Already a member?
Your cart

Your cart is empty.

New CMWAP material & exam β€” launching soon

–days
–hrs
–min
–sec

πŸŽ‰ The new CMWAP material & exam are live!

The Cheese Shop / Certified Modern Web App Pentester (CMWAP)

🧠 CMWAP – Certified Modern Web App Pentester

Work it like a normal day. Stick to scope. Prove how you think.

CMWAP is a single, modern web application pentest exam you run like a professional runs a real engagement. First you get a strict 90-minute window to write and submit your plan (concise β€” no books) before the exam starts, then you wait for sign-off; miss the deadline by a minute and you fail. The exam itself is a 24-hour window worked like one normal day: about 8 hours of hacking, then rest, eat, and step away. Hacking is hard-capped at roughly 14 hours; go over and you automatically fail. You also record a debrief of 10 minutes max. AI is allowed as an assistant, but it can't write your plan or report. We grade adherence to scope far more than the exploits you find.

CMWAP – Certified Modern Web App Pentester badge

Book your 24-hour window

One 24-hour exam window worked like a normal day, lab access, and an async debrief review. No live proctoring β€” your audit logs and debrief video tell the story.

€59.99

Book your CMWAP seat

A hard 90-minute plan deadline before the exam, sign-off, then a normal working day: ~8 hours hacking with time to rest inside the 24-hour window.

Hacking is hard-capped at ~14 hours. Grind past it and you automatically fail β€” pacing and rest are part of the exam.

Graded on scope adherence over exploits. Audit logs confirm you tested what you said you would. AI allowed, but not to write your plan or report.

Scope adherence over exploits

CMWAP is less about landing a rare bug and more about the ideology of a real engagement: scope it, plan it, test exactly what you claimed you'd test, and reflect honestly β€” inside a sane, professional working day. Beginners can pass because it starts slow and grades the thinking behind the work, not raw exploitation.

πŸ‘‰ For anyone who wants to prove they can run a modern web app pentest like a professional β€” beginners welcome.

Ready to scope, hack a normal day, report, and debrief β€” without grinding?

How the CMWAP exam works

It starts before the clock on the hacking even runs. You get a strict 90-minute window to write and submit your plan (keep it concise β€” no books) β€” then you wait for sign-off before the exam begins. After that, treat the exam like a normal working day, not an all-nighter: about a full 8-hour working day of hacking inside a 24-hour window, then step away, eat, sleep, and live your life. There is no live proctor β€” your audit logs and a short debrief video show us how you worked.

The shape of the exam

  • 90 minutes to write and submit your plan β€” a hard deadline, before the exam starts.
  • Wait for sign-off β€” you may only begin once your plan is approved.
  • ~8 hours of focused hacking β€” like a real work day.
  • ~14 hours of hacking is the hard ceiling β€” go over and you auto-fail.
  • The rest of the 24 hours is for rest, food, and breaks. Take them.

The debrief video (max 10 min)

Record a short walkthrough of your engagement. We score it on five criteria:

  1. Scoping β€” what you decided was in and out of scope, and why.
  2. Planning β€” how you structured your approach before diving in.
  3. Findings β€” what you found and how you validated it.
  4. Where your time went β€” an honest account of how you spent the hours.
  5. What you'd cut next time β€” what you'd drop or do differently.

Scope adherence is what we grade

We judge you far more on sticking to your scope than on how many exploits you land. Your testing is logged β€” we check that you actually tested what you said you would. Deliberate, targeted testing beats spraying random payloads and hoping something lands. Say what you'll test, then test exactly that.

Using AI

AI is allowed as an assistant β€” but it must not do the thinking for you. It may not write your full plan or your full report. Those are yours: they're the evidence of how you reason, scope, and reflect.

What you submit

  • Your plan β€” concise, no books (before the exam, within the 90-minute hard deadline).
  • Your pentest report (in your own words).
  • Your debrief video (10 minutes maximum).
  • Audit logs from your testing session (captured automatically).

Example scopes

At exam time you're assigned one target application under thexssrat.com with a scope table β€” that table is the thing you're graded against. Below are illustrative examples of the kinds of apps and scopes you might get. In every case the rule is the same: test what you declare in scope, and stop at the out-of-scope line β€” finding an out-of-scope door is a finding; walking through it is an automatic fail.

ratbank.thexssrat.com

Online banking

Accounts, transfers, cards, and statements β€” money movement in a sandbox.

Roles supplied: customer, support agent

In scope

  • ratbank.thexssrat.com β€” customer web app (login, transfers, cards, statements)
  • ratbank.thexssrat.com/api/v2/* β€” accounts, payments, beneficiaries
  • Sandbox transactions only β€” play money, no real rails

Out of scope

  • Real payment networks / card processors (third party)
  • back-office.ratbank.thexssrat.com β€” staff console
  • Other customers’ accounts and data

ratpackpark.thexssrat.com

Theme-park ticketing

Ticket sales, timed bookings, e-tickets, and promo codes.

Roles supplied: visitor, gate staff

In scope

  • ratpackpark.thexssrat.com β€” booking + checkout flow
  • ratpackpark.thexssrat.com/api/v2/* β€” bookings, tickets, promo codes
  • E-ticket QR generation and validation endpoints

Out of scope

  • Payment provider / gateway (third party)
  • Physical gate scanners and kiosk network
  • admin.ratpackpark.thexssrat.com β€” operations console

rattrack.thexssrat.com

Parcel tracking & logistics

Shipment tracking, label generation, and a dispatcher dashboard.

Roles supplied: sender, courier, dispatcher

In scope

  • rattrack.thexssrat.com β€” tracking portal + dispatcher dashboard
  • rattrack.thexssrat.com/api/v2/* β€” shipments, labels, webhooks
  • Label/QR generation and tracking-link endpoints

Out of scope

  • Carrier integrations you don’t own (third-party APIs)
  • GPS device fleet and hardware
  • ops.rattrack.thexssrat.com β€” internal operations console

Common to every scope: no DoS or mass-delete, be gentle on rate limits, only your own spawned instances, web app only (no host/SSH/DNS/network), and anything not listed is out. A candidate who finds four bugs while quietly abandoning half their stated scope scores below one who finds three and delivers exactly what they promised.

See example plans & reports

Know exactly what "good" looks like: browse example CMWAP pentest plans (what you submit in your 90-minute window) and example reports and worked findings.

View examples

Practice for free before exam day

Warm up on the exam-style labs at cwap.thexssrat.com β€” free to practise. Every CMWAP candidate also gets 3 months of free access to RatCTF.com to sharpen scoping, planning, and methodology β€” so you walk in ready to work a calm, professional day.

CMWAP frequently asked questions

CMWAP is a single modern web application pentest run in a 24-hour window. Treat it like a normal working day: about 8 hours of hacking plus 90 minutes to write your report, then rest. There is no live proctor β€” your audit logs and a debrief video (10 minutes max) show how you worked.

You are graded far more on adherence to the scope you declared than on how many exploits you land. The debrief is scored on five criteria: scoping, planning, findings, where your time went, and what you would cut next time.

Yes. Hacking is hard-capped at roughly 14 hours. Rest and breaks are part of the exam β€” if you grind past the cap you automatically fail. Pace yourself: scope, plan, test what matters, and stop.

No. CMWAP is about the ideology of a real engagement, not exploit trophies. A candidate who finds three issues and delivers exactly what they promised scores above one who finds four while quietly abandoning half their stated scope.

Yes, as an assistant β€” but it may not do the thinking for you. AI cannot write your full plan or your full report. Anything it produces becomes your claim, so budget time to verify it by hand.

Your pentest report (written within the 90-minute report budget, in your own words), your debrief video (10 minutes maximum), and the audit logs from your testing session (captured automatically).

Yes. You first complete a 50-question multiple-choice knowledge check and need 70% (35/50) to proceed. An admin sends you a unique link to take it; once you pass, a proctor reviews your score and approves you to begin.

You are assigned one application (for example ratbank, ratpackpark, or rattrack under thexssrat.com) with a scope table. That table is what you are graded against. Finding an out-of-scope door is a finding; walking through it is an automatic fail.

Yes. Practise the exam-style labs for free at cwap.thexssrat.com, and every CMWAP candidate also gets 3 months of free access to RatCTF.com to sharpen scoping, planning, and methodology before exam day.

Every certificate carries a unique Certificate ID. Anyone can confirm it at certs.thexssrat.com/verify β€” the page shows the recipient, certification, and result.

Yes. It starts slow and rewards clear thinking, honest reflection, and disciplined testing over rare exploits β€” so beginners who work methodically can pass.