Everything you need for hands-on cybersecurity training covering both offensive and defensive scenarios—featuring 10 flagship Pro Labs, unlimited VIP+ access, and upcoming SOC Range simulations.
Mastering real-world cybersecurity requires hands-on experience across the entire operational spectrum. Until now, getting that training meant managing separate subscriptions: paying for Pro Labs to access multi-host network environments, and paying again for VIP+ to practice on retired Machines.
We are excited to announce HTB PRO: an upcoming all-inclusive HTB Labs subscription built to streamline your journey towards offensive and defensive cyber mastery.
New monthly and yearly plans for HTB PRO will be available for purchase starting September 30th, 2026 on HTB Labs.
HTB PRO brings enterprise-level offensive scenarios, defensive triage, and full VIP+ access together into one membership:
HTB PRO plans will be available at either $49 a month or $490 a year, starting September 30th, 2026.
If you are an existing VIP+ subscriber or newly registered on HTB Labs, discover below what makes HTB PRO the right plan for you.
Pro Labs are premium training labs designed to provide an accurate adversary simulation against challenging, and sometimes fully patched, enterprise technologies. Aside from the advanced practical skills that you will obtain, there is a certificate of completion waiting for you at the end of each Pro Lab as well as up to 40 CPE credits.
We are selecting a fleet of 10 flagship Pro Lab environments to be part of the new HTB PRO subscriptions. These represent the gold standard of hands-on offensive training, hand-selected by HTB experts and celebrated by the HTB community.
This is the full list:
| Pro Lab | Scenario Synopsis | Learning Domains |
|---|---|---|
| Dante | Dante LLC have enlisted your services to audit their network. The company has not undergone a comprehensive penetration test in the past and wants to reduce their technical debt. They are concerned that any actual breach could lead to financial and reputational damage. |
|
| Zephyr | Zephyr Server Management has been hired to maintain Painters' infrastructure. You are tasked to explore the corporate environment, pivot across trust boundaries, and compromise all Painters and Zephyr Server Management entities. |
|
| Offshore | Assume the role of an agent tasked with exposing money laundering operations in an offshore bank. Breach the DMZ and pivot through the internal network to locate protected databases. |
|
| Ifrit | Perform a red team engagement on Ifrit’s internal networks as an assumed breach scenario with access to a VDI environment following a new security baseline rollout. |
|
| RastaLabs | Established in 2017, RastaLabs is a start-up provider of IT security and penetration testing services. Our consultants offer expertise, flexibility and extensive support before, during and after each engagement. RastaLabs is an ISO 27001 & 9001 certified organisation, committed to providing an unparalleled service in the Information Security industry. |
|
| Wutai | Perform a penetration test on Wutai Group following a domain username leak. Reach Enterprise Administrator in the wutai.vl domain against an active basic SOC. |
|
| POO | Professional Offensive Operations is a rising name in the cyber security world. Lately they've been working into migrating core services and components to a state of the art cluster which offers cutting edge software and hardware. |
|
| Unintended | Evaluate Unintended’s newly migrated Active Directory infrastructure. Determine whether an attacker can move from initial access to full domain control. |
|
| Wanderer | In a post-apocalyptic wasteland, wander from machine to machine collecting vital information on the survivors who built the remaining IT infrastructure. |
|
| Shinra | Shinra is a electric power company with a fairly good security stance. Your mission is to infiltrate the company from the perspective of an external attacker in form of a red team engagement. Shinra is running a 24/7 SOC and has an EDR running on all endpoints. |
|
Sherlocks build investigative judgment. But reading evidence and reconstructing an incident is different from running the full mechanics of a live SOC shift: claiming an alert, working it under a playbook, using the right tools, documenting every decision, and closing it out.
That is the role of SOC Range, now integrated directly into the HTB Enterprise Platform and coming soon to HTB Labs during Q4 2026.
Built on LetsDefend’s SOC simulation capability, SOC Range is a self-paced, SIEM-mimicking environment where analysts practice the day-to-day workflow of a modern Security Operations Center.
Instead of following a passive alert walkthrough, analysts work through a realistic operational process: claim alerts from a backlog, manage active investigations, review evidence, use integrated security tools, follow alert-specific playbooks, classify findings, document decisions, and close investigations.
The environment includes:
Stay tuned for the launch of SOC Range on HTB Labs through Q4 2026!
Starting September 30th, legacy Pro Labs Monthly and Annual Bundles will no longer be available for new purchases. If you want to guarantee continuous access to the entire archive of 30+ legacy Pro Labs scenarios for the next 12 months, you can upgrade to a Pro Labs annual plan until September 29th, 2026.
Existing subscribers: Nothing changes for you! You will keep your current plan, pricing, and lab access (30+ Pro Labs) as long as you maintain your subscription.
If you want to experiment with advanced network exploitation before jumping into the full Pro Labs collection, try our 2 free mini Pro Labs: Mythical and Puppet (Hacker Rank required).