This class is designed for cybersecurity professionals, VAPT engineers, AppSec engineers, security testers, penetration testers, and beginners who want to build practical skills in Dynamic Application Security Testing (DAST).
The course focuses on hands-on web application security testing rather than source-code analysis. Students will learn how to understand application functionality, identify attack surfaces, intercept and modify HTTP/HTTPS requests, and perform manual and automated security testing.
Key topics include reconnaissance, application mapping, authentication and session management testing, authorization testing, IDOR, SQL Injection, Cross-Site Scripting (XSS), CSRF, SSRF, file upload vulnerabilities, path traversal, command injection, security misconfigurations, information disclosure, open redirects, business logic vulnerabilities, and other common web application security issues.
Students will learn practical workflows using tools such as Burp Suite and OWASP ZAP, along with techniques for validating automated scanner findings manually. The course also covers vulnerability severity assessment, evidence collection, reproduction steps, impact analysis, remediation recommendations, and professional security reporting.