Course Outline
Introduction
Overview of the Web Security Testing Guide
- The OWASP Testing Project
- Tailoring and prioritizing frameworks for organizations
- Core testing principles and techniques
- Defining security testing objectives and requirements
Exploring Various Testing Techniques
- Manual inspections and code reviews
- Threat modeling practices
- Source code analysis
- Penetration testing strategies
- Integrating security tests and analyzing data
Understanding the OWASP Testing Framework
- Activities spanning from development to deployment
- Maintenance and operational considerations
- End-to-end lifecycle testing framework and workflow
- Methodologies for penetration testing
Executing Web Application Security Testing
- Gathering relevant information
- Testing configuration and deployment management
- Identity management verification
- Authentication and authorization controls
- Session management integrity
- Input validation checks
- Error handling mechanisms
- Weak cryptography detection
- Business logic vulnerabilities
- Client-side security checks
- API security testing
Reporting on Testing Assessments and Results
- Composing the introduction section
- Drafting the executive summary
- Detailing the findings section
- Including relevant appendices
Engaging with the Web Security Testing Guide
- Referencing and linking WSTG scenarios
- Adhering to the code of conduct
- Following the contribution guide
- Submitting feature requests and feedback
Summary and Conclusion
Requirements
- A foundational understanding of the web development lifecycle
- Practical experience in web application development, security, and testing
Target Audience
- Developers
- Engineers
- Architects
Testimonials (2)
The training helped me expand my knowledge and understanding of Burp Suite. I also realized that what I had learned through self-study was still quite limited. This training was very helpful to me as a QA because Burp Suite is a valuable tool for performing security testing and improving the overall quality of application testing. I will continue exploring this tool and learning more about its features and capabilities.
Rea Mendez - BAKAWAN Data Anallytics Inc.
Course - OWASP Top 10 2025
I really enjoyed learning about AI attacks and the tools out there to begin practicing and actively using for security testing. I took a lot of knowledge away which I didn't have at the beginning and the course met what I hoped it would be. My favorite part shown from the training was Comet Browser and was amazed at what it could do. Definitely something will be looking into more. Overall it was a great course and enjoyed learning all OWASP GenAI Top 10.