What you will study
A focused six-module roadmap. Exact official syllabus and assessment policies remain subject to OffSec updates.
Learn a repeatable black-box web assessment workflow covering request analysis, common vulnerability classes, exploitation and actionable reporting.
Designed around the workflows and decisions practitioners use—not a collection of disconnected tool demonstrations.
Learn a repeatable black-box web assessment workflow covering request analysis, common vulnerability classes, exploitation and actionable reporting. The learning path combines guided concepts, repeatable lab methodology, evidence collection and professional communication.
Web and API attack surfaces continue to expand as organizations ship cloud-native products faster. Testers who can manually validate issues beyond scanner output remain valuable.
A focused six-module roadmap. Exact official syllabus and assessment policies remain subject to OffSec updates.
Basic Linux, networking, HTTP, HTML and scripting knowledge. Familiarity with browser developer tools helps.
A practical web application assessment and report. Consult the official exam guide for current scope and delivery details.