CWEE Study Plan
Black-box and white-box web exploitation, the step beyond CWES. A free, day-by-day CWEE schedule built from the official HTB Academy: Senior Web Penetration Tester Job Role Path syllabus, scaled to your exam date and weekly hours.
- Approx. cost
- $490–$1,400
- Difficulty
- ♥♥♥♥♥
- Study time
- about 191h
- Start level
- Advanced
> How long does CWEE take?
The plan assumes about 191 study hours. Here is how that stretches across different weekly schedules.
| Hours per week | Time to finish |
|---|---|
| 5 hours | about 39 weeks (9.0 months) |
| 10 hours | about 20 weeks (4.6 months) |
| 15 hours | about 13 weeks (3.0 months) |
| 20 hours | about 10 weeks (2.3 months) |
| 30 hours | about 7 weeks (1.6 months) |
> CWEE exam format
Hack The Box · HTB Academy: Senior Web Penetration Tester Job Role Path
- Black-box and white-box web penetration test against modern, hardened applications
- Must complete 100% of the Senior Web Penetration Tester job-role path first
- Must develop functional exploits and propose patches, not just find bugs
- Commercial-grade report required to pass
- Positioned as the advanced step beyond HTB CWES
> CWEE syllabus and study hours
Every topic in the plan, in order, with its baseline hours. The planner shrinks or stretches these to fit your dates.
Advanced Injection & Auth
Push past the fundamentals into harder auth and injection flaws.
- Injection Attacks8h · learn
- Introduction to NoSQL Injection7h · learn
- Attacking Authentication Mechanisms11h · learn
- Advanced XSS and CSRF Exploitation9h · learn
- HTTPs/TLS Attacks8h · learn
Protocol & Blind Attacks
Where the HTTP protocol itself becomes the attack surface.
- Abusing HTTP Misconfigurations11h · learn
- HTTP Attacks10h · learn
- Blind SQL Injection9h · learn
White-box Mastery
Source-level review, custom exploits, and patch development.
- Intro to Whitebox Pentesting10h · learn
- Modern Web Exploitation Techniques10h · learn
- Introduction to Deserialization Attacks8h · learn
- Whitebox Attacks8h · learn
- Advanced SQL Injections7h · learn
- Advanced Deserialization Attacks7h · learn
- Parameter Logic Bugs12h · learn
Training Grounds
Rebuild exploits from scratch against fresh code.
- Redo every module lab from memory20h · lab
- Reproduce disclosed web CVEs from a source diff16h · lab
Final Boss Prep
A source-review checklist and a timed dry run.
- Build a white-box review checklist per framework8h · review
- Timed mock exam with a working exploit + patch12h · review
> Where to practise for CWEE
Each task in your plan lists practice labs for its own topic. These are the best places to put in extra hands-on hours:
- All Web Security Academy labs (PortSwigger)
- Mystery lab challenge (PortSwigger)
- Juice Shop (practice app) (OWASP)
> CWEE exam-day checklist
General logistics for exam week. The official exam guide always takes priority if it differs.
One to two weeks before
- Schedule your exam and add the start time, time zone and deadline to your calendar
- Read the official exam guide end to end: rules, allowed and banned tools, and what counts as proof
- Be ready to write working exploits and propose patches for each finding
- Complete a full-length timed practice run on your exam setup
- Finalize your note-taking setup and templates (see the notes starter below)
- Build and review your cheat sheets and command references
- Arrange time off, tell people you will be unavailable, and plan your meals ahead
Machine and network
- Charge and test a backup device or phone hotspot, and know how to contact support if your connection drops
- Plug in your laptop and turn off sleep, updates and notifications for the exam
- Test the VPN or lab connection early and know how to reconnect after a drop
- Update your attack VM, take a clean snapshot and keep a spare
- Install and test every tool you plan to use, and check none of them are banned
- Test your screenshot hotkeys and make sure you have plenty of free disk space
During the exam
- Sleep well the night before, and skip last-minute cramming
- Prepare food and water, and set timers for break reminders
- Read the brief and scope carefully before you touch anything
- Write notes and capture proof as you go, not at the end
- Time-box each target and move on when stuck. You can come back later
Report and submission
- Copy your report template and fill in the easy parts (scope, methodology) while you work
- Check every finding has reproducible steps and screenshots
- Proofread: could someone else follow each step?
- Export in the exact format and naming the exam guide requires
- Submit with a buffer before the deadline and confirm it was received
Suggested exam-day rhythm
- Before you start. Check how long the exam window is and work backwards from the deadline.
- Daily. Fixed working blocks of about 90 minutes, a 10-minute break after each, and a proper stop at night.
- Each day. Update notes, list your next ideas and back up your evidence.
- Near the end. Stop new attacks early enough to verify findings and write the report.
- Submission. Submit with a buffer before the deadline and confirm it was received.
▶ Open the interactive CWEE exam kit
The kit lets you tick items off, download a notes starter and report template, and see a readiness score from your plan progress.
> Passed CWEE with PWN PATH
No CWEE debriefs yet
Passed a cert? A short debrief helps the next learner plan their own run, and it only takes a couple of minutes.
▶ Share my debriefDebriefs are self-reported. See all pass stories.
> Frequently asked questions
How long does it take to prepare for CWEE?
PWN PATH builds the CWEE plan on about 191 study hours. At 10 hours a week that is roughly 20 weeks, and at 20 hours a week roughly 10 weeks. Your own timeline depends on how much of the material you already know.
What is the CWEE exam like?
Black-box and white-box web penetration test against modern, hardened applications. Must complete 100% of the Senior Web Penetration Tester job-role path first. Must develop functional exploits and propose patches, not just find bugs. Commercial-grade report required to pass. Positioned as the advanced step beyond HTB CWES.
How hard is CWEE?
We rate CWEE 5 out of 5. It suits web specialists who want black-box and white-box skills and to write exploits and patches. CWES or equivalent web experience.
How much does CWEE cost?
HTB Academy subscription plus a $210 exam voucher. Silver Annual is about $490–550 with a voucher included; some advanced paths need Gold. Prices are approximate, in US dollars unless a currency is shown, and change often. Confirm with the vendor before you buy.
What should I study first for CWEE?
Start with the "Advanced Injection & Auth" phase: Injection Attacks, Introduction to NoSQL Injection, Attacking Authentication Mechanisms. The planner puts topics in a sensible order and scales the hours to the time you have.
What are the prerequisites for CWEE?
CWES or equivalent web experience.
What should I do the week before the CWEE exam?
Re-read the official exam guide for rules and banned tools, test your machine, network and VPN or lab connection, finish a full timed practice run, finalize your notes and cheat sheets, and plan your meals, breaks and sleep. The exam-day checklist on this page covers it step by step.
How should I handle breaks and sleep during the CWEE exam?
Before you start: Check how long the exam window is and work backwards from the deadline. Daily: Fixed working blocks of about 90 minutes, a 10-minute break after each, and a proper stop at night. Each day: Update notes, list your next ideas and back up your evidence. Near the end: Stop new attacks early enough to verify findings and write the report.
What should I take after CWEE?
Common next steps are OSWE. See the roadmap to compare them.
Is the PWN PATH study planner free?
Yes. There are no accounts and no sign-up. Your plan and progress are saved in your browser, and you can export a backup file, add the schedule to your calendar or print it.
> Plan your path
Good stepping stones before CWEE:
Where it leads:
More in web application security:
Not sure CWEE is right for you? Take the one-minute cert quiz.