HTB CPTS Exam Guide: Conquering Flags 4, 5, and 6
HTB CPTS Exam Guide: Conquering Flags 4, 5, and 6
Category: Hack The Box Certification Series • Advanced Tactics • Read Time: 10 min
Once you breach the perimeter and establish your initial footholds in the HTB CPTS exam environment, the assessment shifts heavily toward deep network pivoting, advanced Windows privilege escalation, and lateral movement. Flags 4, 5, and 6 test your ability to navigate segmented subnets, analyze complex local configurations, and harvest post-exploitation artifacts.
Relying purely on automated tools will cause you to stall in this phase. This guide breaks down the core methodologies required to systematically conquer this mid-stage progression without relying on blind luck.
- Flag 4: Internal Network Triage (Establishing stable proxy chains, enumerating internal-only services, and expanding the attack surface)
- Flag 5: Advanced Privilege Escalation (Moving beyond basic checks, analyzing specialized configurations, and securing administrative control)
- Flag 6: Post-Exploitation & Lateral Traversal (Harvesting user artifacts, identifying internal domain patterns, and preparing for the next pivot)
1. Deep Network Mapping & Internal Triage
After compromising a DMZ host, your perspective of the network changes entirely. You must establish a stable dynamic proxy to interrogate internal subnets that were previously shielded by firewalls. The key to Flag 4 is meticulous enumeration of these newly exposed services. Do not assume the internal network is flat or lightly secured; treat it with the same rigorous scanning methodology as the external perimeter.
[Use your preferred tunneling tool e.g., Chisel, SSH, or Ligolo-ng]
# General Methodology: Enumerate Internal Interfaces
[Execute targeted port scans through your established proxychain]
# General Methodology: Service Analysis
[Investigate internal file shares, web applications, and administrative consoles]
2. Advanced Windows Privilege Escalation
Standard Windows privilege escalation checks—like unquoted service paths or simple missing patches—are often dead ends in advanced certification labs. To secure Flag 5, you must look deeper into how the operating system is uniquely configured for its specific business purpose. This often involves auditing assigned user rights, checking for non-standard software deployments, or identifying logical flaws in how services interact with one another.
whoami /all
# System Configuration Baseline
systeminfo | findstr /B /C:"OS Name" /C:"OS Version"
# Analyze the results for non-standard configurations or elevated rights
[Develop and transfer appropriate escalation payload based on findings]
Need the Complete Attack Chain?
Don't get stuck trying to guess the correct escalation path or fighting with double-pivot routing. Our comprehensive CPTS exam report includes the exact methodology, full terminal screenshots, and guaranteed command syntaxes to keep you moving forward.
Unlock the Full CPTS Methodology Report →3. Post-Exploitation Artifacts & Lateral Movement
Once you achieve Administrator or SYSTEM access on a host, the phase is not over. You must immediately transition into artifact harvesting. Users frequently leave valuable data behind in hidden directories, application session files, or custom scripts. Flag 6 relies on your ability to thoroughly pillage the compromised machine, piece together the extracted information, and utilize those findings to authenticate against the next target in the network chain.
dir /a /s C:\Users\<TARGET_USER>\
# Review Installed Applications for Potential Credential Storage
[Check common developer tools, browsers, and configuration files]
# Utilize Recovered Data for Lateral Traversal
[Authenticate to adjacent subnets using discovered credentials]
LoKiTheWar: All At One Place
The LOKI Store is your central hub for elite penetration testing resources. Access verified exam methodologies, enterprise reporting templates, and complete walkthrough archives for CPTS, OSCP+, and Active Directory certifications.
Get the Complete CPTS Report Now