ZeroBox

CPTS-Like Machines: 48 boxes by difficulty

CPTS, the Certified Penetration Testing Specialist from Hack The Box, is a practical certification built around a multi-day exam in which you assess a realistic network and deliver a professional report. It covers enumeration, web attacks, Active Directory, pivoting and reporting.

The 48 machines on this page are tagged CPTS in the ZeroBox catalog and come from HTB. By operating system that is 36 Linux, 12 Windows. The machines below cover the breadth that the exam expects: web application flaws, service enumeration, Windows and Linux escalation, Active Directory and tunnelling. Because CPTS rewards thorough notes and clean reporting, use each box to practise documenting evidence as you go.

To use the list, start at the easiest group and work upward, spending real time on enumeration before looking at any help. After each box, write down the foothold, the escalation and what you would do faster next time. 1 of these are targets I solved myself, so they link to an attack path summary on this site; the others link to the official room. Once you are comfortable, rehearse under pressure in the exam simulator, and follow the phase-by-phase pentest methodology checklist so you do not skip steps. You can also browse the technique hubs to drill one skill at a time.

Jump to difficulty

CPTS machine list by difficulty

Very Easy (2)

MachinePlatformOSTags
FunnelHTBLinuxSSH, Port Forwarding, PostgreSQL, Tunneling
UnifiedHTBLinuxLog4j, CVE-2021-44228, UniFi, MongoDB

Easy (17)

MachinePlatformOSTags
KoboldHTBLinuxsuid
AlertHTBLinuxCPTS, Markdown XSS, LFI, Port Forwarding
BusquedaHTBLinuxCPTS, RCE, Python, Searchor
ChemistryHTBLinuxCPTS, CIF Parser, Python, Pivoting
CraftyHTBWindowsCPTS, Minecraft, Log4j, JNDI
InjectHTBLinuxCPTS, Spring Cloud, SpEL Injection, Ansible
MailingHTBWindowsCPTS, Email, Directory Traversal, LibreOffice
MonitorsTwoHTBLinuxCPTS, Cacti, Docker Breakout, CVE-2022-46169
PCHTBLinuxCPTS, gRPC, SQL Injection, Pivoting
PerfectionHTBLinuxCPTS, SSTI, Ruby, ERB
PreciousHTBLinuxCPTS, Command Injection, pdfkit, YAML Deserialization
SeaHTBLinuxCPTS, SeaCMS, XSS, Pivoting
SightlessHTBLinuxCPTS, SQLPad, Chrome DevTools, Pivoting
SoccerHTBLinuxCPTS, Blind SQLi, WebSockets, Dstat
StockerHTBLinuxCPTS, NoSQL Injection, Server-Side XSS, NodeJS
UnderpassHTBLinuxSNMP-Walk, Daloradius, FreeRADIUS, Password-Cracking
UsageHTBLinuxCPTS, Blind SQLi, 7-Zip Symlink, Privilege Escalation

Medium (28)

MachinePlatformOSTags
AdministratorHTBWindowsActiveDirectory, ADCS, Golden-Cert, Kerberoasting
AgileHTBLinuxCPTS, LFI, Werkzeug PIN, Chrome Debugging
BagelHTBLinuxCPTS, LFI, Spring Boot, .NET Deserialization
BlurryHTBLinuxClearML-CVE-2024-24590, Pickle-Deserialization, PyTorch, Sudo-MLflow
BroScienceHTBLinuxCPTS, Insecure Deserialization, PRNG, PHP
CascadeHTBWindowsAD Recycle Bin, AES-Encryption, Active Directory, Active-Directory
ClickerHTBLinuxCPTS, NFS, Mass Assignment, SQL Injection
EncodingHTBLinuxCPTS, LFI, PHP Filters, Git Hooks
EscapeTwoHTBWindowsActiveDirectory, MSSQL-Linked-Server, Coerce-Authentication, GPO-Abuse
FlightHTBWindowsCPTS, Active Directory, Pivoting, Responder
FormatHTBLinuxCPTS, LFI, Nginx Traversal, Redis
HospitalHTBWindowsRoundcube, Webmail, CVE-2023-43770, SeImpersonatePrivilege
InstantHTBLinuxCPTS, Mobile, Android APK, API
IntelligenceHTBWindowsAD CS, ADIDNS-abuse, Active Directory, BloodHound
InvestigationHTBLinuxCPTS, ExifTool, Forensics, Binary Analysis
JupiterHTBLinuxCPTS, Grafana, PostgreSQL, Jupyter
ManagerHTBWindowsCPTS, Active Directory, MSSQL, AD CS
MonitoredHTBLinuxNagios-XI-CVE-2023-40931, Cacti, SQLi, SUID-Abuse
MonteverdeHTBWindowsActive Directory, Azure AD Connect, BloodHound, MSOL
Only4YouHTBLinuxCPTS, Cypher Injection, Neo4j, Pivoting
RunnerHTBLinuxCPTS, TeamCity, CVE-2024-27198, Portainer
SandwormHTBLinuxCPTS, SSTI, Sandbox Escape, Firejail
ScrambledHTBWindowsActive Directory, Deserialization, Deserialization-attacks, Kerberoasting
SneakyMailerHTBLinuxIMAP, Package Hijack, Phishing, PyPI
SurveillanceHTBLinuxCPTS, Craft CMS, ZoneMinder, Pivoting
TimeHTBLinuxCVE-2019-12384, CVE-2019-12814, CVE-2019-14439, CVE-2020-24616
VisualHTBWindowsCPTS, Visual Studio, MSBuild, SeImpersonatePrivilege
ZippingHTBLinuxZip-Symlink, LFI, SQLi, Shared-Library-Hijack

Hard (1)

MachinePlatformOSTags
IntuitionHTBLinuxFlask, SSTI, Suricata-Bypass, OpenSearch-CVE-2023-23613

Track your progress. ZeroBox keeps a Kanban board, notes and checklists for every box, offline in your browser. Open ZeroBox

Related guides

Machines belong to HTB. ZeroBox is not affiliated with the platforms or certification bodies named here.