🎓 Certification Prep · Modern Web App Pentesting

CMWAP Practice Path

Practice for the Certified Modern Web App Pentester exam (certs.thexssrat.com/cmwap). Prove how you think, not how many payloads you can spray: a 24-hour window, a written report (≤90 min), and a ≤10-minute debrief video — scored on methodology.

2Modules
8Machines
FreeAccess
Get Started →

The CMWAP engagement, step by step

Every full machine on this path runs this exact flow — the same shape as the exam.

0 — Qualify

A 50-question web-app knowledge check gates each engagement. Score 70% or you can't start — the exam assumes you know the fundamentals cold.

1 — Plan (90 min)

Before you touch the target, write and submit a plan: scope, rules of engagement, methodology, tooling, objectives. No plan, no access — exactly like a real engagement.

2 — Test (24 h)

Work the plan. Map the whole surface, then go class by class. Validate every finding with the exact request that proves it. Deliberate, targeted testing — audit logs show how you worked.

3 — Report & debrief

Write the report (exec summary, findings with severity + repro + impact + remediation), then record a ≤10-minute debrief video. In the exam the debrief is where you're scored.

What the debrief is scored on

The CMWAP debrief video (≤10 min) is graded on five dimensions — practice hitting them on every machine.

1 · Scoping

What you chose to test and why.

2 · Approach & structure

Your methodology — not a payload spray.

3 · Finding validation

How you proved each issue is real, and how you present it.

4 · Time allocation

Transparency about where the 24 hours went.

5 · Reflection

What you'd improve about your process next time.

The Two Modules

Warm up on the bug classes, then run the full no-flag engagements.

Module 1 · 🧩

Web-App Vulnerability Fundamentals

Before the full engagement, drill each core web-app bug class in isolation. These are small, single-vulnerability labs (with flags) so you can prove the technique cold — the CMWAP exam assumes you know these.

  • Broken Access Control — IDOR & function-level authz
  • Stored / blind XSS with out-of-band exfil
  • CSRF — forging state-changing requests
  • Business logic abuse
  • Secrets exposure & content discovery
Tools: Burp Suitecurlbrowser devtools
Module 2 · 🎯

Full Engagements — the CMWAP format

No-flag machines run exactly like the CMWAP exam: pass a 50-question qualifier (70%), write a plan in 90 minutes, get 24 hours to compromise a full application, then record a debrief. Nothing to capture — you are graded on how you think and what you deliver.

  • Scoping & rules of engagement
  • Methodology-driven testing (not payload spraying)
  • Finding validation & evidence
  • Report writing within the 90-minute budget
  • ≤10-minute debrief video — the 5 scored dimensions
Tools: Burp SuitecurlYour report + debrief template

No flags. On these machines you don't submit a flag — you submit a pentest plan + report and a debrief video on the machine page. That's the deliverable, exactly like CMWAP.

Ready for the real thing? Book the CMWAP exam →

📕 Going for OSCP too? Check out Uncle Rat's Ultimate OSCP Prep Guide & Course →