Penetration Testing & Web Exploitation
This is the core of the program. Six weeks of structured, end-to-end penetration testing across networks, web applications, wireless environments and Active Directory — the exact scope of a professional VAPT engagement.
What You Will Learn
A detailed, industry-aligned breakdown of every topic covered in this module.
- DoS/DDoS concepts and attack techniques
- Firewall configuration and wireless encryption standards
- Session hijacking concepts and cookie-based attacks
- IDS, IPS, firewall and honeypot evasion techniques
- Web server and web application attack methodology
- SQL Injection — concepts, types and injection tooling
- Cross-Site Scripting (XSS) — reflected, stored and DOM-based
- The OWASP Top 10 web application vulnerabilities
- Active Directory concepts and common AD attack techniques
- Wireless network security assessment and WiFi attack techniques
- Cloud security concepts and cloud service models (IaaS, PaaS, SaaS)
- End-to-end penetration testing methodology and rules of engagement
- Professional penetration test reporting standards
Tools You Will Use
Hands-on time with the same tools used in professional security operations and penetration-testing engagements.
Burp Suite
Web application testing proxy used to intercept, manipulate and fuzz HTTP/S traffic during assessments.
OWASP ZAP
Open-source web application scanner used to identify OWASP Top 10 vulnerabilities in target applications.
SQLmap
Automated SQL injection detection and exploitation tool used against database-backed applications.
Nikto
Web server scanner used to identify outdated software, dangerous files and common misconfigurations.
Wireshark
Network protocol analyzer used to capture and inspect live traffic at the packet level.
Cain & Abel
Windows password recovery and network analysis tool used for credential attacks and traffic sniffing.
Hydra
Parallelized login-cracking tool used to test authentication strength across network services.
Hands-On Labs
Enterprise and SOC-style lab scenarios, run inside your isolated penetration-testing environment.
Execute a SQL injection attack chain against a vulnerable web application.
Identify and exploit XSS vulnerabilities across an OWASP Top 10 lab set.
Run a wireless network security assessment and document WiFi attack findings.
Simulate an Active Directory attack path inside a lab domain environment.
Run a full network and web application penetration test and deliver a professional report.
Assessment
Knowledge Assessment
Quiz covering the OWASP Top 10, Active Directory attack concepts and wireless security fundamentals.
Practical Evaluation
A full penetration-testing engagement on an assigned lab environment, scored against professional reporting standards.
Projects
Industry-style deliverables added directly to your project portfolio.
Web Application Security Audit (OWASP Top 10)
A full application-layer assessment mapped against the OWASP Top 10, with remediation guidance.
Internal Network Penetration Test Report
An end-to-end internal network pentest, scoped, executed and reported to professional standard.
Active Directory Attack Path & Wireless Security Assessment
A combined AD attack-path analysis and wireless security review with findings and fixes.
What This Module Builds
Students learn to plan and execute end-to-end penetration tests across networks, web applications, wireless networks and Active Directory environments.
