OSWE
OffSec

Offensive Security Web Expert

Expert Source-code-driven practical exam + exploit/report Pass: Objective/report-based; exact threshold may vary … $1,499

OSWE emphasizes white-box web exploitation and source-code-driven vulnerability discovery. A strong 2026 approach combines static analysis, exploit chaining, and concise technical communication.

Official Page
IssuerOffSec
FormatSource-code-driven practical exam + exploit/report
Duration48h exam window + report window (indicative)
Pass ScoreObjective/report-based; exact threshold may vary …
Valid For3y
Prerequisites
Recommended: HTTP/HTTPS fundamentals, web app architecture basics, JavaScript familiarity, and hands-on exposure to OWASP Top 10 style issues.
Syllabus Overview

5 exam domains — click "Syllabus" tab for full breakdown

Web Recon & Attack Surface Mapping 20%
Input Validation & Injection 25%
Authentication, Session & Access Control 25%
Business Logic & Modern Web Risks 15%
Reporting & Patch Verification 15%