CWEE Study Plan

Black-box and white-box web exploitation, the step beyond CWES. A free, day-by-day CWEE schedule built from the official HTB Academy: Senior Web Penetration Tester Job Role Path syllabus, scaled to your exam date and weekly hours.

Approx. cost
$490–$1,400
Difficulty
♥♥♥♥♥
Study time
about 191h
Start level
Advanced

▶ Build my CWEE plan

> How long does CWEE take?

The plan assumes about 191 study hours. Here is how that stretches across different weekly schedules.

Hours per weekTime to finish
5 hoursabout 39 weeks (9.0 months)
10 hoursabout 20 weeks (4.6 months)
15 hoursabout 13 weeks (3.0 months)
20 hoursabout 10 weeks (2.3 months)
30 hoursabout 7 weeks (1.6 months)

> CWEE exam format

Hack The Box · HTB Academy: Senior Web Penetration Tester Job Role Path

  • Black-box and white-box web penetration test against modern, hardened applications
  • Must complete 100% of the Senior Web Penetration Tester job-role path first
  • Must develop functional exploits and propose patches, not just find bugs
  • Commercial-grade report required to pass
  • Positioned as the advanced step beyond HTB CWES

Official CWEE page ↗

> CWEE syllabus and study hours

Every topic in the plan, in order, with its baseline hours. The planner shrinks or stretches these to fit your dates.

Advanced Injection & Auth

Push past the fundamentals into harder auth and injection flaws.

  • Injection Attacks8h · learn
  • Introduction to NoSQL Injection7h · learn
  • Attacking Authentication Mechanisms11h · learn
  • Advanced XSS and CSRF Exploitation9h · learn
  • HTTPs/TLS Attacks8h · learn

Protocol & Blind Attacks

Where the HTTP protocol itself becomes the attack surface.

  • Abusing HTTP Misconfigurations11h · learn
  • HTTP Attacks10h · learn
  • Blind SQL Injection9h · learn

White-box Mastery

Source-level review, custom exploits, and patch development.

  • Intro to Whitebox Pentesting10h · learn
  • Modern Web Exploitation Techniques10h · learn
  • Introduction to Deserialization Attacks8h · learn
  • Whitebox Attacks8h · learn
  • Advanced SQL Injections7h · learn
  • Advanced Deserialization Attacks7h · learn
  • Parameter Logic Bugs12h · learn

Training Grounds

Rebuild exploits from scratch against fresh code.

  • Redo every module lab from memory20h · lab
  • Reproduce disclosed web CVEs from a source diff16h · lab

Final Boss Prep

A source-review checklist and a timed dry run.

  • Build a white-box review checklist per framework8h · review
  • Timed mock exam with a working exploit + patch12h · review

> Where to practise for CWEE

Each task in your plan lists practice labs for its own topic. These are the best places to put in extra hands-on hours:

> CWEE exam-day checklist

General logistics for exam week. The official exam guide always takes priority if it differs.

One to two weeks before

  • Schedule your exam and add the start time, time zone and deadline to your calendar
  • Read the official exam guide end to end: rules, allowed and banned tools, and what counts as proof
  • Be ready to write working exploits and propose patches for each finding
  • Complete a full-length timed practice run on your exam setup
  • Finalize your note-taking setup and templates (see the notes starter below)
  • Build and review your cheat sheets and command references
  • Arrange time off, tell people you will be unavailable, and plan your meals ahead

Machine and network

  • Charge and test a backup device or phone hotspot, and know how to contact support if your connection drops
  • Plug in your laptop and turn off sleep, updates and notifications for the exam
  • Test the VPN or lab connection early and know how to reconnect after a drop
  • Update your attack VM, take a clean snapshot and keep a spare
  • Install and test every tool you plan to use, and check none of them are banned
  • Test your screenshot hotkeys and make sure you have plenty of free disk space

During the exam

  • Sleep well the night before, and skip last-minute cramming
  • Prepare food and water, and set timers for break reminders
  • Read the brief and scope carefully before you touch anything
  • Write notes and capture proof as you go, not at the end
  • Time-box each target and move on when stuck. You can come back later

Report and submission

  • Copy your report template and fill in the easy parts (scope, methodology) while you work
  • Check every finding has reproducible steps and screenshots
  • Proofread: could someone else follow each step?
  • Export in the exact format and naming the exam guide requires
  • Submit with a buffer before the deadline and confirm it was received

Suggested exam-day rhythm

  • Before you start. Check how long the exam window is and work backwards from the deadline.
  • Daily. Fixed working blocks of about 90 minutes, a 10-minute break after each, and a proper stop at night.
  • Each day. Update notes, list your next ideas and back up your evidence.
  • Near the end. Stop new attacks early enough to verify findings and write the report.
  • Submission. Submit with a buffer before the deadline and confirm it was received.

▶ Open the interactive CWEE exam kit

The kit lets you tick items off, download a notes starter and report template, and see a readiness score from your plan progress.

> Passed CWEE with PWN PATH

No CWEE debriefs yet

Passed a cert? A short debrief helps the next learner plan their own run, and it only takes a couple of minutes.

▶ Share my debrief

Debriefs are self-reported. See all pass stories.

> Frequently asked questions

How long does it take to prepare for CWEE?

PWN PATH builds the CWEE plan on about 191 study hours. At 10 hours a week that is roughly 20 weeks, and at 20 hours a week roughly 10 weeks. Your own timeline depends on how much of the material you already know.

What is the CWEE exam like?

Black-box and white-box web penetration test against modern, hardened applications. Must complete 100% of the Senior Web Penetration Tester job-role path first. Must develop functional exploits and propose patches, not just find bugs. Commercial-grade report required to pass. Positioned as the advanced step beyond HTB CWES.

How hard is CWEE?

We rate CWEE 5 out of 5. It suits web specialists who want black-box and white-box skills and to write exploits and patches. CWES or equivalent web experience.

How much does CWEE cost?

HTB Academy subscription plus a $210 exam voucher. Silver Annual is about $490–550 with a voucher included; some advanced paths need Gold. Prices are approximate, in US dollars unless a currency is shown, and change often. Confirm with the vendor before you buy.

What should I study first for CWEE?

Start with the "Advanced Injection & Auth" phase: Injection Attacks, Introduction to NoSQL Injection, Attacking Authentication Mechanisms. The planner puts topics in a sensible order and scales the hours to the time you have.

What are the prerequisites for CWEE?

CWES or equivalent web experience.

What should I do the week before the CWEE exam?

Re-read the official exam guide for rules and banned tools, test your machine, network and VPN or lab connection, finish a full timed practice run, finalize your notes and cheat sheets, and plan your meals, breaks and sleep. The exam-day checklist on this page covers it step by step.

How should I handle breaks and sleep during the CWEE exam?

Before you start: Check how long the exam window is and work backwards from the deadline. Daily: Fixed working blocks of about 90 minutes, a 10-minute break after each, and a proper stop at night. Each day: Update notes, list your next ideas and back up your evidence. Near the end: Stop new attacks early enough to verify findings and write the report.

What should I take after CWEE?

Common next steps are OSWE. See the roadmap to compare them.

Is the PWN PATH study planner free?

Yes. There are no accounts and no sign-up. Your plan and progress are saved in your browser, and you can export a backup file, add the schedule to your calendar or print it.

> Plan your path

Good stepping stones before CWEE:

Where it leads:

More in web application security:

Not sure CWEE is right for you? Take the one-minute cert quiz.