WEB-300 · OSWE · Teams and individuals
WEB-300: what the course covers - and what we add.
WEB-300 is the whitebox advanced course (OSWE): source code review, finding authentication bypasses, and building your own exploit chains up to remote code execution in real applications.
Who it is for
Experienced web testers and application security engineers with source access.
Course content (official scope)
- →Source review with an attacker mindset
- →Authentication bypasses
- →Deserialisation and type juggling
- →Writing your own exploits
- →Automating the exploit
Course content, labs and the OSWE exam are provided by OffSec. The official course description always takes precedence. This page reviewed: 2026-08-07.
What Exploit Labs adds
- +A review of your own application as the practical case
- +Handover into an application pentest engagement where internal capacity is missing
For security teams
Multiple people, role paths, reporting and procurement run through OffSec Learn Enterprise.
See Learn EnterpriseFor individual practitioners
Individual licence, access duration, exam attempts and preparation - start here.
See individual licences