Rabat, MoroccoOn-site · Virtual classroom · Corporate training
contact@avnorysacademy.com

Offensive cybersecurity

Web application penetration testing

Conduct a methodical, repeatable and risk-focused web penetration test, from reconnaissance to reporting.

Learning objectives

  • Prepare a test scope and strategy
  • Identify and validate common web vulnerabilities
  • Assess business impact without disrupting the target
  • Produce evidence, recommendations and an actionable report

Who should attend

Junior penetration testers, security developers, AppSec analysts and security engineers.

Prerequisites

Foundations in HTTP, Linux, networking, web development and application security.

Course outline

  • Legal framework, rules of engagement and methodology
  • Reconnaissance, mapping, authentication and sessions
  • Access controls, injection, input validation and business logic
  • Client-side testing, APIs, web services and configuration
  • Manual validation, controlled exploitation and evidence management
  • Scoring, presentation, reporting and remediation workshop

Learning approach

Structured instruction, demonstrations, guided exercises, case studies and learning assessment. Technical environments are used only within an authorised context.

Reference source: OWASP Web Security Testing Guide ↗
Avnorys programme aligned with the OWASP WSTG. It does not constitute an OWASP certification.