Web Pentesting Foundations & Methodology
Setup isolated offensive security machines, modern proxy toolchains, and 7-phase methodology
The operational baseline for ethical offensive security engagements. Set up hardened Kali/Parrot virtual environments with network isolation; master the penetration tester toolchain including Burp Suite Pro, Caido, ffuf, Nmap, and SQLmap; and adhere to the rigorous 7-phase black-box penetration testing methodology from scoping to debriefing.
Course Prerequisites
- Basic networking concepts (HTTP headers, status codes, DNS, TCP/IP).
Part of Academy Track:
What You Will Master
Curriculum Modules (3 Modules)
Explore the structured module breakdown, lesson outcomes, and practical lab exercises.
Module 1: Offensive Machine Setup & Environment Hardening
4 Lessons • ~4.6 Study Hours (0.46 CEUs)Welcome to Module 1: Offensive Machine Setup & Environment Hardening. In this section of the curriculum, learners dive deep into foundational and advanced principles designed for production application. This module covers: Configure a dedicated offensive security workstation using Kali Linux or Parrot OS, evaluate physical vs. VM vs. WSL2 setups, and install the complete Kali toolset.; Configure virtual network adapters (Bridged vs. NAT), connect to client VPNs with OpenVPN/WireGuard, verify external IP routing, and prevent DNS leaks during testing.; Configure a dedicated penetration testing browser, install Burp Suite's CA certificate to inspect HTTPS traffic, set up FoxyProxy profiles, and configure essential browser extensions..
Recommended OS & Virtualization Setup
Configure a dedicated offensive security workstation using Kali Linux or Parrot OS, evaluate physical vs. VM vs. WSL2 setups, and install the complete Kali toolset.
Network Configuration, VPN Routing & DNS Leak Prevention
Configure virtual network adapters (Bridged vs. NAT), connect to client VPNs with OpenVPN/WireGuard, verify external IP routing, and prevent DNS leaks during testing.
Browser Proxying & Burp CA Certificate Configuration
Configure a dedicated penetration testing browser, install Burp Suite's CA certificate to inspect HTTPS traffic, set up FoxyProxy profiles, and configure essential browser extensions.
Engagement Note-Taking, Evidence Collection & Pre-Flight Check
Organize engagement directories, establish structured evidence collection habits with screenshot tools, and execute a 10-point pre-flight sanity check before touching a target.
Module 2: Modern Offensive Security Toolchain
5 Lessons • ~7 Study Hours (0.7 CEUs)Welcome to Module 2: Modern Offensive Security Toolchain. In this section of the curriculum, learners dive deep into foundational and advanced principles designed for production application. This module covers: Master the primary interception proxy workflow: Burp Suite Community Edition (Proxy, Repeater, Intruder, Extender), modern lightweight proxy Caido, and OWASP ZAP.; Discover target assets and live endpoints using Subfinder, Amass passive scanning, and httpx for fast probing and technology detection.; Perform targeted port scans and service version detection using Nmap, and fingerprint target web technologies and server headers with WhatWeb..
Interception Proxies β Burp Suite, Caido & OWASP ZAP
Master the primary interception proxy workflow: Burp Suite Community Edition (Proxy, Repeater, Intruder, Extender), modern lightweight proxy Caido, and OWASP ZAP.
Subdomain Enumeration & Asset Discovery Toolkit
Discover target assets and live endpoints using Subfinder, Amass passive scanning, and httpx for fast probing and technology detection.
Network Scanning & Technology Fingerprinting
Perform targeted port scans and service version detection using Nmap, and fingerprint target web technologies and server headers with WhatWeb.
Web Content Discovery & Directory Fuzzing
Discover hidden directories, files, and virtual hosts using recursive scanners Feroxbuster, Gobuster, and high-performance fuzzer ffuf with SecLists wordlists.
Automated Scanners, Exploitation Utilities & Quick Tool Reference
Leverage SQLmap for database exploitation, Nikto for web server misconfiguration checks, Nuclei for template-driven CVE scanning, curl, JWT Tool, and reference table.
Module 3: End-to-End Engagement Methodology
5 Lessons • ~6.8 Study Hours (0.68 CEUs)Welcome to Module 3: End-to-End Engagement Methodology. In this section of the curriculum, learners dive deep into foundational and advanced principles designed for production application. This module covers: Establish legal scope, verify written authorization, set up isolated engagement folders, and execute pre-engagement checklists before touching any target.; Gather intelligence without touching target servers: identify tech stack, enumerate subdomains with Subfinder and Amass, probe live assets with httpx, and mine GitHub for leaked secrets.; Directly interact with target infrastructure: port scanning with Nmap, web directory fuzzing with Feroxbuster, tech fingerprinting, and parsing JavaScript bundles for hidden endpoints..
Pre-Engagement Scoping & Legal Authorization
Establish legal scope, verify written authorization, set up isolated engagement folders, and execute pre-engagement checklists before touching any target.
Phase 1: Passive Reconnaissance Workflow
Gather intelligence without touching target servers: identify tech stack, enumerate subdomains with Subfinder and Amass, probe live assets with httpx, and mine GitHub for leaked secrets.
Phase 2: Active Reconnaissance & Attack Surface Mapping
Directly interact with target infrastructure: port scanning with Nmap, web directory fuzzing with Feroxbuster, tech fingerprinting, and parsing JavaScript bundles for hidden endpoints.
Phases 3 to 6: Authentication, Authorization, Injection & API Testing
Execute systematic vulnerability assessments covering authentication, role-based authorization (IDOR), input injection (SQLi, XSS, Cmdi), and API-specific test suites.
Phases 7 to 11: Uploads, Logic, Sessions, Infra & Reporting Workflow
Complete engagement execution: test file upload controls, business logic flows, session security, infrastructure misconfigurations, and review engagement time estimates.
Offensive Security & PenTest Progression
Continue advancing through the sequential curriculum stages of this academy track: