← Research Hub
Tools & Setup

HTB Machines β†’ CPTS Modules

Curated list of 30+ HackTheBox machines mapped to specific CPTS exam objectives β€” ordered by difficulty and topic coverage to maximize study efficiency.

Fundamentals & Enumeration

MachineOSCPTS ModulesKey Concepts
LameLinuxNmap, ShellsSamba exploit, basic enumeration
LegacyWindowsNmap, Common ServicesMS08-067, SMB exploitation
BlueWindowsNmap, ExploitationMS17-010 (EternalBlue)
NibblesLinuxWeb Info Gathering, FootprintingWeb app enum, CMS exploitation
KeeperLinuxFootprinting, Password AttacksDefault creds, KeePass exploitation

Web Application Attacks

MachineOSCPTS ModulesKey Concepts
PoisonLinuxFile Inclusion, ShellsLFI β†’ RCE, log poisoning
MagicLinuxFile UploadMIME bypass, PHP webshell upload
BoltLinuxSQLi, SQLMapServer-side template injection, credential reuse
HorizontallLinuxFfuf, Web AttacksAPI subdomain, Strapi RCE
BashedLinuxFootprinting, PrivEscWeb discovery, sudo privesc
OptimumWindowsCommon AppsHFS RCE, Windows privesc
BountyWindowsFile UploadASPX upload bypass, SeImpersonate
MachineOSCPTS ModulesKey Concepts
ForestWindowsAD Enum, AD AttacksAS-REP Roasting, DCSync, ExchangeWindows Permissions ACL
BlackfieldWindowsAD Attacks, ACL AbuseAS-REP Roast, ForceChangePassword, DCSync
MonteverdeWindowsAD Enum, Password AttacksAzure AD Connect, credential reuse
CascadeWindowsAD Enum, AD AttacksLDAP enum, AD recycle bin, .NET reversing
SaunaWindowsAD Enum, AD AttacksKerbrute user enum, AS-REP Roast, DCSync
ActiveWindowsAD Enum, KerberoastingGPP password, Kerberoasting DA
ReturnWindowsAD Enum, Common ServicesLDAP credential leak, Server Operators group
EscapeWindowsAD Attacks, ADCSMSSQL hash capture, ADCS ESC1
ManagerWindowsADCS AttacksADCS ESC7, Certipy, LDAP enum
SupportWindowsAD Enum, RBCDSMB info leak, RBCD attack

Privilege Escalation

MachineOSCPTS ModulesKey Concepts
BeepLinuxLinux PrivEsc, Common ServicesFreePBX/Elastix LFI β†’ RCE, Webmin exploit, multiple privesc paths (sudo nmap, sudo -l)
SundaySolarisLinux PrivEsc, Password AttacksFinger enumeration, shadow hash cracking, sudo wget
ValentineLinuxLinux PrivEscHeartbleed, tmux session hijack
ShockerLinuxLinux PrivEscShellshock, sudo perl
ArcticWindowsWindows PrivEscColdFusion exploit, JuicyPotato
BastardWindowsWindows PrivEsc, Common AppsDrupal RCE, JuicyPotato

Study Strategy

Recommended Order: Lame β†’ Blue β†’ Bashed β†’ Nibbles (basic skills) β†’ Poison β†’ Magic β†’ Bounty (web) β†’ Sauna β†’ Forest β†’ Active (AD basics) β†’ Blackfield β†’ Escape β†’ Manager (AD advanced)
  • Don't read walkthroughs until you've spent 2+ hours on a machine
  • After completing, read at least 2 public writeups to see alternate approaches
  • AD machines (Forest, Blackfield, Sauna) are the closest to actual CPTS exam feel
  • Manager and Escape specifically practice ADCS β€” high value for CPTS
  • Retire machines rotate β€” check HTB retired list for machine availability