Skip to content
HackTheBox Certified Defensive Security Analyst (CDSA)

Conquer the HackTheBox CDSA Certification: Tips and Insights

March 2025HackTheBoxPassed
Certification
CDSA
Provider
HackTheBox
Difficulty
Intermediate
Rating
★★★★½4.8/5.0
Introduction

HackTheBox (HTB) is a well-known cybersecurity platform where you can legally "hack" into virtual machines, testing and improving your penetration testing skills. Beyond that, HTB also offers a learning platform called HackTheBox Academy. With an existing HTB account, you can log in via SSO and access a wide range of modules covering offensive and defensive security, as well as foundational topics like Windows, Linux, macOS, and more.

HTB also provides certifications to validate skills for various career paths, including Bug Bounty, Penetration Testing, Web Exploitation, Active Directory Penetration Testing, and, most importantly for this blog, the SOC Analyst path.

The HTB Certified Defensive Security Analyst (CDSA) certification, launched in September 2023, focuses on skills essential for SOC Analysts and is the highlight of this article.

So without further ado, let's explore what this certification has to offer and what it takes to get certified!

WARNING: A LOT OF TEXT ahead. Grab a coffee. ☕
Exam Prerequisite & Strategy

To be able to take the HTB CDSA exam, you need to enroll in and complete the SOC Analyst Path, which has a total of 15 modules combined, costing 1,190 cubes to unlock them all. I've already calculated which approach gives you the best value for money and the most preparation time while spending less than a yearly subscription.

HTB Academy annual subscription tiers comparison
Figure 1

First, let's talk about the annual subscription. HTB Academy has 2 types of annual subscriptions as shown in the figure above, and both can access the SOC Analyst path since there are no Tier 3 or Tier 4 modules in this path. Getting the Gold Annual is overkill for CDSA, which means the only sensible choice here is Silver Annual.

HTB Academy Silver Annual subscription details
Figure 2

The Silver Annual doesn't limit you to the SOC Analyst path: it also covers all Tier 2 modules and below, including the Bug Bounty Hunter path and Penetration Tester path. If you don't want to limit yourself to just blue team work and can commit to studying for a full year, this subscription is for you. It also includes step-by-step module solutions and 1 exam voucher (2 exam attempts: first try plus one retake). It's best if you can get your employer to cover the cost.

HTB Academy monthly subscription options
Figure 3

Now let's talk about the monthly subscription plus exam voucher option. You won't get step-by-step solutions with this option, but it's the better value if you only want to tackle the SOC Analyst path and CDSA exam, just like I did.

The Student tier is the best bang for your buck here. You can access all Tier 2 modules and below, just like Silver Annual, while paying only $8 per month. If you have an educational email address, definitely use it to work through all the Tier 0–2 modules available to you.

HTB Academy Student tier and PwnBox usage details
Figure 4

Before we compare options, one more thing worth considering is PwnBox: HTB's pre-built Parrot VM that learners can access via the browser. With PwnBox, you can access Academy labs from anywhere, including your workplace. That said, if you already have your own workstation (which you really should), connecting to the lab via VPN is sufficient.

Now you might see why PwnBox factors into this calculation. Another thing to factor in is the cube reward for completing modules. The strategy here is to get 1,000 cubes, unlock 10 Tier 2 modules and complete them, and you'll get 200 cubes back: enough to unlock all the rest, complete the path, buy an exam voucher ($210, valid for 365 days after purchase), and take the exam. Here's a breakdown of your options:

  1. 1 month of Platinum (Total: $278 USD). The lowest upfront cost outside of the Student tier. Only one month of PwnBox, but you can unlock all modules in the path with a single purchase.
  2. 5 months of Silver (Total: $305 USD). Best for people who need PwnBox access and can't afford to pay for a full month of Platinum at once. Think of it as an installment plan.
  3. 2 months of Gold (Total: $286 USD). Slightly pricier than the first option, but it breaks the mental barrier of a single large payment. A compromise between options 1 and 2: you get 2 months of PwnBox and can still unlock all modules in the path.

Note that all totals above already include the exam voucher price. To see the subscription-only cost, deduct $210 from any figure.

The choice is yours. Now let's talk about the modules I recommend you immerse yourself in: they'll make a real difference in the exam.

Exam Preparation

As mentioned above, you have a total of 15 modules to complete before taking the exam. Here are the ones I particularly emphasized. Spend real time fully understanding the context and content of each:

  • Introduction to Threat Hunting & Hunting with Elastic: especially the Hunting with Stuxbot section and the Skills Assessment
  • Windows Event Logs & Finding Evil: especially Analyzing Evil with Sysmon & Event Logs and the Skills Assessment
  • Understanding Log Sources & Investigating with Splunk: the whole module is a gem
  • Detecting Windows Attacks with Splunk: the whole module is a gem; take notes and keep all queries in your cheatsheet
  • Introduction to Digital Forensics: especially Memory Forensics, Rapid Triage Examination & Analysis Tools, the Practical Digital Forensics Scenario, and the Skills Assessment
  • Windows Attacks & Defense: the whole module is a gem
  • Security Incident Report: especially the Real-world Incident Report section

Beyond the Academy modules, you can also practice in labs that have Splunk or Elastic available to help you get comfortable with SIEM, since you'll be spending the most time there, followed closely by Volatility. Practicing with labs from Blue Team Labs Online (BTLO) or CyberDefenders.org will build both skill and confidence heading into the exam.

HackTheBox Sherlocks — practice for CDSA
Figure 5

Another question people often ask: "Can we practice for CDSA using Sherlocks?" My answer is Yes and No. Sherlocks will help you build a digital forensics mindset and sharpen your skills, but the volume of evidence provided is nowhere near what you'll face in the exam, and there's no time limit unless you set one yourself.

HTB Sherlocks list
Figure 6

Note: this next part is for "PEOPLE WHO CAN SPEND MONEY WITHOUT WORRYING ABOUT IT" only. If budget isn't a concern, or you want to spend more to boost your confidence, I recommend participating in The DFIR Labs CTF or working through their cases using Splunk and Elastic. I participated in the DFIR Labs CTF during March 2025 and it was the most enjoyable DFIR-style CTF I've ever done: it also boosted my confidence and fired up my motivation to keep learning.

The DFIR Labs CTF — store page
Figure 7

One important point about DFIR Labs cases: access is purchased on a time basis. To best simulate the actual CDSA exam environment, I recommend working on two cases (one using Splunk and another using Elastic), opting for 2-day access on each, giving you a total of 4 days in the labs. Then spend 2–3 days practicing report writing, aligning with the 7-day timeframe of the real CDSA exam.

DFIR Labs case access and time-based pricing
Figure 8

Speaking of the report: you'll need to write a single report covering 2 incidents, and the formatting must strictly follow HTB's format. I recommend using SysReptor, which already has a template for all HTB exams: you can use their free cloud service (for HTB exam reports only) or self-host it. That said, you can absolutely write the report without SysReptor. You'll receive a report template when you start the exam, so your favorite Microsoft Word works just fine, just save it as a PDF before submitting.

With that, let's talk about my experience with the exam.

Exam Experience
CDSA exam start — environment overview
Figure 9

I originally planned to take this exam around August 2025, but thanks to a lot of "encouragement" from my friends, I changed my plan and scheduled it for 20:00 on 14th March 2025: a time when I could take two days off work and be well-rested going in.

HTB CDSA exam scheduling
Figure 10

As it turned out, I took a sick day that day: I was ill with a severe headache and couldn't go to work. The plan was still the plan, though: I slept and expected to recover before the scheduled start time. I woke up at 12:00 to a message from a friend asking "How was your exam?" I don't quite remember what I was thinking in that moment, but I told him: "Let me have breakfast first, then I'll tell you after I start." That led to me kicking off the exam an hour and a half later than planned.

CDSA exam environment initialization
Figure 11

After starting the exam, I was presented with all the information needed to access the exam environment, including the initial brief, exam guide, all flags that needed to be submitted, and the report template. I began by accessing the exam environment and taking a quick look at what I had to work with.

After exploring the environment and discovering the evidence and tools available, I jumped straight into Incident 1. Within 7 hours, I had submitted all 20 flags, scoring a perfect 100%. That huge confidence boost had me thinking: "Maybe I can finish both incidents in a single day?"

CDSA 20 flags submitted — 100% score on Incident 1
Figure 12

As you might have guessed, I managed to complete my initial findings for both incidents on the first day. Why "initial"? Because over the next two days, I focused on writing my report, and during that time, I had to revisit the exam environment to retake screenshots and fill in missing details. Writing the report made me realize I had overlooked some obvious elements that needed to be addressed. But the more time I spent on the exam, the more the headache and illness began to creep back, so I pushed through, finished my report on day 3, submitted it, and rested for the remainder of the day.

CDSA report writing process
Figure 13

And don't get me wrong, the exam is not "easy," but it was manageable for me. I had spent 2 months completing 180 labs from BTLO while working full-time, so my body and focus were already trained for sustained effort. The same may not apply to everyone, so take your time and don't rush to finish.

Since the review process can take up to 20 business days (Monday–Friday), I expected my result sometime during Thailand's Songkran week, between 13th and 18th April 2025.

Waiting for CDSA exam result
Figure 14

Then, during a workday on 27th March 2025, I received an email with my exam result, and as you can see, I passed! I wasn't alone either: many people on the HackTheBox Discord were reporting passes at the same time, which revealed that HTB grades and releases results in batches. You won't get certified in isolation if many people took the exam around the same period as you.

CDSA exam result email — Passed
Figure 15

Upon logging back into the Academy, I was able to specify the name I wanted displayed on my certification.

HTB Academy — specify name for certification
Figure 16

Once I specified my name, it appeared on the certification preview as shown above. I could go back to edit it or confirm by clicking "CLAIM CERTIFICATION."

CDSA certification preview with name
Figure 17

With the certification claimed, it became available to download. A link to the HackTheBox store was also generated for certification holders: you can order a certification package that includes a physical certificate, frame, 2 stickers, 1 pin, and a themed T-shirt in your specified size.

HTB certification store — physical package options
Figure 18

You'll also receive feedback from the examiner who graded your report, which you can review in your exam history.

HTB exam history — examiner feedback on report
Figure 19

HackTheBox will also send out a badge via a separate email, which you can accept on Credly and share on social media, in addition to the digital certification downloadable from the Academy.

CDSA Credly badge email
Figure 20

Lastly, if you want to look cooler on the HackTheBox Discord, type the /verifycertification command followed by your certification ID (found in the top-right corner of your certificate) and your real name, and boom, you'll have a custom CDSA holder badge on the HackTheBox Discord!

Exam Tips & Key Takeaways
  • Explore the exam environment first: find your tools and evidence before diving into investigation.
  • Know your tools: what each one does and what output you should expect from it.
  • Know your evidence: what story each piece can tell and how to pivot between sources to build complete findings.
  • Start with Incident 1: it will give you a massive confidence boost if you make solid progress early.
  • Don't be too hard on yourself. Don't fixate on a single flag for too long.
  • Take breaks and come back with fresh eyes when you get stuck.
  • Use SysReptor for report writing: it has an HTB exam template ready to go.
  • Write a brief description for each screenshot as you take it. It will save you time when writing the report.
  • Keep all of your queries saved. Linking each query to its corresponding screenshot is extremely helpful during report writing.
  • Write the report as you go through the investigation: you may come up with new angles and need new screenshots to support your findings.
  • Build a timeline as you investigate. It keeps you oriented and prevents you from retracing the same steps.

That's my key takeaway for those studying and preparing for the HTB CDSA exam. Good luck!

Peace Out~ ✌