Skip to content
normSight — Cyber Security

Defensive Trainings

Web Application Security

The Web Application Security (PWD) course gives developers and defensive teams the skills to close vulnerabilities in web applications and detect attacks against them.

Study at Your Own Pace

PWD comes with lifetime access to course materials and flexible access to the world’s best Web Application Security virtual labs.

Highly Practical

Apply web application defence against real-world attacks. PWD includes the most advanced virtual lab in IT Security.

The Course at a Glance

  • Close the gap between web application attack and defence
  • Mitigation recommendations for multiple platforms and languages
  • Full coverage of the OWASP Testing Guide
  • Comprehensively aligned with OWASP methodologies, tools and tests
  • Covers the OWASP Top 10 and goes beyond it
  • Detailed techniques and methodology for simplifying the defence of web applications
  • No tedious theory: a practice-oriented curriculum
  • More than 20 different lab scenarios
  • Advanced use of OWASP ZAP, OWASP OWTF and ModSecurity
  • Coverage of the OWASP Cheat Sheets, OWASP OpenSAMM and the OWASP ModSecurity Core Rule Set

Course Material

  • 25 hours of HQ video training material
  • 2700+ slides
  • 20 labs in Hera

Course Delivery

  • Self-paced
  • Offline access available
  • Access from PC, tablet and smartphone

Curriculum

Module 1: Introduction to the Tools

Module 2: Information Gathering

Module 3: Configuration Management

Module 4: Authentication

Module 5: Authorisation

Module 6: Session Management

Module 7: Business Logic Flaws

Module 8: Data Validation

Module 9: Cryptography

Module 10: Denial of Service

Module 11: Web Services

Module 12: Client Side and Phishing

Module 13: Error Handling and Logging

Module 14: Applied Secure Coding Principles

Module 15: Virtual Patching and Intrusion Detection

Module 16: Securing Web Applications

  • Prerequisites

  • Basic programming knowledge: loops, variables, functions, file includes and so on

  • Reading and understanding PHP code is not required but will help

  • Basic knowledge of tools such as curl, Wireshark and OWASP ZAP (or Burp)

  • Knowledge of security concepts is an advantage but not mandatory

Who Can Attend

  • Web developers
  • Web application security researchers
  • Penetration testing teams
  • IT managers and staff

Frequently Asked Questions

Is this course for developers or for security professionals?

It suits both. Developers learn how a vulnerability arises and how to close it in code, while security teams learn how to detect the corresponding attack in production.

How does it differ from the web application penetration testing course?

The penetration testing course teaches how to find and exploit vulnerabilities. This course teaches how to close those same vulnerabilities, make secure design decisions and detect attacks — it is on the defensive side.

Which technologies are covered?

The course is built on language- and framework-agnostic security principles; examples are worked through hands-on using common web technologies.

See the real risks in your systems.

Talk to our team about a penetration test or training plan that fits your scope.