Web Pentesting Foundations & Methodology

Setup isolated offensive security machines, modern proxy toolchains, and 7-phase methodology

The operational baseline for ethical offensive security engagements. Set up hardened Kali/Parrot virtual environments with network isolation; master the penetration tester toolchain including Burp Suite Pro, Caido, ffuf, Nmap, and SQLmap; and adhere to the rigorous 7-phase black-box penetration testing methodology from scoping to debriefing.

$99 $19 81% OFF
2 CEU Credits
20 Study Hours (4 Weeks)
Foundational
3 Modules
14 Hands-on Labs
Course Tuition
$99 $19 81% OFF
CEU Credits 2 CEUs
Study Workload Breakdown (20 Hours):
Architectural Reading & Theory: 4.7 hrs
Hands-on Labs & Coding Drills: 13.7 hrs
Live Mentorship Cohort $150

Prefer live accountability? Join a guided 4–6 week cohort with weekly live faculty calls, 1-on-1 code reviews & capstone grading. Subsidized by Savadub Limited CSR.

Join Cohort ($150)
Subsidized Tuition: This course is made accessible at $19 through the Corporate Social Responsibility (CSR) endowment from Savadub Limited and partner sponsors.

Course Prerequisites

  • Basic networking concepts (HTTP headers, status codes, DNS, TCP/IP).
Part of Academy Track:
Offensive Security & Web Application Penetration Testing Stage 1 of 3 Courses in this track progression.
Access Lab Materials on LMS
Competency Matrix

What You Will Master

Configure an isolated offensive testing workstation free from DNS and traffic leaks
Intercept, manipulate, and replay HTTP/WebSocket traffic with Burp Suite and Caido
Conduct systematic passive and active reconnaissance against web targets
Operate strictly within legal and ethical Rules of Engagement (ROE)
Detailed Syllabus

Curriculum Modules (3 Modules)

Explore the structured module breakdown, lesson outcomes, and practical lab exercises.

01

Module 1: Offensive Machine Setup & Environment Hardening

4 Lessons • ~4.6 Study Hours (0.46 CEUs)
~4.6 hrs 0.46 CEUs

Welcome to Module 1: Offensive Machine Setup & Environment Hardening. In this section of the curriculum, learners dive deep into foundational and advanced principles designed for production application. This module covers: Configure a dedicated offensive security workstation using Kali Linux or Parrot OS, evaluate physical vs. VM vs. WSL2 setups, and install the complete Kali toolset.; Configure virtual network adapters (Bridged vs. NAT), connect to client VPNs with OpenVPN/WireGuard, verify external IP routing, and prevent DNS leaks during testing.; Configure a dedicated penetration testing browser, install Burp Suite's CA certificate to inspect HTTPS traffic, set up FoxyProxy profiles, and configure essential browser extensions..

01
Recommended OS & Virtualization Setup

Configure a dedicated offensive security workstation using Kali Linux or Parrot OS, evaluate physical vs. VM vs. WSL2 setups, and install the complete Kali toolset.

~73 min Lab Exercise
02
Network Configuration, VPN Routing & DNS Leak Prevention

Configure virtual network adapters (Bridged vs. NAT), connect to client VPNs with OpenVPN/WireGuard, verify external IP routing, and prevent DNS leaks during testing.

~65 min Lab Exercise
03
Browser Proxying & Burp CA Certificate Configuration

Configure a dedicated penetration testing browser, install Burp Suite's CA certificate to inspect HTTPS traffic, set up FoxyProxy profiles, and configure essential browser extensions.

~65 min Lab Exercise
04
Engagement Note-Taking, Evidence Collection & Pre-Flight Check

Organize engagement directories, establish structured evidence collection habits with screenshot tools, and execute a 10-point pre-flight sanity check before touching a target.

~73 min Lab Exercise
Automated Code Evaluations & Lab Grading in LMS Launch in LMS Playground

Welcome to Module 2: Modern Offensive Security Toolchain. In this section of the curriculum, learners dive deep into foundational and advanced principles designed for production application. This module covers: Master the primary interception proxy workflow: Burp Suite Community Edition (Proxy, Repeater, Intruder, Extender), modern lightweight proxy Caido, and OWASP ZAP.; Discover target assets and live endpoints using Subfinder, Amass passive scanning, and httpx for fast probing and technology detection.; Perform targeted port scans and service version detection using Nmap, and fingerprint target web technologies and server headers with WhatWeb..

01
Interception Proxies β€” Burp Suite, Caido & OWASP ZAP

Master the primary interception proxy workflow: Burp Suite Community Edition (Proxy, Repeater, Intruder, Extender), modern lightweight proxy Caido, and OWASP ZAP.

~89 min Lab Exercise
02
Subdomain Enumeration & Asset Discovery Toolkit

Discover target assets and live endpoints using Subfinder, Amass passive scanning, and httpx for fast probing and technology detection.

~65 min Lab Exercise
03
Network Scanning & Technology Fingerprinting

Perform targeted port scans and service version detection using Nmap, and fingerprint target web technologies and server headers with WhatWeb.

~65 min Lab Exercise
04
Web Content Discovery & Directory Fuzzing

Discover hidden directories, files, and virtual hosts using recursive scanners Feroxbuster, Gobuster, and high-performance fuzzer ffuf with SecLists wordlists.

~89 min Lab Exercise
05
Automated Scanners, Exploitation Utilities & Quick Tool Reference

Leverage SQLmap for database exploitation, Nikto for web server misconfiguration checks, Nuclei for template-driven CVE scanning, curl, JWT Tool, and reference table.

~110 min Lab Exercise
Automated Code Evaluations & Lab Grading in LMS Launch in LMS Playground

Welcome to Module 3: End-to-End Engagement Methodology. In this section of the curriculum, learners dive deep into foundational and advanced principles designed for production application. This module covers: Establish legal scope, verify written authorization, set up isolated engagement folders, and execute pre-engagement checklists before touching any target.; Gather intelligence without touching target servers: identify tech stack, enumerate subdomains with Subfinder and Amass, probe live assets with httpx, and mine GitHub for leaked secrets.; Directly interact with target infrastructure: port scanning with Nmap, web directory fuzzing with Feroxbuster, tech fingerprinting, and parsing JavaScript bundles for hidden endpoints..

01
Pre-Engagement Scoping & Legal Authorization

Establish legal scope, verify written authorization, set up isolated engagement folders, and execute pre-engagement checklists before touching any target.

~65 min Lab Exercise
02
Phase 1: Passive Reconnaissance Workflow

Gather intelligence without touching target servers: identify tech stack, enumerate subdomains with Subfinder and Amass, probe live assets with httpx, and mine GitHub for leaked secrets.

~110 min Lab Exercise
03
Phase 2: Active Reconnaissance & Attack Surface Mapping

Directly interact with target infrastructure: port scanning with Nmap, web directory fuzzing with Feroxbuster, tech fingerprinting, and parsing JavaScript bundles for hidden endpoints.

~105 min Lab Exercise
04
Phases 3 to 6: Authentication, Authorization, Injection & API Testing

Execute systematic vulnerability assessments covering authentication, role-based authorization (IDOR), input injection (SQLi, XSS, Cmdi), and API-specific test suites.

~65 min Lab Exercise
05
Phases 7 to 11: Uploads, Logic, Sessions, Infra & Reporting Workflow

Complete engagement execution: test file upload controls, business logic flows, session security, infrastructure misconfigurations, and review engagement time estimates.

~65 min Lab Exercise
Automated Code Evaluations & Lab Grading in LMS Launch in LMS Playground

Offensive Security & PenTest Progression

Continue advancing through the sequential curriculum stages of this academy track:

STAGE 1 4 Weeks
Web Pentesting Foundations & Methodology
Currently Viewing
Enroll in SEC-101 on LMS