Learning objectives
- Prepare a test scope and strategy
- Identify and validate common web vulnerabilities
- Assess business impact without disrupting the target
- Produce evidence, recommendations and an actionable report
Who should attend
Junior penetration testers, security developers, AppSec analysts and security engineers.
Prerequisites
Foundations in HTTP, Linux, networking, web development and application security.
Course outline
- Legal framework, rules of engagement and methodology
- Reconnaissance, mapping, authentication and sessions
- Access controls, injection, input validation and business logic
- Client-side testing, APIs, web services and configuration
- Manual validation, controlled exploitation and evidence management
- Scoring, presentation, reporting and remediation workshop
Learning approach
Structured instruction, demonstrations, guided exercises, case studies and learning assessment. Technical environments are used only within an authorised context.
Reference source: OWASP Web Security Testing Guide ↗
Avnorys programme aligned with the OWASP WSTG. It does not constitute an OWASP certification.
Avnorys programme aligned with the OWASP WSTG. It does not constitute an OWASP certification.
