Web Application Pentest Training
Security testing training for web applications.
Overview
Course overview
This course teaches practical web application penetration testing, covering the OWASP Top 10 and beyond through hands-on lab exercises against real, vulnerable applications. Participants learn to find and exploit common web flaws while understanding the secure coding practices needed to prevent them in production.
Who It's For
Who this training is for
Objectives
What you'll learn
Curriculum
Curriculum & modules
- Web application security fundamentals & HTTP deep dive
- OWASP Top 10 overview
- Reconnaissance and information gathering for web targets
- SQL Injection — in-band, blind, and out-of-band
- Cross-Site Scripting (XSS) — reflected, stored, and DOM-based
- Cross-Site Request Forgery (CSRF)
- Broken authentication and session management
- Broken access control and IDOR
- Security misconfiguration
- File upload and file inclusion vulnerabilities (LFI/RFI)
- XML External Entity (XXE) injection
- Server-Side Request Forgery (SSRF)
- Insecure deserialization
- API security testing (REST/GraphQL)
- Business logic vulnerabilities
- Reporting and remediation guidance
How It's Taught
Practical, hands-on training
Hands-on lab environments
Practical exercises using real tooling, not lecture-only theory.
Live instructor-led sessions
Delivered live by an instructor — not a self-paced video course.
Tools
Tools & technologies
Training Format
Live, instructor-led sessions
This course is delivered as live, instructor-led training with hands-on labs — not a self-paced video course.
Related Training
You may also be interested in
Ready to enquire about Web Application Pentest Training?
Reach out to discuss scheduling and get the latest details on this course.