How I Passed HTB CWEE: My Preparation, Exam Experience, and Lessons Learned
The Certified Web Exploitation Expert (CWEE) from Hack The Box is an advanced, hands-on certification focused heavily on real-world web exploitation.
The exam is a 10-day assessment that expects candidates to have strong practical security skills, understand complex attack chains, and be comfortable reading and understanding code across different languages and frameworks.
For me, the code-reading part was probably the easiest.
I have several years of experience in software engineering and web development, along with experience in Application Security and Product Security. Reading code across different languages and frameworks has always been something I genuinely enjoy — it’s almost my favourite sport. :D
But having software development experience doesn’t automatically make the exam easy.
Web exploitation requires a different mindset: understanding how an application works, identifying weaknesses, chaining vulnerabilities together, and turning individual findings into a meaningful attack path.
That was the part I wanted to go deeper into.
Why I Decided to Take CWEE
After passing CPTS and CWES, I wanted to move deeper into web exploitation from an AppSec perspective.
What I particularly enjoy about web security is chaining vulnerabilities and misconfigurations together.
Finding an IDOR by itself can be interesting. Finding an SSRF can be interesting. Finding a prototype pollution issue can be interesting.
But finding a way to chain several seemingly unrelated weaknesses into a complete attack path is where things become really interesting for me.
That was one of the main reasons I decided to pursue CWEE.
My Preparation
I started studying the CWEE material primarily during weekends.
My initial target was roughly 6 hours per day on weekends, but realistically, life doesn’t always follow the study plan.
I have a full-time job, a family, and plenty of other responsibilities. Some days I studied for only 30 minutes, while other days I managed to get a couple of hours in.
The important thing was consistency rather than trying to maintain a perfect schedule.
First Pass: ~5 Months
It took me around five months to complete the material path.
Some of the content was already familiar because of my professional experience and previous certifications, so I wasn’t learning everything from scratch.
However, I deliberately didn’t skip topics just because I already knew them.
I took notes throughout the entire path and gradually built my own collection of techniques, commands, concepts, and attack patterns.
By the end of the first pass, I had a fairly large set of notes that I could eventually turn into a personal cheat sheet.
The Second Pass
After finishing the material once, I realized that not every module had the same level of importance for me.
Some topics were already deeply familiar, while others required more attention and practice.
So instead of immediately jumping into the exam, I went through the material a second time.
The second pass took approximately two months.
This time, I focused much more on:
- Understanding the exploitation methodology
- Connecting different concepts together
- Reviewing techniques I had forgotten
- Identifying areas where my understanding was still shallow
- Improving my notes
- Building a practical, ready-to-use cheat sheet
This second pass was probably more valuable than I initially expected.
The first pass gave me coverage.
The second pass gave me confidence.
Practice Before the Exam
After completing the second pass, I started focusing more heavily on practical labs.
One of the most useful resources for me was the official CWEE Preparation Track from Hack The Box.
I found it extremely useful for getting into the right mindset and understanding the kind of problems I would be expected to solve.
I also worked through various web challenges on Hack The Box.
This was particularly useful because, despite having significant web security experience, I didn’t have a huge amount of experience specifically with HTB web challenges.
The track exposed me to different ways of thinking about problems and forced me to work through exploitation scenarios rather than simply reading about them.
Where I Struggled
I definitely got stuck during the preparation.
There were several points where I couldn’t figure out what I was missing.
Sometimes a tiny hint was enough to get me moving again.
There were also some challenges where I got stuck on something that, after seeing the solution, felt almost embarrassingly obvious.
You know that feeling:
“How did I not see this?” :D
I think that’s actually an important part of the learning process.
Getting stuck is not necessarily a sign that you’re not ready. What matters is whether you can understand why you got stuck and incorporate that lesson into your methodology.
What About PortSwigger?
Interestingly, I didn’t specifically practice PortSwigger Web Security Academy for CWEE preparation.
However, I had already completed a significant number of PortSwigger labs during my CWES preparation, several years ago.
So while I wasn’t actively using PortSwigger as part of my CWEE preparation, the concepts and experience from those labs were still useful.
The Exam
When I finally started the exam, the preparation started paying off.
I managed to complete the required flags needed to pass — 5 out of 6 flags, worth 90 points — in approximately 2.5 days.
The exploitation itself wasn’t the end of the process, though.
The report took me approximately four additional days to complete.
This is something I would strongly recommend keeping in mind if you’re planning to take the exam.
Don’t think:
“I only need a few days to get the flags.”
You also need time to properly document your work and produce a good report.
How I Used AI During the Exam
This is probably the part people are most curious about.
I’ll be completely honest:
Agentic AI was quite helpful — but only when I already understood the attack chain.
I used Claude Code to help me write some of the Python exploit scripts.
For example, if I already understood exactly what needed to happen, I didn’t want to spend an hour figuring out the exact syntax for making a particular requests POST request.
That’s where AI was extremely useful.
I could focus on the security problem while letting the AI handle some of the implementation details.
But there was also a very important lesson:
AI Can Be Extremely Confident and Completely Wrong
At one point, I had already figured out the attack flow.
I provided the AI with:
- The Burp Suite request
- The relevant context
- The end-to-end attack flow
- What I expected the exploit to accomplish
I asked it to automate the process for me.
Instead of producing the correct solution, it started hallucinating and sent me down the wrong path.
I spent approximately five hours trying to get it to solve a problem that I didn’t actually need to solve.
Eventually, I reviewed the script it was trying to build and identified the actual problem.
I fixed it manually and successfully passed that flag.
That experience reinforced something important for me:
AI is an excellent implementation assistant, but it is not a replacement for understanding the attack chain.
If you don’t understand the exploitation yourself, it’s very easy to spend more time debugging the AI’s solution than it would have taken to solve the problem manually.
Key Takeaways
If you’re preparing for CWEE, these are my biggest takeaways.
1. Understand Every Module End-to-End
Don’t settle for shallow understanding.
You should be able to explain:
- What the vulnerability is
- Why it exists
- How to identify it
- How to exploit it
- How it can be chained
- What the relevant code is doing
The ability to recognize an exploitation pattern is much more valuable than memorizing commands.
2. Take the Skill Assessments Seriously
The skill assessments are extremely useful.
Try to solve them without hints.
If you need a hint, that’s fine — but go back afterward and understand exactly what you missed.
3. Do the CWEE Preparation Track
I found the official CWEE Preparation Track very useful.
Take notes.
Don’t just complete the labs and move on.
Try to extract the methodology and techniques that you can reuse in other environments.
4. Solve as Many Web Challenges as Possible
Especially if you don’t have a lot of experience with Hack The Box web challenges.
The more different applications you break, the better you’ll become at recognizing patterns.
5. TAKE NOTES
Seriously.
Take as many useful notes as you can throughout the preparation.
Eventually, turn those notes into your own cheat sheet.
The goal isn’t to create a giant collection of random commands.
Build something that helps you quickly remember:
- Methodologies
- Interesting exploitation techniques
- Payload patterns
- Useful commands
- Common attack chains
- Things you personally tend to forget
Your cheat sheet should reflect how you think about web exploitation.
Was CWEE Really That Hard?
I’ve read quite a few posts from people describing CWEE as an insane or nightmare-level exam.
Everyone’s experience is different.
For me, honestly, it wasn’t like that.
I found it to be a medium-difficulty and genuinely enjoyable exam.
That doesn’t mean the exam is objectively easy.
My experience is heavily influenced by my background in software engineering, web development, and application security.
I’ve been working with web applications for years, so understanding application logic and reading source code wasn’t a major obstacle for me.
In fact, that’s probably one of the biggest advantages I had going into CWEE.
For someone without that background, the same exam could feel significantly harder.
Is CWEE Worth It?
Absolutely.
For me, it was worth every cent.
Even though some parts of the material were already familiar because of my professional experience and previous certifications, the overall journey was still extremely valuable.
More importantly, it pushed me further into the area of web exploitation that I genuinely enjoy.
I don’t think certifications should be treated simply as badges.
The real value is the process of preparing, practicing, getting stuck, figuring things out, and eventually becoming better at the skill itself.
And that’s what I got from CWEE.
A big thank you to Hack The Box for creating such a great certification and learning experience.
If you’re considering taking CWEE, I hope my experience gives you a realistic idea of what preparation can look like.
Good luck, and happy hacking! 🔥
Certification
Hack The Box — Certified Web Exploitation Expert (CWEE)