CAPenX Exam Prep & Study Resources

The SecOps Group certification · 1 product

Certified AppSec Pentesting eXpert

Study materials for CAPenX

Frequently asked questions

What is HTB CAPE?

CAPE (Certified Active Directory Penetration Expert) is Hack The Box's advanced certification focused entirely on Active Directory security. It targets the techniques used by red teams and sophisticated threat actors to compromise enterprise AD environments, covering enumeration, attack chain development, lateral movement, privilege escalation within domains, and full domain compromise. CAPE is designed for experienced offensive security professionals who want to demonstrate expert-level Active Directory exploitation skills validated through a rigorous practical exam.

How hard is HTB CAPE?

CAPE is one of HTB's most challenging certifications, positioned at the advanced end of their certification track. It requires deep knowledge of Active Directory internals, Kerberos authentication mechanics, modern evasion techniques, and the ability to chain multiple subtle misconfigurations into domain-level compromise. Candidates without extensive prior AD attack experience, including hands-on practice in realistic enterprise lab environments, will find the exam extremely difficult. CAPE is not intended for beginners or intermediate practitioners; it targets experienced red teamers and senior penetration testers.

What topics does CAPE cover?

CAPE covers the full spectrum of Active Directory attack techniques at an advanced level. Topics include Kerberoasting and AS-REP roasting, DCSync attacks, Pass-the-Hash and Pass-the-Ticket, Golden and Silver Ticket attacks, ACL and ACE abuse for privilege escalation, domain trust exploitation, Active Directory Certificate Services (ADCS) attacks, lateral movement through complex multi-system environments, BloodHound-based attack path analysis, and modern evasion techniques for bypassing security controls commonly deployed in enterprise AD environments.

Prerequisites for CAPE?

CPTS or equivalent penetration testing experience is the recommended baseline for CAPE. Strong foundational knowledge of Windows administration, Active Directory architecture, and Kerberos authentication is required. Hands-on experience with tools like BloodHound, Impacket, Rubeus, and Mimikatz is expected. Prior red team experience in realistic AD environments, either through HTB Pro Labs or professional engagements, is strongly recommended. Candidates without this background should build AD attack skills through resources like CRTP, CRTE, or HTB Pro Labs before attempting CAPE.

Is CAPE worth it?

Yes, for advanced offensive security professionals who specialize in enterprise Active Directory environments. CAPE is a rigorous, respected credential that demonstrates expert-level AD attack skills applicable in high-end penetration testing and red team operations. As organizations increasingly harden their AD environments with tools like Microsoft Defender for Identity and tiered administration models, demonstrated expertise in navigating these defenses becomes more valuable. CAPE validates exactly those skills, making it a strong differentiator for senior offensive security professionals.

How long to prepare for CAPE?

Three to six months of focused Active Directory attack study is typically required for experienced professionals to prepare for CAPE. Completion of the HTB Academy Active Directory attack modules provides a strong foundation, and hands-on practice in HTB Pro Labs (particularly RastaLabs, Offshore, and Cybernetics) is highly recommended to build the speed and intuition needed for the exam. Candidates should ensure they are comfortable executing the full AD attack chain, from initial enumeration through to domain controller compromise, in a realistic environment before scheduling their exam.

Related

All The SecOps Group certifications · Browse cheatsheets