Already a member?
Your cart

Your cart is empty.

CMWAP example plans & reports

Learn the expected format: example plans (what you submit in your 90-minute window) and example reports and findings. These are illustrative β€” your exam deliverables are your own work.

← Back to CMWAP

CMWAP Pentest Plan β€” template

CMWAP Pentest Plan β€” Template

8-hour exam. Fill this in and send it to your examiner before the plan deadline in your brief. Nothing here is pre-filled β€” the budget arithmetic is the exercise. No edits after submission; deviations go in the change log. Source for [TEMPLATE] CMWAP Pentest Plan - 010.pdf / .docx. The XSS Rat Β· CMWAP.


Pentest Plan β€” Template

Eight hours. You decide how many of them are testable, and which endpoints get them.

How this is used. Fill it in and send it to your examiner before the plan deadline in your brief. Not a draft β€” the finished plan. Everything after that is graded against what you wrote.

No edits after submission. If something changes, you do not rewrite the plan β€” you add a line to the change log and carry on.

Nothing in this template is filled in for you. The budget is the plan. Working out your own numbers is the exercise β€” a plan you did not do the arithmetic for is a plan you cannot defend in the debrief.

FieldValue
Candidate
Target / engagement
Window opens (T+0:00)date + clock time + timezone
Plan duefrom your brief β€” write the real clock time, not β€œT+…”
Report + debrief due
Authorizationwhat permits this engagement, and any published rules that still apply
Plan versionv1.0

1 Β· Objective (suggested 0:00 – 0:10)

One sentence. Start with a verb, name a consequence. In an eight-hour window you are answering one question well, not surveying an application.


A consequence is something the client feels β€” money, data, trust, downtime. β€œTest the application for vulnerabilities” is an activity, not a consequence.

2 Β· Time budget (suggested 0:10 – 0:20)

Do this before the endpoint table. You cannot decide what to defer until you know what you can afford. Every number below is yours to set and yours to defend.

Fixed costs β€” what the window owes before you test anything

Fixed costHoursWhy that much
Total window8.00given
Writing and sending this planβˆ’
Report β€” ring-fence it, never borrow from itβˆ’
Debrief video: record, review, uploadβˆ’
Setup, access, evidence adminβˆ’
TESTABLE TIME = total βˆ’ fixed costsh= Β Β Β Β  min

Write the minutes figure down. Section 3 has to add up to it.

How the testable time is spent

Wall clockBlockBudgetWhat must be true when it ends
Plan β€” write and sendsubmitted; timer stops
Recon and mapping
IN Β· MUST endpoints
IN Β· SHOULD endpoints
Verify and capture proof
Reportring-fenced; not testing time
Debrief video
Submit and buffer
Testing subtotal β€” recon + MUST + SHOULD + verifyminmust equal your testable time above

3 Β· Endpoint inventory and disposition (suggested 0:20 – 0:35)

One row per endpoint or function β€” not per feature. Every row gets a WSTG ID, a disposition, and a reason a stranger would accept. This table is your scope statement.

IN β€” authorized, relevant, and it fits your budget. You will test it. / OUT β€” not authorized, or not yours to touch. Never tested, at any budget. / DEFERRED β€” authorized and relevant, but it does not fit your testable time. Named, not silently dropped.

#Endpoint / functionMethodRole(s)WSTG ID(s)DispositionWhy this dispositionBudget
1WSTG-min
2WSTG-min
3WSTG-min
4WSTG-min
5WSTG-min
6WSTG-min
7WSTG-min
8WSTG-min
9WSTG-min
10WSTG-min
11WSTG-min
12WSTG-
13WSTG-
14WSTG-
15WSTG-
16WSTG-
17WSTG-
18WSTG-
IN minutes β€” must equal your MUST + SHOULD budget from section 2min

The arithmetic is the discipline. Add up the Budget column for your IN rows. If the total is larger than the MUST + SHOULD figure you set in section 2, you do not have a plan β€” you have a wish. Move rows to DEFERRED until the two numbers match. An examiner can forgive a small scope; nobody forgives a plan that was never achievable.

4 Β· Deferred register (suggested 0:35 – 0:40)

Deferred is a decision, not a gap. Each row names what would have to be true for you to pull it forward β€” that sentence is what you say in the debrief when you are asked what you left on the table, and it is what turns mid-engagement curiosity into a logged decision instead of drift.

Deferred itemWSTG ID(s)Why it did not fitWhat would pull it forward

5 Β· Rules of engagement (suggested 0:40 – 0:45)

Environment (prod / staging / lab)
Accounts issued to you / created by you
Rate limit / thread cap you will hold to
Actions you will NOT take (destructive, DoS, spam)
Out-of-band listener
Evidence: what you capture, where it is stored
Escalation on a critical β€” who, how fast
Abort criteria β€” what makes you stop and report
The line you will not crossthe finding you would confirm but deliberately not develop, and why
Tools declared, with tier (incl. AI)
Time budgeted to verify anything a tool or AI produced

6 Β· Thesis, risks and change log

Thesis

Which IN row do you believe holds the serious finding, and why? Test it first. A thesis that turns out wrong is fine β€” say so and re-plan on the record.


Assumptions and risks

The right-hand column is the useful one: an assumption with no stated fallback is just a hope.

Assumption or riskWhat you do if it turns out false

Change log β€” starts empty, stays open the whole window

Every deviation, with its cost in minutes and what you cut to pay for it. In an eight-hour window an unlogged forty-minute overrun is a large slice of your testable time, unaccounted.

T+What changedCostPaid for by

Before you send it β€” 60-second check

☐ Objective is one sentence and names a consequence Β  ☐ Fixed costs subtracted; testable minutes written down / ☐ Every endpoint row has a WSTG ID Β  ☐ Every row is IN, OUT or DEFERRED β€” none blank / ☐ IN minutes equal your MUST + SHOULD budget Β  ☐ Every deferred row has a trigger / ☐ Abort criteria and the line you will not cross are written Β  ☐ Thesis names one IN row / ☐ Change log present and empty Β  ☐ Sent before the plan deadline

Appendix Β· WSTG v4.2 quick reference

The IDs you will actually reach for on a modern web app. Use this to fill the endpoint table fast β€” a plan with no IDs cannot demonstrate coverage. It is a starting point, not the whole guide: if your target has a surface that is not listed here, go and find the right ID.

IDTestReach for it on
WSTG-CONF-05Enumerate admin interfacesadmin panels, /admin, staff routes
WSTG-CONF-06HTTP methodsany endpoint accepting more than it should
WSTG-IDNT-04Account enumerationlogin, signup, password reset
WSTG-ATHN-03Weak lockout mechanismlogin, OTP, 2FA
WSTG-ATHN-04Bypassing authentication schemaforced browsing past login, token forgery
WSTG-ATHN-09Weak password change / resetreset flows, change-password
WSTG-ATHZ-01Directory traversal / file includefile download, template, path params
WSTG-ATHZ-02Bypassing authorization schemaforce-browsing a privileged route
WSTG-ATHZ-03Privilege escalationrole fields, mass assignment on a write
WSTG-ATHZ-04Insecure direct object referencesany id=, uuid, order or basket ref
WSTG-SESS-02Cookie attributesevery Set-Cookie
WSTG-SESS-03Session fixationlogin β€” does the ID rotate?
WSTG-SESS-05Cross-site request forgeryevery state-changing POST
WSTG-SESS-09Session hijackingtoken replay, JWT tamper and re-sign
WSTG-INPV-01Reflected XSSsearch, filters, error echoes
WSTG-INPV-02Stored XSSprofiles, comments, tickets, notes
WSTG-INPV-05SQL injectionanything reaching a query
WSTG-INPV-18Server-side template injectiontemplated emails, rendered names
WSTG-INPV-19Server-side request forgeryURL fetchers, webhooks, imports, previews
WSTG-BUSL-01Business logic data validationquantity, price, currency fields
WSTG-BUSL-02Ability to forge requestsskipped steps, replayed one-time actions
WSTG-BUSL-09Upload of malicious filesevery upload
WSTG-CLNT-01DOM-based XSShash/postMessage into innerHTML sinks
WSTG-CLNT-04Client-side URL redirect?next=, ?redirect=
WSTG-CLNT-09Clickjackingany sensitive action without frame defence

JWT-specific tests appear as WSTG-SESS-10 in the v4.2 checklist; where your examiner expects the stable-guide numbering, cite WSTG-SESS-09 with WSTG-ATHN-04 and describe the attack.

The XSS Rat Β· CMWAP Β· Authorized testing only. Test only what your endpoint table marks IN.