u/Background-Moment342

For Web Pentesting Learners: Would You Recommend PortSwigger or HTB CWES?

I’m currently planning to focus more on web exploitation/web pentesting, and before fully committing to a platform, I wanted to ask for opinions from people who have already used both.

In terms of:

  • quality of content
  • labs/practical exercises
  • learning experience
  • difficulty progression
  • overall comfort/UI/community

Which do you think is better for learning web exploitation: PortSwigger Web Security Academy or Hack The Box CWES and CWEE Path?

I’m still a student, so I’m trying to choose where I should invest more of my time first.

I’d really appreciate hearing your experiences, especially from people who completed either platform/path. Thanks!

reddit.com