Hack The Box, commonly abbreviated as HTB, is a cybersecurity learning and skills-development platform built around guided instruction, hands-on exercises, realistic lab environments, and practical assessments.
Rather than teaching security only through videos or written lessons, Hack The Box gives learners access to systems, applications, and simulated environments where they can apply cybersecurity techniques themselves. Its offerings range from beginner-level instruction to advanced penetration testing, defensive security, artificial intelligence security, and enterprise network scenarios.

For individual learners, the two most relevant parts of Hack The Box are:
- HTB Academy, which provides structured courses and learning paths.
- HTB Labs, which provides machines, challenges, investigations, and other practical environments where learners can test and extend their skills.
These services complement each other, but they are not interchangeable. Academy is generally the better starting point when you need instruction. Labs become particularly valuable when you are ready to work through less prescriptive security problems.
Hack The Box at a Glance
| HTB offering | Primary purpose | Best suited for |
|---|---|---|
| HTB Academy | Guided cybersecurity instruction with interactive exercises | Learners building new skills or preparing for cybersecurity roles |
| HTB Labs | Gamified practice through vulnerable machines, technical challenges, and defensive investigations | Learners who already understand some fundamentals and want more independent practice |
| Starting Point | A guided introduction to beginner HTB machines | Absolute beginners entering the HTB Labs environment |
| HTB Pro Labs | Simulated corporate networks with interconnected systems and attack paths | More experienced practitioners seeking enterprise-style practice |
| HTB for Business | Workforce development, team assessments, curriculum management, reporting, and cyber ranges | Employers, security teams, government organizations, and educational institutions |
HTB Academy combines guided courses, real-world examples, skills-assessment exercises, interactive targets, and an in-browser penetration-testing virtual machine called Pwnbox. HTB Labs, meanwhile, provides a gamified environment containing machines, challenges, defensive scenarios called Sherlocks, and realistic corporate networks known as Pro Labs.
How Hack The Box Complements Cybersecurity Practice Tests
Many visitors to The Cybersecurity Trail use practice tests to prepare for certifications, identify weak domains, and check whether they can distinguish between closely related cybersecurity concepts.
Hack The Box serves a different but complementary purpose. Practice tests help you determine what you know. HTB Academy helps you study technical subjects in greater depth and apply them in interactive environments. HTB Labs then gives you opportunities to solve increasingly realistic security problems with less guidance.
| Learning resource | Primary purpose |
|---|---|
| Practice tests | Measure knowledge recall, identify weak domains, and improve exam readiness |
| HTB Academy | Teach cybersecurity concepts through structured lessons and guided exercises |
| HTB Starting Point | Introduce beginners to hands-on machines with walkthrough-style guidance |
| HTB Labs | Develop independent investigation and technical problem-solving skills |
| HTB Pro Labs | Provide multi-system, enterprise-style security environments |
For example, if your practice-test results show weaknesses in authentication, network services, web vulnerabilities, incident response, or Active Directory, you can look for corresponding HTB Academy Modules or Paths and study those subjects through hands-on exercises.
You can begin by reviewing our cybersecurity practice tests, then use the results to guide what you study in Hack The Box.
What Is HTB Academy?
HTB Academy is Hack The Box’s structured learning platform. It is designed for people who want to develop practical cybersecurity skills but may not yet know which topics to study, what order to study them in, or how to translate theoretical knowledge into hands-on ability.
Academy courses combine explanatory material with questions, exercises, and live systems. Instead of simply reading about service enumeration, privilege escalation, web exploitation, log analysis, or incident investigation, learners are expected to perform relevant tasks in a controlled environment.
Hack The Box describes Academy as suitable for skill levels ranging from beginner to advanced. Fundamental and Easy modules are intended to help beginners enter cybersecurity through a combination of guided theory and interactive practice.
Academy Modules
An Academy Module is a standalone course covering a particular subject. Examples can include Windows Fundamentals, Linux Privilege Escalation, web requests, Active Directory attacks, security monitoring, or digital forensics.
Each Module is divided into smaller Sections. A Section generally functions like a chapter or lesson and may include:
- Technical explanations
- Examples and commands
- Assessment questions
- Live target systems
- Practical exercises
- Skills assessments
This structure allows you to study a subject in manageable portions while regularly applying what you have learned.
Skill Paths
A Skill Path groups related Modules into a recommended sequence focused on a particular technical capability.

For example, someone who wants to improve at web exploitation may need to understand HTTP requests, web application architecture, authentication, common vulnerabilities, and exploitation techniques. A Skill Path organizes the relevant Modules so the learner does not have to design the entire curriculum independently.
Skill Paths are useful when you want to strengthen a defined capability without necessarily preparing for a specific job title.
Job Role Paths
Job Role Paths are broader learning tracks designed around the skills required for particular cybersecurity roles. They combine multiple Modules in a logical order and may culminate in preparation for an HTB certification.
Depending on the current Academy catalogue, available paths may cover areas such as:
- Web penetration testing
- Infrastructure penetration testing
- SOC analysis
- Defensive security
- Junior cybersecurity analysis
- Active Directory security
- AI red teaming
- Web exploitation
- Security operations
For example, the Web Penetration Tester path covers the stages of a web security assessment, including reconnaissance, vulnerability identification, exploitation, documentation, and communication of findings.
Pwnbox and Interactive Targets
HTB Academy is designed to be usable through a browser. Its interactive sections can provide a Pwnbox, which is a browser-based security workstation that learners can use to interact with Academy targets.
This reduces the amount of local setup required. You do not necessarily need to install a penetration-testing distribution, configure a virtual machine, or establish your own lab environment before beginning.
Learners who prefer their own systems may also be able to connect from a local virtual machine using the available VPN or container-based access options.
What Can You Learn Through HTB Academy?
Although Hack The Box has traditionally been associated with offensive security, Academy covers a wider set of cybersecurity disciplines.
Common subject areas include:
- Cybersecurity fundamentals: Networking, operating systems, command-line usage, scripting, protocols, and security concepts.
- Penetration testing: Reconnaissance, enumeration, vulnerability discovery, exploitation, privilege escalation, pivoting, and reporting.
- Web application security: HTTP, authentication, APIs, injection vulnerabilities, file attacks, server-side weaknesses, and web exploitation methodologies.
- Active Directory security: Windows environments, domain enumeration, credential attacks, lateral movement, privilege escalation, and enterprise compromise.
- Security operations: Alert analysis, traffic analysis, SIEM monitoring, threat detection, incident investigation, and reporting.
- Digital forensics and incident response: Evidence collection, log analysis, malware-related investigations, and reconstruction of attacker activity.
- Artificial intelligence security: AI application vulnerabilities, prompt-related attacks, model security, AI red teaming, and defensive controls.
- Professional methodology: Note-taking, documentation, assessment planning, reporting, and communication of findings.
This breadth means that Academy can support several types of learner. It may be useful for someone seeking a first cybersecurity role, an IT professional transitioning into security, a junior analyst developing deeper technical skills, or an experienced practitioner moving into a new specialization.
HTB Academy Versus HTB Labs
One of the most common points of confusion is the difference between Academy and Labs.
| Question | HTB Academy | HTB Labs |
|---|---|---|
| Does it teach the underlying concepts? | Yes. Instruction is a central part of the experience. | Sometimes, but learners are generally expected to investigate more independently. |
| Is the content arranged as courses? | Yes. Content is organized into Modules and Paths. | No. Content is primarily organized as machines, challenges, Sherlocks, and labs. |
| Does it include hands-on work? | Yes. Many Sections contain interactive targets and assessments. | Yes. Hands-on problem-solving is the main activity. |
| Is it suitable for complete beginners? | Yes, particularly the Fundamental and Easy content. | Starting Point is designed for beginners, but other Labs content may require more background. |
| Is it useful for experienced practitioners? | Yes, particularly advanced Modules and specialist Paths. | Yes. More difficult machines and realistic networks can challenge experienced users. |
| Does it require a separate subscription? | Academy plans apply to Academy. | Labs subscriptions apply to Labs. |
Hack The Box explicitly treats Academy and Labs as separate services, with separate subscriptions. Paying for an Academy subscription does not automatically provide a Labs subscription, and vice versa.
A practical way to use both is to learn a technique in Academy and then look for Labs content that requires you to apply it with fewer instructions.
What Is Hack The Box Starting Point?
Starting Point is a beginner-oriented section of HTB Labs. It consists of a linear series of relatively simple machines with guided explanations.
Each Starting Point machine includes a write-up that explains the solution and the concepts involved. The content is divided into tiers that gradually introduce greater complexity:
- Tier 0 introduces basic connectivity, ports, services, and simple interactions.
- Tier 1 introduces fundamental exploitation techniques.
- Tier 2 introduces fuller attack chains involving enumeration, initial access, and privilege escalation.
Starting Point is therefore useful for learners who have completed some introductory material but are not yet comfortable approaching a standard HTB machine without assistance. It serves as a bridge between guided learning and more independent problem-solving.
What Types of Content Are Available in HTB Labs?
HTB Labs includes several forms of practical content.
Machines
Machines are vulnerable virtual systems running operating systems such as Linux, Windows, or FreeBSD. Learners enumerate the target, identify weaknesses, gain access, and attempt to reach higher privilege levels.
Machines are assigned difficulty levels ranging from Easy to Insane.
Challenges
Challenges are smaller exercises focused on a particular technique or cybersecurity discipline. They are generally narrower than full machines and may concentrate on subjects such as cryptography, web exploitation, reverse engineering, forensics, hardware, or binary exploitation.
Sherlocks
Sherlocks are defensive investigation scenarios. Rather than compromising a target, the learner analyzes evidence and attempts to understand what happened.
They can involve areas such as:
- Digital forensics
- Incident response
- Malware analysis
- Cloud investigations
- SOC analysis
- Threat intelligence
Pro Labs
Pro Labs are larger, enclosed environments designed to resemble corporate networks. They can contain multiple machines, operating systems, trust relationships, security configurations, and possible attack paths.
These environments are more suitable for learners who already possess foundational penetration-testing skills and want experience navigating interconnected systems.
How Much Does HTB Academy Cost?
HTB Academy provides some free access, although broader access requires Cubes or a subscription.
Cubes are Academy’s platform currency. They are used to unlock Modules. Free users receive an initial allocation and can earn additional Cubes by completing eligible content, while paid monthly plans provide a recurring Cube allowance.
As of July 2026, the official Academy subscription options include:
| Academy plan | Current listed price | Access model |
|---|---|---|
| Free | $0 | Limited free Cubes and access to selected introductory content |
| Silver Monthly | $18 per month | 200 Cubes per month |
| Gold Monthly | $38 per month | 500 Cubes per month |
| Platinum Monthly | $68 per month | 1,000 Cubes per month |
| Student | $8 per month | Direct access to Modules through Tier II, subject to academic eligibility |
The paid monthly plans include unlimited Pwnbox usage and support for submitting continuing professional education credits. The Student plan requires verification through an eligible educational or academic institution. Prices and plan inclusions may change, so check the official subscription page before purchasing.
Does Hack The Box Offer Certifications?
HTB Academy offers practical certifications associated with selected Job Role Paths.

Rather than relying solely on multiple-choice questions, HTB certification exams can require candidates to complete practical security tasks in an examination environment. Depending on the certification, candidates may also be expected to produce professional documentation or an assessment report.
Examples of current HTB certifications cover areas such as:
- Penetration testing
- Web exploitation
- Defensive security analysis
- Active Directory penetration testing
- Junior cybersecurity
- Wi-Fi penetration testing
- Offensive AI security
Before attempting an Academy certification exam, the related learning path must be completed. Exam vouchers can be purchased separately or included with qualifying annual subscriptions, depending on the plan.
Who Should Consider Hack The Box?
Hack The Box may be particularly useful for:
- Cybersecurity students who need practical experience beyond classroom instruction
- Certification candidates who understand theory but have limited hands-on exposure
- IT professionals transitioning into cybersecurity
- Junior penetration testers who want to develop a repeatable methodology
- SOC analysts who want experience investigating realistic security events
- Developers learning how vulnerabilities are identified and exploited
- Experienced practitioners moving into web security, Active Directory, cloud, AI security, or another specialization
- Job seekers who want demonstrable practical training and project experience
However, Hack The Box should not be treated as a substitute for every other form of learning. Beginners may still need foundational study in networking, operating systems, scripting, and security concepts. Practitioners also need experience with documentation, communication, risk evaluation, and organizational processes that cannot always be reproduced through an individual lab.
Is HTB Academy Suitable for Beginners?
Yes, provided the learner begins with appropriate content.
Someone with little technical background should not necessarily start with an advanced penetration-testing path or an unfamiliar HTB machine. A more manageable sequence would be:
- Learn basic networking, Linux, Windows, and command-line concepts.
- Complete introductory Academy Modules.
- Follow a relevant Skill Path or beginner Job Role Path.
- Use Starting Point to become comfortable with HTB machines.
- Attempt Easy machines or Challenges related to completed Academy subjects.
- Review unsuccessful attempts and document what was learned.
- Progress to more independent and complex environments.
This sequence preserves the value of problem-solving without requiring the learner to guess their way through topics they have never studied.
Is Hack The Box Only for Penetration Testers?
No. Offensive security remains a major part of the platform, but Hack The Box also provides defensive investigations, SOC-oriented learning, incident-response scenarios, threat intelligence material, AI security training, and broader workforce-development capabilities.
Its business platform extends these resources to organizations through role-based plans, curriculum management, team assessments, reporting, CTFs, and enterprise ranges. Managers can use these capabilities to assign training, evaluate progress, identify skills gaps, and align development programs with organizational roles.
Individual learners do not need these administrative features, but their availability explains why Hack The Box is used by both independent practitioners and organizational security teams.
Is Hack The Box Worth Using?
Hack The Box is most valuable when you approach it as a learning environment rather than simply a collection of boxes to complete.
Academy can provide the structure needed to learn unfamiliar subjects. Starting Point can help you enter the practical Labs environment. Machines, Challenges, and Sherlocks can expose weaknesses in your understanding that may not appear while reading a course. More advanced environments can help you practice combining multiple techniques into a coherent investigation or assessment.
The platform will not remove the need to research, troubleshoot, take notes, and revisit difficult concepts. Those activities are part of the learning process. Completing large numbers of machines without understanding the underlying techniques is less valuable than completing fewer exercises while documenting the methodology, mistakes, and lessons from each one.
How to Get Started With Hack The Box
A practical starting process is:
- Define the role or capability you want to develop.
- Review the available Academy Job Role Paths and Skill Paths.
- Begin with Fundamental Modules if you are new to the subject.
- Complete the exercises instead of reading only the instructional text.
- Keep notes on commands, tools, findings, and troubleshooting steps.
- Use Starting Point when you are ready to enter HTB Labs.
- Attempt Labs content related to subjects you have studied.
- Return to Academy when a lab reveals a knowledge gap.
- Use practice tests when studying for knowledge-based certification exams.
- Periodically repeat exercises without relying on the original walkthrough.
You can explore Hack The Box Academy and begin with its free content.
Final Thoughts
Hack The Box is not a single course or certification. It is an ecosystem for learning, practicing, and assessing cybersecurity skills.
For most individual learners, HTB Academy is the logical entry point because it explains concepts, organizes subjects into Modules and Paths, and provides guided interaction with live targets. Starting Point and HTB Labs then offer opportunities to apply those skills with progressively less guidance.
The strongest learning plan does not rely exclusively on courses, practice tests, or labs. It uses each for what it does best: structured instruction for learning, practice questions for evaluating conceptual understanding, and hands-on environments for developing practical judgment.