HTB CAPE is the hardest thing Hack The Box has put in front of an Active Directory specialist, and the failure pattern is unusual: most people who do not pass are not stopped by the machines. They are stopped by running out of days, or by writing a report that an HTB Academy instructor cannot accept.
The exam gives you a 10-day window, asks for 90 points, and requires a professional-grade penetration test report submitted on Hack The Box's own template. It is open-book. Google, your notes and the course material are all fair game. None of that makes it easier, because the difficulty lives in a multi-domain Active Directory environment that behaves like a real client estate rather than a lab.
This plan covers the 10 weeks before the exam and the 10 days of the exam itself.
What the HTB CAPE Exam Actually Is
HTB CAPE stands for Hack The Box Certified Active Directory Pentesting Expert. It launched on 10 December 2024 and sits above CPTS in the Hack The Box certification range, aimed specifically at Active Directory exploitation rather than general penetration testing.
| Detail | HTB CAPE |
|---|---|
| Full name | HTB Certified Active Directory Pentesting Expert |
| Launched | 10 December 2024 |
| Exam window | 10 days of lab access |
| Pass requirement | 90 points, plus an accepted report |
| Format | Hands-on VPN lab, via Pwnbox or your own VM |
| Book policy | Open book |
| Report | Commercial-grade, on the HTB template, marked by an HTB Academy instructor |
| Prerequisite material | Active Directory Penetration Tester job-role path, 15 modules |
| Attempts | Two per voucher |
The subject matter is narrow and deep: enumeration, lateral movement, domain privilege escalation, Kerberos attacks, DACL abuse, NTLM relay, command-and-control infrastructure, evasion and post-exploitation.
Exam Tip: The 90 points are only half the requirement. An instructor reads your report, and a passing point total with an unacceptable report is not a pass. Budget the report as a deliverable, not as paperwork.
Start With an Honest Prerequisite Check
The Active Directory Penetration Tester job-role path runs to 15 modules, and it is not a formality. Candidates who arrive from CPTS often assume their general pentesting background will carry them, then discover that CAPE expects fluency in attack primitives CPTS only introduces.
Before week one, check that you can do these without looking anything up:
- Explain what a Kerberoasting ticket actually contains and why the hash is crackable
- Read a DACL and identify which ACE gives you a path to a higher-privileged object
- Describe the difference between unconstrained, constrained and resource-based constrained delegation
- Relay NTLM authentication and say what conditions make the relay possible
- Get a beacon out of a network that is watching outbound traffic
If more than one of those is shaky, add two weeks to the plan below rather than compressing them.
The 10-Week HTB CAPE Study Plan
The plan assumes 10 to 12 hours a week. It front-loads the theory and back-loads the practice, because CAPE rewards recall speed in the lab far more than it rewards breadth.
Weeks 1 to 2: Enumeration Until It Is Boring
Work through the enumeration modules of the AD path and build a repeatable collection routine. Your goal is a single documented process that takes you from initial foothold to a full picture of users, groups, ACLs, trusts, sessions and delegation settings.
Write that process down as a checklist now. You will use it on day one of the exam when you are least likely to think clearly.
Weeks 3 to 4: Kerberos and DACL Attacks
These two areas carry a large share of the exam's point value. Cover Kerberoasting, AS-REP roasting, delegation abuse and ticket forging, then move to DACL and ACE abuse chains.
Practise chaining rather than executing single attacks. CAPE paths are rarely one hop.
Week 5: NTLM Relay and Coercion
Relay attacks are where lab habits break down, because they depend on conditions you must confirm rather than assume: signing settings, coercion methods and which listener maps to which target. Build a decision tree for when a relay is viable.
Weeks 6 to 7: C2 and Evasion
Set up your own command-and-control infrastructure and get comfortable with the operational side: listener configuration, payload staging, sleep and jitter, and getting traffic out of a restricted segment. Practise recovering from a dead beacon, because you will lose one during the exam.
Week 8: Multi-Domain and Trusts
The exam environment spans more than one domain. Study trust relationships, cross-domain privilege escalation, and how a foothold in a child domain becomes control of a forest. Build a small multi-domain lab if you can, or repeat the path's trust material until the attack paths are automatic.
Week 9: Full Dry Run
Give yourself a compressed, timed run against a hard Active Directory target or an HTB Pro Lab. Take notes exactly as you would in the exam, with screenshots and commands captured as you go rather than reconstructed afterwards.
Week 10: Report Practice and Consolidation
Write a full report from your week 9 notes, using Hack The Box's template. This is the week most candidates skip, and it is the reason report failures are so common.
Then rest. Do not start the exam on the day you finish studying.
How to Pace the 10-Day Exam Window
Ten days sounds generous. It stops sounding generous around day four, when a path you were confident about turns out to be a dead end.
A workable shape:
- Days 1 to 2: Enumeration only. Run your checklist across everything reachable. Resist the urge to exploit anything you have not fully mapped.
- Days 3 to 6: Exploitation and lateral movement. Bank points as you go. Take the reliable path before the interesting one.
- Day 7: Review your point total honestly against the 90-point requirement, and decide where the remaining points are cheapest.
- Days 8 to 9: Write the report. Not draft it. Write it.
- Day 10: Fill gaps the report exposed, then submit.
Exam Tip: Screenshot and log every command at the moment you run it, with the host and timestamp visible. Rebuilding evidence on day nine for an exploit you ran on day three costs more time than the exploit did.
The Report Is the Real Exam
Hack The Box asks for a commercial-grade report because the certification is meant to prove you could hand the document to a client. An HTB Academy instructor assesses it.
What that means in practice:
- Every finding needs reproducible steps, not a narrative of what you tried
- Impact has to be written in business terms, not "attacker gets domain admin"
- Remediation advice must be specific to the misconfiguration you found
- The attack path needs to read as a chain, showing how each step enabled the next
If you have only ever written HTB writeups, the register is different. A writeup explains a puzzle. A report tells an organisation what is wrong with its estate and what to do about it.
HTB CAPE vs OSEP: Which Advanced Cert Fits
"htb cape vs osep" is one of the most common searches around this certification, and the two are genuinely close in level while differing in focus.
| HTB CAPE | OffSec OSEP | |
|---|---|---|
| Focus | Active Directory exploitation in depth | Evasion and bypassing defences |
| Exam length | 10-day window | 48 hours, plus report time |
| Environment | Multi-domain Active Directory | Mixed, with heavy AV and application allowlisting |
| Book policy | Open book | Open book |
| Best for | AD-heavy internal pentest roles | Red team roles where evasion is the constraint |
Pick CAPE if your work is internal network testing against Windows estates. Pick OSEP if your obstacle is getting past defensive tooling. If you are choosing what comes after OSCP more broadly, our guide on what to take after OSCP compares the wider field.
Frequently Asked Questions
What is CAPE certification?
HTB CAPE is the Hack The Box Certified Active Directory Pentesting Expert certification. It is a hands-on credential earned by compromising a multi-domain Active Directory environment during a 10-day exam window, reaching 90 points, and submitting a professional penetration test report that an HTB Academy instructor accepts.
What certifications does Hack The Box offer?
Hack The Box Academy currently certifies at several levels, including CBBH for bug bounty hunting, CDSA for defensive security analysis, CPTS for general penetration testing, CWEE for web exploitation and CAPE for Active Directory. CAPE and CWEE sit at the expert end of the range. Our HTB CPTS study plan and HTB CDSA study plan cover the two most common starting points.
How much does the HTB CAPE exam cost?
An exam voucher is included with a Hack The Box Academy Gold Annual subscription, and can otherwise be bought separately from the Academy billing page. Each voucher carries two attempts. Hack The Box changes pricing and runs periodic discounts, so check the Academy billing page for the current figure rather than relying on third-party listings.
Is HTB CAPE harder than CPTS?
Yes, and by a clear margin. CPTS tests broad penetration testing competence across a mixed environment. CAPE narrows the scope to Active Directory and then goes several levels deeper, expecting fluency in Kerberos attacks, DACL abuse, NTLM relay and cross-domain trust exploitation.
Do I need to complete the whole job-role path first?
The Active Directory Penetration Tester path is 15 modules and is the material the exam is built on. Completing it is the intended route. Skipping modules because a topic looks familiar is the most common reason candidates find gaps mid-exam.
Ready to Start Practising?
The candidates who pass HTB CAPE are the ones who arrive with an enumeration checklist they trust and a report template they have already used once. Both are built during the 10 weeks, not during the 10 days.
If you are working towards Active Directory and penetration testing roles more broadly, CertCrush practice questions cover the underlying certifications on the same path, including CompTIA PenTest+.
Create your free CertCrush account and start practising today.
