Where HackTheBox helps is with creative thinking and understanding attack chains. Many of the boxes themselves are not what people professionally do day to day. However, the attack chains you learn from doing them will help. Command injection isn't always straightforward there's a lot of small tricks you pick up. For example, the machine that just retired today had Apache Uno which allows you to specify a binary and the first argument. Which I had a heck of a time getting RCE without dropping a program to disk and executing that. After publishing the video, someone pointed out you could use AWK in order to get RCE within these constraints. You pick up tons of things like that, which work in extremely niche scenarios. That situation may not come up anytime in the near future, but knowing 100 niche scenarios means most of the time when an exploit fails initially I'll know another trick to try. With work, I find it hard to really figure out how things work under the hood since you can't always take time to play with things or even take the risk of playing with it, as if things go wrong it can go south very fast. In a CTF there's no limitation on how much time you spend, or intrusive actions you take in order to learn the most you can. Answer from Ipp on reddit.com
🌐
Hack The Box
ctf.hackthebox.com
Live Events - Hack The Box CTF
Prove your cybersecurity skills on the official Hack The Box Capture The Flag (CTF) Platform! Play solo or as a team. Jeopardy-style challenges to pwn machines.
HTB
Welcome to the Hack The Box CTF Platform. Looking for hacking challenges that will enable you to compete with others and take your cybersecurity skills to the next level? You are at the right place. From Jeopardy-style challenges (web, crypto, pwn, reversing, forensics, blockchain, etc) to ...
Marketplace
Choose from pre-built CTF bundles by Hack The Box to help you host your next CTF event.
Level 1
Pack Details - Hack The Box CTF page has loaded.
Level 0
Pack Details - Hack The Box CTF page has loaded.
🌐
Hack The Box
hackthebox.com › capture-the-flag
Hack The Box CTF Platform | Cybersecurity Team Assessment
Forget static ranges! The HTB CTF platform enables security leaders to shape realistic live-fire team assessments based on the outcome desired and the specific audience involved - hosting up to thousands of players, easy to deploy.
Discussions

Getting Started with CTF's.
I would honestly probably just start on HTB Academy and then as you progress there moving up to Challenges and Boxes on the main platform. I’ve only done the HTB sponsored CTFs and they’re great, but only a handful a year. I have never tried the other CTFs offered as, at least the last time I was on HTB CTF, most are locked to specific audiences. HTB Academy has a lot of great content and a cheap student subscription to get access to most of it. More on reddit.com
🌐 r/hackthebox
6
14
April 11, 2026
CTF
tryhackme might be a better place to start for a beginner. there's a bunch of free rooms on there that will walk you through the basics, then you can run through hack-the-box challenges with more confidence. More on reddit.com
🌐 r/hackthebox
12
3
October 8, 2023
How realistic are CTFs on hackthebox
Where HackTheBox helps is with creative thinking and understanding attack chains. Many of the boxes themselves are not what people professionally do day to day. However, the attack chains you learn from doing them will help. Command injection isn't always straightforward there's a lot of small tricks you pick up. For example, the machine that just retired today had Apache Uno which allows you to specify a binary and the first argument. Which I had a heck of a time getting RCE without dropping a program to disk and executing that. After publishing the video, someone pointed out you could use AWK in order to get RCE within these constraints. You pick up tons of things like that, which work in extremely niche scenarios. That situation may not come up anytime in the near future, but knowing 100 niche scenarios means most of the time when an exploit fails initially I'll know another trick to try. With work, I find it hard to really figure out how things work under the hood since you can't always take time to play with things or even take the risk of playing with it, as if things go wrong it can go south very fast. In a CTF there's no limitation on how much time you spend, or intrusive actions you take in order to learn the most you can. More on reddit.com
🌐 r/hackthebox
19
48
August 17, 2024
CTF Challenges Solutions?
Active challenges do not have public solutions. If you have a VIP on HTB you can do retired challenges that do have writeups More on reddit.com
🌐 r/hackthebox
9
9
March 12, 2022
🌐
Hack The Box
help.hackthebox.com › all collections › htb ctf - ctf platform › ctf platform user's guide › ctf user's guide
CTF User's Guide | Hack The Box Help Center
June 9, 2026 - New to CTFs? Looking to participate in one? Check out this article. ... A Capture The Flag (CTF) event is a cybersecurity competition where teams or individuals solve Challenges to find hidden text strings called "Flags." The participant or team that collects the most flags in the shortest amount of time wins the competition.
🌐
Hack The Box
hackthebox.com › blog › what-is-ctf
What is CTF in hacking? Tips & CTFs for beginners by HTB
March 21, 2022 - CTFs are gamified competitive cybersecurity events that are based on different challenges or aspects of information security. They are excellent for both beginners and experienced hackers looking to develop, test, and prove their skills because ...
🌐
CTFtime.org
ctftime.org › ctf › 554
CTFtime.org / Hack The Box CTF
CTFs / Hack The Box CTF · Offical URL: https://www.hackthebox.com/events/cyber-apocalypse-2022 · Hack The Box CTF's ·
🌐
Hack The Box
help.hackthebox.com › all collections › htb ctf - ctf platform › ctf platform user's guide › setting up your hack the box ctf account
Setting Up Your Hack The Box CTF Account | Hack The Box Help Center
May 29, 2026 - This guide explains how to register for a Hack The Box Capture The Flag (CTF) account, manage your public profile, and update your security settings.
🌐
Hack The Box
hackthebox.com › hacker › ctf
Capture The Flag Competitions For Hackers | Hack The Box CTFs
All challenge types are included in this category. Pick the ones that best fit your company's CTF requirements. From reversing and web to pwn and hardware. Hack a web app via a chain of attacks and exploits.
Find elsewhere
🌐
Reddit
reddit.com › r/hackthebox › ctf
r/hackthebox on Reddit: CTF
October 8, 2023 -

I want to join a CTF event online to expand/ increase my knowledge and skills(I'm a newbie btw :D). Can someone give me advice/on things that I need to do before participating in a CTF, like do I need to be connected to a safe network or use a VPN, basically what are the "Do's and Dont's" .
Thank you!

🌐
Reddit
reddit.com › r/hackthebox › how realistic are ctfs on hackthebox
r/hackthebox on Reddit: How realistic are CTFs on hackthebox
August 17, 2024 -

I play hackthebox a lot and enjoy it. I want to know how realistic some of these things are though. I am an aspiring red teamer / pentester.

Would red teams use something like gobuster? It seems noisy and detectable and like it would get them caught very easily. If not then what alternative do they have to enumerate hidden directories, subdomains etc.

Do pentesters and red teams use reverse shells in practice? This also seems detectable. I’m guessing they would use a C2 instead of just a simple reverse shell but want to check.

Top answer
1 of 7
33
Where HackTheBox helps is with creative thinking and understanding attack chains. Many of the boxes themselves are not what people professionally do day to day. However, the attack chains you learn from doing them will help. Command injection isn't always straightforward there's a lot of small tricks you pick up. For example, the machine that just retired today had Apache Uno which allows you to specify a binary and the first argument. Which I had a heck of a time getting RCE without dropping a program to disk and executing that. After publishing the video, someone pointed out you could use AWK in order to get RCE within these constraints. You pick up tons of things like that, which work in extremely niche scenarios. That situation may not come up anytime in the near future, but knowing 100 niche scenarios means most of the time when an exploit fails initially I'll know another trick to try. With work, I find it hard to really figure out how things work under the hood since you can't always take time to play with things or even take the risk of playing with it, as if things go wrong it can go south very fast. In a CTF there's no limitation on how much time you spend, or intrusive actions you take in order to learn the most you can.
2 of 7
9
The scenarios are not realistic, maybe there is a handful of boxes I've done that I thought represented scenarios that can actually happen. The reasons for this are many, but the main one is that HTB boxes are made to be vulnerable on purpose, while infrastructure in the real world is vulnerable by accident. That being said, most tools and techniques you learn solving HTB boxes are real and can be applied in the real world in some cases.
🌐
Hack The Box
hackthebox.com › business › business-ctf
Host A CTF Event | CTF Hosting & CTF As A Service | Hack The Box
Host a CTF competition for your company or IT team. Get CTF hosting or CTF as a service for hacking challenges to upskill your IT/cyber team's skills.
🌐
Hack The Box
help.hackthebox.com › all collections › htb ctf - ctf platform › ctf platform user's guide › ctf registration & teams
CTF Registration & Teams | Hack The Box Help Center
1 month ago - To participate in CTFs as a team, it is essential to have an HTB Account linked to the CTF Platform. If you already have an HTB Account, you can simply navigate to ctf.hackthebox.com and click on Sign in With HTB Account.
🌐
Hack The Box
hackthebox.com › events › htb-business-ctf-2024
HTB Business CTF 2024 - CTF Competition for Companies
Join a free, global CTF competition designed for corporate teams. Sharpen your skills on a team level, show them to the world, and get to the top of a global leaderboard. ... The #1 platform to build attack-ready teams and organizations. ... Courses & Certifications Cyber Ranges Enterprise Attack Simulations Cloud Infrastructure Simulations Capture The Flag Tabletop Exercises Talent Sourcing · Courses & Certifications Hacking Labs Defensive Labs Red Team Labs Capture The Flag Job Board
🌐
GitLab
0xdf.gitlab.io
0xdf hacks stuff | CTF solutions, malware analysis, home lab development
The box runs openSUSE, where I’ll abuse a PAM environment-variable flaw to convince Polkit I’m a local console session, then exploit a libblockdev/udisks vulnerability to mount a crafted XFS image carrying a SetUID-root shell and escalate to root. In Beyond Root, I’ll get CopyFail and DirtyFrag (two recent Linux kernel page-cache privilege-escalation exploits) working on the host. ... ctf hackthebox htb-overwatch nmap windows domain-controller active-directory mssql netexec netexec-spider-plus dotnet wcf dotpeek reverse-engineering csharp sqlite mssqlclient mssql-linked-servers htb-darkzero dns nslookup ldapsearch bloodyad dns-record dns-write responder evil-winrm-py nssm http-sys command-injection soap wcf-soap wcf-client secretsdump dcsync
🌐
Hack The Box
help.hackthebox.com › all collections › htb ctf - ctf platform › ctf organization guide › ctf marketplace
CTF Marketplace | Hack The Box Help Center
June 3, 2026 - These are templates for different styles of CTFs that you can choose from. With Packs, you can easily select both the type of content you are looking for, as well as the difficulty. For example, if you are running an event as part of some initial, entry-level pentesting training, you may want to go for the Hack All Things 101 - Level 0 Pack, suitable for people who aren't very experienced in hacking challenges or are junior.
🌐
YouTube
youtube.com › playlist
Hack The Box - CTF Challenges - YouTube
Share your videos with friends, family, and the world