Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

HTB CPTS: technical exam workflow and pentest report

HTB CPTS tests a complete infrastructure pentest and commercial report. Learn path requirements, the ten-day exam and an evidence workflow.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
19 June 2026
READING TIME
9 min read
TOPIC
Careers and Certifications
HTB CPTS: technical exam workflow and pentest report

HTB CPTS is a practical certification following the HTB Academy Penetration Tester path. Starting the exam requires 100% path completion and a voucher. The current CPTS deadline is ten days.

Assessment outcome

Candidates test from an entry point, reach the required score and submit a commercial-grade actionable report in English. Documentation covers methodology, evidence, risk and remediation.

The scope is broad: enumeration, web, Linux and Windows, pivoting, Active Directory and credentials. Maintaining a dependency map across several days is a central challenge.

Workflow

Build a graph of hosts, subnets and identities. Record every credential with its source and confirmed reach. Re-enumerate visible services after each new access level.

Develop the report daily. HTB accepts an unencrypted PDF or ZIP up to 20 MB through the dashboard. Final submission terminates the lab and cannot be replaced.

After a failed attempt, a report is still required to remain eligible for the second attempt. Convert feedback into regression tests and runbook changes.

Readiness

Path completion is a prerequisite, not proof of readiness. Complete several multi-host networks without walkthroughs and report in parallel.

CPTS emphasises depth and documentation. Compare it with OSCP+ and PNPT before choosing a route.

Managing the ten-day window

A long window does not justify unstructured testing. Use the opening portion for inventory and dependency mapping, the middle for validating attack paths, and the final portion for closing evidence gaps and reviewing the report. End each day with a short balance: confirmed facts, rejected hypotheses, missing proof and the first action for the next session.

Keep separate directories for hosts, scans, loot, screenshots and report versions. Label every credential with its owner, source and confirmed scope. In a large network, the wrong user context creates false conclusions and repeated enumeration.

Professional report standard

HTB requires an English report. It must stand alone: a reader should understand scope, method, limitations, risk summary, detailed findings and the complete technical path without access to private notes. Link each finding to evidence and a specific recommendation; do not assign severity from the technique name alone.

Before final submission, verify that the file is unencrypted, within the current size limit and opens on another device. Official guidance states that final submission closes the lab, so all evidence must already be saved. If the first attempt is unsuccessful, submitting the report remains necessary to retain the second attempt.

Readiness criteria

Complete 100% of the learning path, then test the skills in a new environment. You should enumerate services without tunnel vision, maintain pivots, return to earlier evidence and write in parallel. A rehearsal must also reserve time for language review, screenshot checks and PDF export.

CPTS primarily validates a coherent process. Gaining access without documenting it or explaining the impact does not complete a professional penetration test.

Attack-path completeness control

For each new host, review services, operating system, interfaces, routes, users, sessions and local rights. Then return to the whole-network graph: new access may unlock a resource overlooked hours earlier. Apply a consistent checklist while adapting tests to evidence; mechanically running every tool creates noise.

Document every pivot by entry point, target network, tunnel mechanism and verification method. Save configuration and commands on both ends. If routing fails, isolate session, listener, forwarding, DNS and firewall before rebuilding the chain.

Before export, cross-check that every conclusion has evidence, each screenshot is referenced and every recommendation addresses the stated condition. Open the final PDF from a separate directory and verify contents, images, links and code readability.

Keep a decision log explaining why a path was prioritised and what caused it to be abandoned. It does not all belong in the report, but it exposes personal bias and improves the next multi-host assessment.


Sources: HTB Academy Certifications, HTB Enterprise Certifications.

SHARE / COPY