HackTheBox → AYSEC Mapping
HTB Academy modules + retired machines mapped to AYSEC tracks.
HackTheBox — Mapping to AYSEC Modules
HackTheBox (HTB) Academy modules + retired machines mapped to AYSEC tracks.
Note: HTB content is split across HTB Academy (paid by Cube credits or annual sub) and the main HackTheBox platform (machines, prolabs, fortresses).
HTB Academy Job-Role Paths Mapped
| Path |
AYSEC Tracks |
| Penetration Tester (CPTS) |
AYSEC-101 + AYSEC-106 |
| Bug Bounty Hunter (CBBH) |
AYSEC-106 |
| SOC Analyst (CDSA) |
AYSEC-102 |
| Senior Web Penetration Tester |
AYSEC-106 + AYSEC-201 |
| Active Directory Penetration Tester |
AYSEC-101 (M11–12) + AYSEC-201 |
AYSEC-101 Penetration Testing
Foundational HTB Academy modules
- Penetration Testing Process
- Network Enumeration with Nmap
- Footprinting
- Information Gathering — Web Edition
- Vulnerability Assessment
- File Transfers
- Shells & Payloads
- Using the Metasploit Framework
- Password Attacks
- Attacking Common Services
- Pivoting, Tunneling, and Port Forwarding
Active Directory modules
- Active Directory Enumeration & Attacks
- Active Directory LDAP
- Active Directory PowerView
- Kerberos Attacks
Recommended HTB retired machines (OSCP-like)
| Difficulty |
Box |
What you practice |
| Easy |
Lame |
SMB, Samba exploits |
| Easy |
Legacy |
MS-style SMB + Eternal-style |
| Easy |
Devel |
Web → Windows |
| Easy |
Optimum |
Public exploit chain |
| Easy |
Bashed |
Web shell + privesc |
| Easy |
Nibbles |
Web admin + privesc |
| Medium |
Bastard |
Web app + Windows privesc |
| Medium |
Granny / Grandpa |
Old Windows |
| Medium |
Tally |
Windows + complex enumeration |
| Medium |
Active |
AD GPP password |
| Medium |
Forest |
AS-REP roasting + DCSync |
| Medium |
Cascade |
AD complex chain |
| Hard |
Sizzle |
Full AD chain |
| Hard |
Mantis |
Kerberos + AD |
| Hard |
Reel / Reel2 |
OSINT + AD |
| Hard |
Hathor |
Windows + AD |
The "TJnull OSCP-like" community list curates 50+ HTB boxes that resemble OSCP exam difficulty.
Pro Labs (subscription)
- Dante — beginner-friendly multi-host network.
- Offshore — Active Directory focused; AYSEC-101 M11-12 capstone.
- RastaLabs — red team adjacent.
- Cybernetics — advanced.
- Zephyr — modern AD.
- APTLabs — APT emulation.
AYSEC-102 SOC / Blue Team
HTB Academy SOC modules
- Introduction to Defensive Security
- Splunk Fundamentals
- Working with IDS/IPS
- Security Monitoring & SIEM Fundamentals
- Detecting Windows Attacks with Splunk
- Windows Event Logs & Finding Evil
- Introduction to Threat Hunting & Hunting With Elastic
- Understanding Log Sources & Investigating with Splunk
- YARA & Sigma for SOC Analysts
- Introduction to Malware Analysis
- Intermediate Malware Analysis
Sherlocks (Blue Team challenges)
HTB's "Sherlocks" are blue-team scenarios — investigate a packaged incident.
| Sherlock |
Topic |
| Brutus |
Brute force investigation |
| Tracer |
Network forensics |
| Heartbreaker |
Malware analysis |
| RogueOne |
DFIR, Windows |
| ProjectAphrodite |
Cloud / O365 |
AYSEC-103 DFIR
HTB Academy
- JavaScript Deobfuscation
- Operating System Attacks
- Hardware Attacks
- DFIR-tagged Sherlocks
CyberDefenders (parallel platform)
- BlueTeam Labs Online (BTL Online).
- HTB Sherlocks overlap with CyberDefenders style.
AYSEC-104 GRC
HTB doesn't have GRC content — supplement with:
- ISACA online training.
- IAPP for privacy.
- ISC2 CC + CGRC.
AYSEC-105 Cloud Security
HTB Academy
- AWS Cloud Pentesting
- Hacking AWS S3
- Cloud Pentesting Fundamentals
- Containerization Hardening
AYSEC-106 AppSec / Bug Bounty
HTB Academy (Bug Bounty path)
- Web Requests
- Introduction to Web Applications
- Web Attacks
- Login Brute Forcing
- Using Web Proxies
- Attacking Web Applications with Ffuf
- Cross-Site Scripting (XSS)
- SQL Injection Fundamentals
- SQLMap Essentials
- Web Service & API Attacks
- Hacking WordPress
- JavaScript Deobfuscation
- File Upload Attacks
- Server-Side Attacks
- Command Injections
- Information Gathering — Web Edition
Senior Web Pentester additions
- Whitebox Pentesting 101: Command Injection
- JavaScript Deobfuscation
- Advanced SQL Injection
- Modern Web Exploitation Techniques
Recommended retired web boxes
| Difficulty |
Box |
| Easy |
OpenAdmin (web → privesc) |
| Easy |
LaCasaDePapel |
| Medium |
TartarSauce |
| Medium |
Bart |
| Medium |
Nightmare |
| Hard |
RopeTwo |
AYSEC-150 IoT / OT
HTB doesn't focus on ICS; for OT-specific labs, use:
- TryHackMe ICS rooms.
- Pi-PLC community projects.
- PLCBuddy simulator.
AYSEC-151 AI Security
HTB Academy 2024+:
- Adversarial Machine Learning Fundamentals
- AI-Sherlocks added periodically.
AYSEC-152 Cryptography
HTB Academy
- Cryptography
- Crypto challenges in regular HTB.
AYSEC-201 Red Team
HTB Academy
- Active Directory Enumeration & Attacks
- Kerberos Attacks
- Whitebox Pentesting
- Stealthy Modules
Pro Labs
- Offshore
- RastaLabs
- Cybernetics
- Zephyr
- APTLabs
These are subscription-based 1-week immersive multi-host labs. Excellent capstones for AYSEC-201.
AYSEC-202 RE & Malware
HTB Academy
- Introduction to Malware Analysis
- Intermediate Malware Analysis
- Reverse Engineering
Reversing challenges
- HTB Challenges → Reversing category.
- Easy: Bypass, Headache, MyBaby.
- Medium: Eval Me.
- Hard: Vault.
AYSEC-203 Threat Hunting
HTB Academy
- Introduction to Threat Hunting & Hunting With Elastic
- Detecting Windows Attacks with Splunk
Sherlocks (recommended)
- Brutus — brute force forensics.
- Heartbreaker — multi-stage IR.
- Persistence — backdoor hunting.
AYSEC-204 Mobile AppSec
HTB's mobile content is sparse. Supplement with:
- TryHackMe MASQ.
- Frida / Objection community labs.
- Hacking-Lab.com mobile challenges.
How to Approach HTB
Starting Point Tier (free)
- 4 free machines (rotated): great for first-week practice.
Cube Credits
HTB Academy modules cost "cubes." Buy cubes (~$10 / 100 cubes) and use them for the exact modules you need. Or annual sub for unlimited Academy + retired machines.
TJnull's OSCP-like list
The most-referenced study list. Search "TJnull OSCP HTB list."
Pro Labs subscription
For AYSEC-201 (red team) capstone work, Pro Lab subscription (separate from main HTB) gives 30 days on a multi-host network. Excellent capstone.
Pricing as of 2026 (verify on htb.com)
- HTB Free Tier — 4 active machines + Starting Point.
- HTB VIP — ~$14/mo, all retired machines.
- HTB VIP+ — ~$20/mo, includes Pro Labs lite access.
- HTB Academy — Cubes per module or annual subscription.
- HTB CPTS exam — ~$210 (with the Academy path).
Recommended Sequence
Pre-AYSEC: 0-10 hours
HTB Starting Point Tier 0 (free)
AYSEC-101: 200-400 hours
HTB Academy "Penetration Tester" path
+ 30-50 retired machines from TJnull's OSCP-like list
AYSEC-101 capstone:
HTB Pro Lab "Dante" or "Zephyr"
AYSEC-201:
HTB Pro Lab "Offshore" + "RastaLabs"