My Past Is Not My Future

I still remember like it was yesterday: on a friday morning, at 8AM, sitting on a table at a pastry shop realizing wtf have I been doing with my life.

For some context, at this point, I have been desiring for some (hardcore) change in my life. Don’t get me wrong, I had “stable job” (does it exist nowadays?) with a salary, and quitting it just because I was “sad”, seemed like a shot in the foot.

I am a strong believer that, to get different results, you actually need to commit to different actions.

And this ancient and wise wizard logo from CAPE have been popping on and off my mind for quite some months. At this point I already had the OSCP certification, but my contact with AD has been only some controlled-labs I have been doing for quite some time and the exam labs from that certification.

But it was enough. The craziness that was in all the fields of my life and the spark that have been growing within me fueled my desire for change (or was hit the sunlight hitting my eyes?).

Then, something clicked.

I had to become the version of me that has it all. And that version was nowhere on the point I was or in the path I was walking on.

I was decided, and the journey started in January 2026. To fully commit to it, I quit my past job and fully embraced the madness I was proposing myself to. ~8 hours a day (sometimes weekends) of just studying, researching and note taking.

Little did I know I was going to suffer from one of the strongest windstorms ever in my country and being without internet for 3 months…

My goal was set and when that happens, nothing can stop me. I decided to move to a friend’s apartment for that “reconstruction week” that turned into 3 months!

The Study Journey

The path consists of 16 modules, ranging from generic AD and Windows knowledge to the most atomic property of a ticket request operation.

For a first, I decided to take the estimate number of days to complete a module as a hard rule. If you want to start this journey, please, DON’T DO THAT ASSUMPTION. Everyone has his own methodology, mentality, notetaking and life still happens outside the computer. So no, don’t take those days as a rule of thumb.

On the first module, instead of the estimated 7 days, I took almost 14!

Not because I did not understand or know the concepts, but because I was determined to make it and pass the exam. And because of that, I changed my notetaking methodology.

Notetaking is one of the most important aspects of my success in achieving, memorizing and redo some task.

I use Obsidian to take them but the “module per page” approach was becoming very messy for my taste. That is because the modules are not isolated in space. Module 1 can contain generic information about PowerView, but there is also a fully made module for that tool also.

My take on this?

Create pages by context and link them. I have pages for the actual topic, description and functioning, but also I link them to other topics on other pages that arise and to the different tools that might help achieving an exploit or a further enumeration, for example.

I was familiar with most of the tools, NetExec, BloodHound, the Impacket framework, but the in-depth knowledge I got from the modules was insane.

I can say easily that my favorite modules were: Kerberos Attacks, NTLM Relay Attacks, Active Directory Trust Attacks and ADCS Attacks.

But, for sure, CAPE exam was not made only using techniques you like, and believe me, you will hate a lot of thing. A LOT!

Reading similar blogposts online, I knew I had to pay special attention to the Evasion Techniques Module, which I, as a normal human being, did (not). What did it cost? Fortunately almost nothing, besides some stress, hair loss and time consuming tasks like payload obfuscation for common tools that could be done in days prior to the exam…

But I managed to create them! Still to this day, I have these .exe sitting on my fully updated Windows machine, just waiting to see if someday Windows will detect them.

The content presented in the path is powerful, extensive and very very detailed. Don’t expect to just take the exam when you know 100% of it, because you will not. That is why we create notes. Even today, there are topics that get me confused.

But not everything is beautiful and this part is also a rant.

Some modules are deprecated and even obsolete. I can’t still understand why HackTheBox did not give some love to them. And the thing is, these two are precisely two of the most important ones, CrackMapExec that “is no longer mantained due to the existence of a hostile fork” (I just love this sentence, sorry!), NetExec, and the mighty BloodHound.

For the CrackMapExec one, the change is pretty simple, the command is nxc instead of cme and that is pretty much it besides some minor module changes. You can work around easily. But BloodHound? Oh boy…

BloodHound module is a complete nightmare due to the way module completion works. On HackTheBox, you can only complete a module if you answer correctly the final questions at the end of the pages. And this is the problem.

BloodHound is now a community edition version, leaving behind the legacy version of it. that means that, when you extract information from the Domain Controller, the way it saves the edges and all that kind of information is different. You can still import old legacy data into the community edition, but a lot (and I mean, A LOT) of information is lost. A simple example was a question asking what was the edge between to nodes and I didn’t have any. I spent 2 hours trying to figure out what was wrong just to check the answers (I paid for the 1y subscription) to find out I was not seeing the same information. A module of this magnitude should, for sure, receive some loves. The principles between versions apply but the way you visualize and gather data are completely different. A BloodHound-CE Module is due a long time ago… For this, I had to boot up a vm just to install legacy BloodHound and finish the questions with the provided data.

Some final tips to actually go through the path without feeling overwhelmed:

  1. Take regular breaks. You are not superman. On average, a human being can completely focus for around 45 minutes. The rest is just waste of energy. Take a 10 minutes break. It will do wonders.
  2. Make sure your notes are clear and that you can move around them easily. Don’t copy-paste HTB pages, if you need them, you can search during the exam.
  3. Gamify your journey. HackTheBox already does this for you but you can improve it by setting personal objectives within a module and rewarding yourself after accomplishing it.
  4. Enjoy what you are doing. If something feels off, it is better to stop. Restart at a later time. Life exists outside. Storms can still happen xD

After studying I was feeling too confident for my taste, so I decided to train and humble myself. Cybernetics. The ones who did it, know what I am talking about. The ones who heard of it, fear it. For the others that have no idea about its contents and difficulty, well… I envy you.

Cybernetics was a very insightful exercise to prepare myself to the exam. Multiple AD misconfigurations and a lot of services studied on the CAPE path were put in place.

For me, it was a humbling experience, as I said previously, but very very good for my exam preparation.

And man, the dopamine boost when I finally got the Completion Certificate was insane.

I was determined to start the exam.

Taming The Beast: CAPE Exam

Before starting talking about the exam itself, I still need to tell you something.

Regarding the report part, some people used tools like Word, LateX and some complex way of converting markdown to pdf.

In my case, I spent some days booting up Sysreptor. Sysreptor is a tool where you can, from a template, fill various pieces of information “on-demand”. HackTheBox already provide templates on their pages so, in reality, you just have to fill information regarding hosts you find and the different vulnerabilities found. It saved me precious hours.

The notetaking part here is a bit different from the study notes. Instead of writing “by context” I write it as a walkthrough by machine (you can check on my HTB labs writeups). If some jump from one machine to another is needed, just create a markdown link and move on.

I wrote all the commands I used (even the failed ones), and walked through it like a story, always side by side with screenshots from flags to new accesses or BloodHound or Adalanche paths.

A quick tip here: if you find an unexplored path that you think it might work, take the screenshot immediately before exploiting it and paste it on the notes. I made the mistake of not doing it immediately, fed new information to the graph and a path got messed up due to the changes I had already made.

For the exam, if you see something out of place, odds are that that is the path.

As I said, obfuscation of payloads was crucial because these are not Easy machine labs with no AV or AMSI. However, you will not face webapps or any other techs non related to AD. But it doesn’t mean it gets easier.

Quite the opposite!

For the first flags, it was quite straight forward, but around the middle of the exam, I spent 2 days with nothing. When I say nothing is literally nothing.

I had the path, I had the tools, I had the knowledge, but somehow my final step was deciding to give me a middle finger :).

I was devastated. I had committed full 5 months for that moment and I was done. The final date was arriving and I still had 90% of a report to do and more flags to achieve. Yes, the posts talking about “don’t let the report for the last days”, have you seen those? Me too, I decided to ignore…

The crucial part was remembering a tip I already gave you: “Enjoy what you are doing”. And I was forgetting it.

In my mind, the exam was done, so, I better enjoy what I have been doing. Treat it like a lab, learn new things, go deeper on some aspects. In the end, I still had another attempt!

It was not easy to shift the mindset, after all I was unemployed, bills accumulating, natural disasters happening and personal things going on.

But that’s it. Let it go of the things you can’t control. And the thing I could control was the joy of doing these labs, moving around users and machines. And I did it.

Out of nowhere, I decided to go deeper in the authentication mechanism I was trying to forge, learn their fields and behaviors and when I saw something weird, I decided to search online. It appears that some people also faced a mysterious change on that field…

I decided to reach one of my connects regarding that and in fact he had faced something similar before. It was like a breakthrough.

The moment I tried to mess with that field, suddenly I got that OK from the tool. No more countless hours of middle fingers, just a thumbs up. I have never been so happy for seeing some random text on a terminal!

And that is it, from that point on, I was able to complete the minimum flags to pass it and start building the report!

I know I have a tendency of just writing concisely what is needed to achieve a goal, so when I finished the report, I had around 130 pages. Far from the 300, 400 and 500 you see online. I was chocked at first, trying to understand if I missed some screenshots, information or anything that I might have accidentally deleted. Nothing. I reviewed the notes and everything was there.

The thing is, size doesn’t matter if you don’t know what you are doing, am I right…? I think it applies here!

Finally I uploaded the PDF. The journey was done. I had to wait.

And wait…

And wait…

And the wait was painful, I thought the hard part was done when I finish the exam but the wait for a verdict was even more stressful than the exam itself, because you want to relax, to see the certificate, to enjoy the deserved win. But it tends to get delayed…

But it came. I still remember to this day. I decided to take a nap of 15 minutes that afternoon that, somehow, extended to 2 hours. I woke up, looked at the phone, and saw an email from HackTheBox. I am not even exaggerating, I think in that moment, my girlfriend could hear my heartbeat increasing.

The moment I read that email I think I almost started crying…

That was it, I am now CAPE certified!

All the pain and effort, the adventurous decision proved fruitful. I proved myself I was able to achieve everything and modify my life the way I wanted it to be. I am now in the path to become my best self and there is no better feeling than that.

Post-CAPE realization

The journey was not easy, because you cannot isolate yourself from the world for 6 months and that’s it.

I know I struggled a lot, the mental pressure I had, the amount of moments I even considered to give up…

All these things will cross your mind, specially when you see people working in the industry for 7-8 years saying that it is very hard and that they failed to pass. These intrusive thoughts are normal but will get you nowhere.

Did my life change miraculously? Of course not!

Since CAPE, I have been struggling to get work, not sure why exactly, but my mind remains fortified. Because I did it. I committed to a long term objective where the odds were low and did it. It proved my thesis that you can forge your path the way you want it to be.

And that was the best outcome from this journey. It doesn’t matter what people say. In reality, you can never take advice from people who never had something or never had been in the places you want to reach and the Internet is full of them. Forge your own path, achieve the goals you want and just enjoy the path.

For me?

I will continue researching AD stuff, learning new tricks such as the new Certighost attack, proposing myself to companies’ infrastructure assessments and living my best life.

If you reached this point, I hope you learnt something from my journey and don’t hesitate to contact me to connect, do some gigs or simply exchange ideas.

Yours Truly, Daniel

©
2026 Daniel Andrade 👨🏻‍💻
RSS