and fingerprinting web technologies. a foundation of basic web pentest.
- **File Transfers** — In this module, you will learn various ways to transfer file between machines; you will definitely find a lot of useful techniques that you will utilize in the exam here.
- **Password Attacks **— In this module, you will learn the fundamentals of password attacks, from password cracking, spraying, and stuffing to password attacks for Windows, password attacks for Linux and this one is also important because, in order to achieve lateral movement or gain a foothold, getting a valid credential is required.
- **Attacking Common Services **— In this module, you will learn how to attack common services such as FTP, SMB, SQL database, RDP, DNS, and SMTP. Think of it like the second step or extension of the Footprinting module.
- **Pivoting, Tunneling, and Port Forwarding**— in this module, you will learn how to pivot, and in order to pass the exam, double-pivot is a must, but the tools being taught in this course are not ideal for newbies, so I recommend using the lab in this module to practice how to use Ligolo-ng or Ligolo-mp effectively.
- **Active Directory Enumeration & Attacks** — In this module, you will learn the fundamentals of AD enumeration and attacks, which will prove useful again and again in the actual exam, so make sure to spend your time here and digest everything.
- **SQL Injection Fundamentals** — In this module, you will learn the fundamentals of SQL injection attacks and how to conduct them. After this module, make sure to spend some extra time on the SQLMap Essential module as well.
- **File Inclusion** — in this module, you will learn a few techniques for file inclusion attacks.
- File Upload Attacks — In this module, you will learn more about file upload attacks and a few bypass techniques.
- **Attacking Common Applications** — In this module, you will learn various of common application attacks, including CMS such as WordPress, Joomla, and Drupal, and also something like Splunk, Jenkins, Tomcat, PRTG Network Monitor, GitLab, osTicket, and so on.
- **Linux Privilege Escalation **— self-explanatory
- **Windows Privilege Escalation**—self-explanatory
- **Documentation & Reporting **— self-explanatory
- Attacking Enterprise Networks— the ultimate test that summarize your journey into a single module to recap and practice in large networks, the scale is not the same as the exam but it is still the important to practice this one.
That’s a lot to go through, but it is necessary because the CPTS exam is no joke.
Now, what about the CPTS preparation path on the HTB Labs platform? Honestly, I don’t think it prepares you for the CPTS exam all that much, because it consists of standalone machines, while in the actual exam you are dealing with a full enterprise network with multiple endpoints that you need to compromise in order to pass.
So if you ask me, if you are looking for additional labs to practice outside of the path, HTB ProLabs is your best bet, as it consists of multiple endpoints.

And with that said, let’s jump right into the exam experience.
Exam Experience

I started my exam on 2nd May 2026. A lot of enumeration happened on that first day, which had me digging through notes I wrote back during my OSCP cramming days and revisiting parts of the penetration tester path to refresh some techniques I thought would work.
After wrestling with each endpoint, going back and forth with all the credentials I had gathered, and pushing through some self-doubt, I finally obtained all the flags on 4th May 2026. For reference, you need to obtain at least 12 out of 14 flags while documenting everything in a customer-ready report within 10 days, so looking back at it, I think I did pretty well considering I came from a DFIR background.


I submitted my report on 8th May 2026, which came out to over 150 pages. More flags mean more findings, and more findings mean more documentation; that’s just how it works. I’ve seen many people stop at flag 12, but I wanted a perfect score so I wouldn’t have any regrets.
One thing I forgot to mention is that for the report, I used Sysreptor, and honestly, why not? It carried me through CDSA, CJCA, and now CPTS. Without it, my Word would have crashed repeatedly and I probably wouldn’t have finished in time, and might have even failed on formatting alone. 🤣

Once the report was submitted, the VPN access was cut off from the exam environment, and it was just a waiting game from there, as results are announced in batches.


Five days later, I got my result back during a Thai holiday, and just like that, another cert added to the collection.


After claiming the cert, the role is automatically assigned to your Discord profile without needing to manually type a verification command anymore.

You can also visit your exam history page to read the feedback provided. I won’t be sharing mine here.
Exam Tips and Key Takeaways
- The exam is fairly linear, so do not jump ahead chasing other flags before completing the current objective, you simply won’t find them until you are meant to.
- Take screenshots as you go, along with the commands and their outputs.
- Some applications and services are there for a reason. You might not think they are useful at first, but sometimes they end up being the key to moving forward.
- Double pivoting and file transfer techniques are a must to learn before going into the exam.
- Sometimes there are multiple ways to exploit the same vulnerability. If one approach fails, look for another PoC or even write your own.
- If you have a valid domain user credential, do not forget to run BloodHound.
- If you cannot get a reverse shell due to connection issues from double pivoting or any other unknown reason, consider creating a backdoor admin account and logging in using that instead. 😉
- Avoid using RustScan. The HTB VPN simply cannot handle the scan speed and it will cause more problems which cost you some important information.
- Use SysReptor for report writing, it has an HTB exam template ready to go.
메타데이터
- post_id
- dbb0d30ddb09
- slug
- hackthebox-certified-penetration-testing-specialist-htb-cpts-guide-and-review-dbb0d30ddb09
- url
- https://medium.com/@chaoskist/hackthebox-certified-penetration-testing-specialist-htb-cpts-guide-and-review-dbb0d30ddb09
- canonical_url
- https://medium.com/@chaoskist/hackthebox-certified-penetration-testing-specialist-htb-cpts-guide-and-review-dbb0d30ddb09
- author_url
- https://medium.com/@chaoskist
- status
- ok
- fetched_at
- 2026-06-09 15:37:30