Zum Hauptinhalt springen

15-week roadmap: calendar and HTB Academy mapping

The tests-intrusion course is calibrated for 15 weeks at 4 hours of class time per week, roughly 60 hours of student time. This layout matches a Canadian or French undergraduate university course on a full semester, or a professional continuing education program spread over three to four months.

Each week combines:

  • A concepts lesson — vocabulary, methodology, definitions (~ 45 min of reading).
  • A guided demonstration — an exploit or attack chain seen end to end (~ 45 min of reading + follow-along).
  • A hands-on lab — you replay the exercise on our local Docker lab (~ 2 h of hands-on).
  • A module quiz — 5 questions to check retention (~ 15 min).
  • One or several HTB Academy modules to complete on your own at home (~ 4 to 8 h per module).

The total exceeds 4 h/week if you also complete the HTB Academy modules — plan for 8 to 10 hours per week if you want to seriously prepare the CPTS.

The thematic map of the path

Six blocks chained together, each building on the previous. There is no reasonable shortcut that skips a block: Active Directory lateral movement (W11) assumes that you already mastered Metasploit (W9) and privilege escalation (W10).

The week-by-week mapping

Wk.ThemeThis course moduleHTB Academy modulesTotal hours
W0OrientationM00 — Orientation, labs and certifications(background reading)2 h
W1Kali environmentM01 — Introduction & KaliGetting Started, Learning Process, Linux Fundamentals8 h
W2Methodology & ROEM02 — Planning & rules of engagementPenetration Testing Process6 h
W3OSINTM03 — Open-source intelligenceInformation Gathering – Web Edition, DNS Enumeration Using Python8 h
W4Active scanningM04 — Active reconnaissanceNetwork Enumeration with Nmap, Footprinting8 h
W5VulnerabilitiesM05 — Vulnerability research and prioritizationVulnerability Assessment6 h
W6Social engineeringM06 — Social engineering & human factorLogin Brute Forcing + concepts (no dedicated HTB module)6 h
W7Web OWASP (first half)M07 — OWASP Top 10 (part 1)Using Web Proxies, SQL Injection Fundamentals, SQLMap Essentials, Cross-Site Scripting (XSS)10 h
W8Web OWASP (rest) + mid reviewM07 (part 2) + mid-term reviewFile Inclusion, File Upload Attacks, Command Injections, Web Attacks, Attacking Web Applications with Ffuf, Hacking WordPress10 h
W9Automation & MetasploitM08 — Metasploit and automationUsing the Metasploit Framework, Shells & Payloads, Introduction to Bash Scripting10 h
W10Privilege escalationM09 — Linux and Windows privescPassword Attacks, Cracking Passwords with Hashcat, Linux Privilege Escalation, Windows Privilege Escalation10 h
W11Lateral movementM10 — Lateral, pivoting, Active DirectoryPivoting, Tunneling & Port Forwarding, File Transfers, Active Directory Enumeration & Attacks, Active Directory LDAP, Kerberos Attacks12 h
W12Cloud, mobile, IoTM11 — Cloud, mobile & IoT + WPA2 bonusAttacking Common Services, Attacking Common Applications (+ external cloud resources)10 h
W13Report and deliverableM12 — Report & recommendationsDocumentation & Reporting6 h
W14Offensive code analysisM13 — Code analysis (SAST / DAST)Introduction to Bash Scripting, DNS Enumeration Using Python (code reading)6 h
W15Final missionInternal CTF project / mock examAttacking Enterprise Networks (CPTS-style capstone)12 h

Total student tempo: about 130 hours, of which 60 in this course (lessons + labs + quizzes) and 70 in HTB Academy. If you add occasional TryHackMe rooms for catch-up and 5 to 10 HTB Labs machines, plan for 160 to 180 hours total over 15 weeks.

On a standard week (W3 to W13, excluding review weeks):

DayDurationActivity
Monday45 minConcepts lesson of the week's module
Tuesday60 minGuided demonstration + command reading
Wednesday2 hHands-on lab on the local Docker lab
Thursday2 hMatching HTB Academy module (graded exercises)
Friday30 minModule quiz + summary notes
Saturday2 hMore HTB Academy or TryHackMe catch-up room
SundayBreak

This rhythm respects the rule of 20 hours studied over 5 spaced days that produces the best retention in cybersecurity, according to SANS 2023 and 2025 surveys.

Thematic progression at a glance

Foundations (W1–W2): you set up and you scope. Kali Linux, VM isolation, vocabulary (vulnerability, exploit, impact), penetration testing methodology, and rules of engagement (ROE) formalized with the client.

Reconnaissance (W3–W5): you learn to map a target quietly (OSINT), then to scan actively (Nmap, Footprinting), then to sort vulnerabilities by risk (CVE, CVSS, EPSS).

Attack vectors (W6–W8): you add the human factor (social engineering, phishing) and you dive into web security via the OWASP Top 10 (SQL injection, XSS, file inclusion, file upload, command injection).

Exploitation (W9–W11): you automate (Metasploit, bash), you escalate privileges (Linux and Windows), you move laterally in an Active Directory environment (Kerberoasting, pivoting).

Post-exploitation (W12–W13): you extend to modern environments (AWS/Azure/GCP cloud, Flutter/Android mobile, WiFi IoT with the WPA2 bonus), then you write the final client report that is the real deliverable of any pentest.

Reporting (W14–W15): you audit code (SAST with Semgrep, DAST with Burp), then you apply everything on a CTF-style final mission that mirrors the CPTS exam format.

What to remember

  • 15 weeks at 4 h + 4 to 6 h of personal work = 8 to 10 hours weekly total.
  • 60 hours in this course, 70 hours in HTB Academy, 20 to 40 hours in complementary labs (HTB Labs, TryHackMe).
  • Each module of this course maps to one or several HTB Academy modules in the Penetration Tester Path.
  • The recommended pace is 5 sessions per week of 30 to 120 minutes, respecting the SANS rule of spaced repetition.
  • At the end of 15 weeks, you have covered 100 % of the CPTS program — 6 more months of training are then required for a high first-attempt pass rate.

Next step

You have finished module 0. You can now move to Module 1 — Introduction & Kali, which starts the technical content of the course with the installation of your isolated lab and your first SYSTEM shell.