> For the complete documentation index, see [llms.txt](https://ajaykumar-kanthi.gitbook.io/write-ups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ajaykumar-kanthi.gitbook.io/write-ups/blogs/how-i-passed-the-htb-cwes-exam.md).

# How I Passed the HTB-CWES Exam

Captured 10/10 flags in 2 days.

The HTB Certified Web Exploitation Specialist (CWES) exam gives you 7 days to work through a set of targets and then write up a professional report. I passed it, and here's a breakdown of how the week went and what actually helped along the way.

<figure><img src="https://3740518612-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FOH84nxPA0OhkjhNX692h%2Fuploads%2F5wZLmT1hNCJ2wb5qnfhP%2Fimage.png?alt=media&amp;token=87c5f1d7-5799-486a-9008-159ead25bb10" alt=""><figcaption></figcaption></figure>

### My Timeline

* **Day 1:** Got 9 flags. This was the momentum day  most of the applications fell into place once I settled into a rhythm.
* **Day 2:** Cleared the remaining flag. This one took more digging than the rest.
* **Day 3:** Wrote and submitted the report.

That left several days of buffer I didn't even need, but having that time on the clock is part of what made the exam feel manageable rather than rushed.

The one flag that gave me real trouble was **Flag 6**. Everything else went smoothly. Coming into this right after passing CPTS, the exam felt noticeably easier  the CPTS grind had already built up the mindset this exam expects.

#### Watch Out for the Honeypots

The exam has a good number of honeypots scattered around. It's easy to sink hours into something that looks promising and turns out to be a dead end designed to waste your time. If something feels off, or a path seems too obvious, don't burn your whole day chasing it. Step back, reassess, and don't be afraid to abandon a lead that isn't producing results.

#### Stick to What's in the Modules

This is probably the most important mindset shift: **don't try to invent exploits or techniques that aren't covered in the CWES modules.** The exam is scoped tightly to the material in the path  if you're reaching for something exotic or trying to force a custom technique, it's simply not going to work, and you're wasting time chasing something the exam was never built to test. Everything you need is already in the coursework. The exam rewards recognising the pattern from the modules and applying it methodically, not creativity for its own sake.

#### Grind the CWES Preparation Track Machines

Getting familiar with the preparation track machines before sitting the exam made a huge difference. It's not just about knowing techniques  it's about training how you *think* and *process* a box under exam conditions. The prep machines condition you to the exam's style of thinking, so when you hit something similar during the real thing, your brain already has a groove to fall into instead of starting from scratch.

#### Take Breaks Seriously

When you feel exhausted, or you've run out of ideas on a target, step away. Pushing through mental fatigue rarely gets you the flag faster it usually just burns time while you stare at the same dead end. A short break resets your perspective, and more often than not you'll come back and spot something you completely missed before. This mattered a lot for how I approached the tougher moments during the exam.

#### If You're Studying for CPTS

If CPTS is next on your list, CWES is genuinely great practice leading up to it. It sharpens the flow of thinking through and exploiting vulnerabilities step by step, which is exactly the muscle CPTS leans on. Doing them in either order builds on the other.

#### Final Thoughts

CWES rewards preparation, discipline, and sticking to the scope of what's taught  not improvisation. Grind the prep machines, don't chase honeypots, trust the modules, and take breaks when you need them. Do that, and the exam is very achievable.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://ajaykumar-kanthi.gitbook.io/write-ups/blogs/how-i-passed-the-htb-cwes-exam.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
