ZETLAN TECHNOLOGIES
Course Categories 172+
Cloud & Infrastructure 7
Networking 8
Virtualisation 5
IT Security 10
CyberSecurity & Mgmt 14
Software Development 16
Web Dev & Database 27
Data Science & AI 14
Mobile, Testing & Games 22
Design & Creative 49
Navigation
Home Business About Us Contact Us All Courses FAQ & Help
Contact Us
+91 8680961847 +91 8680961847 (WhatsApp) info@zetlantechnologies.com
Browse by Domain
Cloud & Infrastructure 7
Networking 8
Virtualisation 5
IT Security 10
CyberSecurity & Mgmt 14
Software Development 16
Web Dev & Database 27
Data Science & AI 14
Mobile, Testing & Games 22
Design & Creative 49
2000+ Courses · 15+ Technology Domains
Microsoft Cisco AWS EC-Council View All Courses
Home  /  Kali OffSec  /  OSWA
Core · Web Security

OSWA

OffSec Web Assessor

Learn a repeatable black-box web assessment workflow covering request analysis, common vulnerability classes, exploitation and actionable reporting.

Course overview

Skills with real-world context

Designed around the workflows and decisions practitioners use—not a collection of disconnected tool demonstrations.

Learn a repeatable black-box web assessment workflow covering request analysis, common vulnerability classes, exploitation and actionable reporting. The learning path combines guided concepts, repeatable lab methodology, evidence collection and professional communication.

Web Security Analyst Application Security Tester Junior Penetration Tester
2026 market direction

Web and API attack surfaces continue to expand as organizations ship cloud-native products faster. Testers who can manually validate issues beyond scanner output remain valuable.

Course content

What you will study

A focused six-module roadmap. Exact official syllabus and assessment policies remain subject to OffSec updates.

01

HTTP & Assessment Setup

Requests, responses and headers
Cookies, sessions and tokens
Proxy configuration
Testing scope and methodology
02

Application Mapping

Content and endpoint discovery
Parameters and input points
Technology fingerprinting
Authentication flow mapping
03

Input Vulnerabilities

Injection fundamentals
File path and inclusion issues
Command execution pathways
Validation and encoding bypasses
04

Identity & Access

Authentication weaknesses
Session handling flaws
Authorization testing
Password reset workflows
05

Browser & Server Attacks

Cross-site scripting
Cross-site request forgery
File upload weaknesses
Server-side request behavior
06

Exploitation & Reporting

Manual proof development
Impact validation
Evidence collection
Developer-friendly remediation
Plan your preparation

Audience, prerequisites and exam

Who should attend

  • Pentesters starting web application testing
  • Developers moving into application security
  • QA and security analysts validating web risk

Recommended prerequisites

Basic Linux, networking, HTTP, HTML and scripting knowledge. Familiarity with browser developer tools helps.

Certification assessment

A practical web application assessment and report. Consult the official exam guide for current scope and delivery details.

Learning outcomes

Capabilities you will build

Map a web application attack surface
Use a proxy-led manual testing workflow
Exploit common web vulnerability classes
Produce reproducible findings and remediation advice
Primary curriculum reference: Official OSWA course information . Pricing, exam format and availability should always be confirmed with OffSec.