An interactive, offline-friendly study tracker for the Hack The Box Certified Junior Cybersecurity Associate (HTB CJCA) certification.
It lays out the full curriculum of the Junior Cybersecurity Analyst Job-Role Path (all 20 modules and 318 sections) and tracks your progress, notes, and pace as you go. Pick a 15-, 25-, 35-, or 45-day timeline to match the time you have: the curriculum stays the same, just repackaged into a denser or gentler schedule. The whole thing is one self-contained HTML file, with no build step, no dependencies, and nothing to fetch at runtime.
It's built on mattrfield's coae-study-tracker, which was the original inspiration for this project.
- Adjustable 15 / 25 / 35 / 45-day timeline. Choose how long you have, and the same full curriculum regroups into denser or lighter days. The day cards, weeks, progress chart, pace indicator, and weekly-hours estimate (about 28 hrs/week at 45 days, up to about 85 hrs/week at 15 days) all adjust to match, and your checked-off progress carries over when you switch.
- Day-by-day plan. Each module is split into day-sized chunks that follow HTB's actual section headings. The plan runs from InfoSec and networking basics through Linux, Bash, Windows and PowerShell, web fundamentals, the pentest process, Nmap, footprinting, WordPress and Metasploit, then the defensive half: traffic analysis, incident handling, Windows event logs, SIEM, and threat hunting. It ends with Easy-box practice, alert-triage drills, a mock exam, and report practice in SysReptor.
- Progress dashboard. An overall completion ring with the CJCA badge at its center, days completed, best streak, current phase, a weekly progress chart, a per-phase breakdown, and an ahead/behind pace indicator based on your start date.
- Notes and journal. A collapsible notes field on every day for logging commands that worked, KQL queries worth saving, and things to revisit.
- Resource library. 57 curated links across nine categories, starting with the community (the HTB Discord and r/hackthebox), then the official cert and all 20 Academy modules in study order. It includes first-hand exam reviews, reporting templates, and a tooling reference (Nmap, WPScan, Metasploit, PEASS-ng, Wireshark, KQL, Sysmon, and more), and it ends with tips from people who passed, grouped by reviewer.
- Badge-themed look. The colors come from the CJCA logo: its navy disc, with blue as the main accent and red as the second, like the eye swoosh.
- Local persistence. All progress saves automatically to your browser's
localStorage, and the Export and Import buttons let you back up or move it.
- Download or clone this repository.
- Open
cjca-study-tracker.htmlin any modern browser (double-click it, orFile > Open). - Choose your timeline (15, 25, 35, or 45 days) and set your start date at the top. Every day's calendar date and your pace indicator are computed from them.
- Tick tasks as you complete them. A day is marked complete when all its tasks are done.
No server, no install. It runs entirely in your browser.
Tip: Progress is stored per-browser. Use the Export backup button regularly, and Import it if you switch browsers or machines. (Some browsers restrict
localStorageonfile://pages. If progress doesn't stick, exporting and importing is your reliable backup.)
| Phase | Days (45-day) | Focus |
|---|---|---|
| 1 | 1–7 | Security & networking foundations: InfoSec, Network Foundations, Intro to Networking |
| 2 | 8–12 | Linux Fundamentals & Bash scripting |
| 3 | 12–16 | Windows Fundamentals & the Windows command line |
| 4 | 17–19 | Web Requests & Intro to Web Applications |
| 5 | 20–24 | Intro to Penetration Testing & Pentest in a Nutshell |
| 6 | 25–33 | Nmap, Footprinting, Hacking WordPress, Metasploit, Easy HTB boxes |
| 7 | 34–40 | Traffic analysis, incident handling, event logs, SIEM, threat hunting, alert triage |
| 8 | 41–45 | SysReptor setup, practice reports, mock exam, final review |
The day ranges above describe the default 45-day layout. Every timeline packs the same curriculum, about 182 hours total, into more or fewer days, so the weekly load changes: roughly 28 hrs/week at 45 days, 36 at 35 days, 51 at 25 days, 85 at 15 days. HTB estimates the path itself at 17 days 3 hours, about 139 hours at 8 hrs/day, and the module days here add up to exactly that; the extra time goes to labs, the mock exam, and report practice.
You earn the HTB CJCA by completing the Junior Cybersecurity Analyst Job-Role Path 100% and passing a 5-day practical exam with two halves. In the red-team half you attack 5 machines, each with a user and a root flag. In the blue-team half you triage SIEM alerts in Elastic as true or false positives. You then submit a professional report, which HTB grades and which can fail you on its own. Reviewers report a pass mark of 80 of 100 flag points; HTB officially says only "a minimum point threshold". Always confirm current module counts, exam format, and pricing on the official HTB Academy site.
Issues and pull requests are welcome, whether that's improvements to the curriculum, the resources, or the UI. Since the tracker is a single HTML file, edits are straightforward: the curriculum lives in the CURRICULUM array and resources in the RESOURCES array inside the <script> block.
This tracker grew out of mattrfield's coae-study-tracker, which was the original inspiration and the base the interface is built on. The CJCA curriculum, resources, and content here are this project's own, and the tips come from the exam reviews linked in the resource library.
This is an independent, community study aid. It is not affiliated with, endorsed by, or sponsored by Hack The Box. "Hack The Box" and "HTB" are trademarks of their respective owner.
MIT. Free to use, modify, and share.