Home eWPT prep
INE Security · 23 live drills mapped

eWPT practice,
one technique at a time.

Make web exploitation a reflex. The eWPT is a practical web-application penetration test against a realistic target, reported like a real engagement. PwnKata drills every primitive it leans on — injection, inclusion, upload-to-shell, SSRF, and access-control flaws — as repeatable reps on live targets, so you walk in with the workflow already in your fingers.

Exam Hands-on web-application pentest · realistic target · professional written report.
Syllabus map

The eWPT skills, as drillable reps.

Each exam area maps to a set of single-technique drills you can grind until recognition is automatic.

Before exam day

Know you're ready — don't guess.

When the techniques feel automatic, run an Exam Sprint: a timed battery of unseen, blind items weighted to the eWPT blueprint. It returns a readiness report by skill area, so you find your weak spot here instead of in the exam.

  • Blind items — identify the weakness yourself, like the real thing
  • Solved-vs-attempted by skill area, with time outliers flagged
  • A readiness verdict you can actually act on
eWPT sprint readiness On track
Recon & content discovery 86%
Injection attacks 68%
File & inclusion attacks 44%
Server-side attacks 80%
Client-side & access control 86%
⚠ illustrative — your report is built from your own reps

Start your eWPT reps

Free to start — live isolated targets, a fresh variant every rep.

Start drilling