This certification has been designed by industry experts to validate the hands-on, job-ready skills required to attack real web applications across every testing scenario. It focuses on practical web application pentesting across the full exploitation spectrum - from blackbox authentication attacks and whitebox source review through to the full injection and client-side attack surface - aligned to real-world appsec workflows and OWASP Top 10.
A Guide to Web Application Pentesting Skills
WEB1 training content Blackbox exploitation (Section 1 - 20%, 1 flag)
Break into web applications with no source access, the way an external attacker sees them. Exploit authentication, session, and access-control flaws using only what the application exposes: predictable reset tokens, weak or none-algorithm JWTs, MFA bypass, OAuth misconfiguration, broken session management, trusted-header bypass, and IDOR. Covers Authentication / Authorisation, Session Management, and Sensitive Information Disclosure.
Whitebox exploitation (Section 2 - 20%, 1 flag)
Read the source, then break the server. Work with access to source code to discover and exploit the hardest server-side vulnerability classes the way appsec engineers who live in code actually work. Covers HTTP request smuggling, race conditions, insecure deserialisation, and SSRF.
Greybox exploitation (Section 3 - 60%, 5 flags at 120 each)
Work the full injection and client-side spectrum with partial knowledge of the target - the largest section of the exam. Exploit the full injection spectrum (SQL, NoSQL, LDAP, ORM, command, XXE, SSTI) and client-side attacks (reflected/stored XSS, DOM-based XSS, CSRF, CORS misconfiguration, prototype pollution), alongside authorisation, session management, and file I/O flaws. Five vulnerabilities are live per instance.
Professional reporting & remediation
For every vulnerability, produce a short write-up covering the attack description, practical remediation guidance, and correct naming/classification of the vulnerability. Within each flag: 70% exploitation, 12.5% attack description, 12.5% remediation, 5% correct vulnerability naming.
Tooling & workflow fluency
Every target is a deployable web application. Attack it from the TryHackMe AttackBox or your own VPN-connected machine. All you need is a browser and your usual web testing toolkit. No paid tool licence (e.g. Burp Suite Pro) is required to sit the exam.
Frequently Asked Questions
What is WEB1?
What is WEB1?
A hands-on web application security certification that proves you can find, exploit and remediate named web vulnerabilities across three access models: blackbox, whitebox and greybox. Every exercise is a deployable web app you attack from the AttackBox or your own VPN-connected machine, recovering a unique flag and writing a short report per vulnerability.
Who is WEB1 Designed for?
Who is WEB1 Designed for?
Appsec and cyber security students proving practical web skills, software engineers moving into application security, junior pentesters specialising in web, and anyone preparing for PT1 who wants to build web depth first.
Is WEB1 entry-level?
Is WEB1 entry-level?
No. It's a focused web specialisation that runs well into intermediate territory (request smuggling, race conditions, insecure deserialisation, prototype pollution). It sits before PT1 in the learning path as pre-preparation.
How is WEB1 different from other web certifications?
How is WEB1 different from other web certifications?
It assesses three access models in one exam (no rival under $1,749 assesses whitebox at all), combines flag-verified exploitation with per-vulnerability remediation reporting, and gives you a 48-hour window instead of a 4-hour sprint.
What does the exam format look like?
What does the exam format look like?
48 hours, fully hands-on. Three sections (blackbox 20%, whitebox 20%, greybox 60%), 1000 points, pass at 70%. Exploitation is 70% of each flag; the write-up (attack description, remediation, vulnerability name) is the other 30%.
Do I need to buy any extra tools?
Do I need to buy any extra tools?
No. Unlike BSCP, which requires an active Burp Suite Professional licence (~$499/yr) to sit, WEB1 includes everything. The AttackBox provides a full web testing toolkit, or connect your own machine over VPN.
Is WEB1 fully hands-on?
Is WEB1 fully hands-on?
Yes. There are no multiple-choice questions. You exploit live, deployable web applications, recover unique flags, and document each finding. Flags verify your exploitation objectively, and your write-ups are graded against a rubric.
Is there a retake policy?
Is there a retake policy?
Yes. One free retake is included, with fresh per-instance flags.
Will employers recognise WEB1?
Will employers recognise WEB1?
As a new certification, we position WEB1 as skills proof plus portfolio evidence: your per-vulnerability reports are tangible work product you can show employers. We recommend pairing it with established certs as your career progresses.
Does WEB1 expire?
Does WEB1 expire?
Validity terms will be confirmed at launch.
How does WEB1 relate to PT1?
How does WEB1 relate to PT1?
WEB1 is a web application pentesting certification that runs alongside PT1 rather than building on top of it. You don't need to complete PT1 first. WEB1 sits in its own web-focused track, similar to how other providers offer a dedicated web path next to their core pentesting certs. Think of them as parallel specialisations: PT1 for network/infrastructure pentesting, WEB1 for web app pentesting.
Still got more questions?
You can reach out to [email protected] or ask in our Discord server or Subreddit for further assistance.
TryHackMe
