Hands-on pentesting exercises
Prior to conducting the training with your team, we’ll have an initial scoping meeting. This session is designed to customize the course to your specific requirements, helping us decide on the most suitable approach and focus areas to address your needs effectively.
Why this training is built around exercises
An investigation among 194 industry developers (Gasiba, Lechner, Pinto-Albuquerque et al., ICSE-SEET 2021) found that 51% recognized vulnerable code and 40% could write a secure version. Recognizing a flaw and writing the fix are different skills. So I teach through exercises aimed at concepts, not through a lecture and not through a catalog of isolated cases. The same survey that names hands-on formats, including capture-the-flag events, also says secure-coding training should focus on concepts rather than specific cases.
In my hands-on pentesting training, we will attack my training web application targets (spawned in my cloud for each participant). The participants will learn how to use professional security tools through numerous practical exercises as well as the general procedure of pentesters when attacking web applications and backends.
The attack paths learned in this training include pivoting and post-exploitation for a deeper persistence in the attacked system. Interactive engagement elements via Workshop Board keep participants involved throughout the session, whether attending remotely or on-site.
The training can either use the open-source intercepting proxy OWASP ZAP or the more pentester oriented Burp Suite Pro, depending on your choice.
My hands-on pentesting training is highly modular—you can choose which vulnerabilities and exploit styles your team wants to focus on.
Select from the following topics to tailor the training to your needs:
- Injection Vulnerabilities, including Post-Exploitation towards Remote Code Execution (RCE)
- XML External Entity Attacks (XXE)
- Path-Traversals (including ClassPath-Traversals)
- Cross-Site Scripting (XSS): Reflected, Persistent, DOM-based and different contexts
- Session Attacks, etc.
- Authentication Bypass
- Information Disclosures
- Server-Side Request Forgery (SSRF), especially in cloud-based environments
- Attacks on File-Uploads and -Downloads
- Attacks on WebSockets
- Java Deserialization Vulnerabilities & Attacks: Trigger-, Abuse-, Bypass-, and Golden-Gadgets
- In-band signaling: Time-based & Denial-of-Service
- Out-of-band signaling: Generic DNS-Payloads
- Advanced XML Attacks (leading to RCEs)
- JSON Attacks (leading to RCEs)
- GenAI & Agentic Systems: Prompt Injection Exploitation, RAG Data Poisoning, MCP Tool Poisoning & Rug Pulls
- Analyzing security of Low-Code/No-Code Platforms
- Checking Passkey implementation security
- Attempting container breakouts
- and many more, pwning all the things…
This hands-on offensive training teaches how to find these vulnerabilities (even the hard to find ones) and how to exploit them fully (including post-exploitation). If instead you’re more defensive-oriented and interested how to avoid and remediate these vulnerabilities in a defense-in-depth style, the Web Security Bootcamp might be of more interest to you.
What participants will receive
All my trainings can be held in German (native speaker) or English (business fluent).
Participants receive the following along with my training:
- Access to cloud-based training environments (individually spawned for each participant).
- All slides and workshop material as a set of PDFs.
- Lifetime access to GitHub and DockerHub repos with my training environments in order to recap all exercises with a working setup (including freshly added stuff in the future).
- Support via mail for setup and exercise handling afterwards.
- Printed and signed Certificate of Participation listing the training contents.
Interested in your organization’s individual quote? Let’s talk
Standards mapping, if you need a file for an auditor
The curriculum is cut to your stack, your roles, and your risk profile. As a separate deliverable I can map each module actually taught against the frameworks you name: NIS2, DORA, PCI DSS, IT-Grundschutz, or others. The mapping is a claim about the session you booked. It is not an audit opinion and not a certification.
A quiz instead of a feedback form
A satisfaction sheet mostly measures how people felt. A quiz with a pass mark measures whether someone can apply what the modules actually covered.
I write the questions so they follow the curriculum modules. You get a result you can file: who sat it, which modules, pass or fail. I can write the quiz, or you write it and I review it in a fixed number of review rounds.
A 2019 paper on measuring security-awareness programs (Jayatilaka et al., IT Professional 2019) cites a SANS survey of more than 1,500 security professionals in 91 countries: under 7% had a metrics framework for their awareness programs. Kirkpatrick's ladder is reaction, then knowledge, then behavior. A feedback form is reaction. The quiz is knowledge. It does not measure later behavior.
Mapping without a measurement is a curriculum claim with no check. A quiz without a mapping is a score with no stated requirement. Together they are an evidence pack you hold, and a reviewer weighs. They do not make you compliant. What each framework actually asks, and what this pack can supply, is on the regulatory context page.
Different Options
As always in life, there is no one-fits-all solution. So regarding the concrete setup and execution of my trainings and workshops, you have different options and variants to choose from.
Fully customizable training agenda
In case you want certain aspects of your technology stack or specific internal process or tools covered during the training: The training agenda can be customized to your needs, resulting in an individual setup and content.
On-site or Remote? – Choice is yours!
My trainings and workshops can be executed on-site (either directly at your office or at one of my training sites) as well as fully remote for home-office workers. Even hybrid variants are possible, where some remote-only workers can join online, while I execute the training on-site for the majority of the participants. I’ve already conducted numerous online-based variants of my training, even for bigger audience groups.
Either way, participants just need a browser as nothing needs to be installed locally, since my training runs with participant-individual environments in my cloud.
Alternative option: Professional training recording
In case you would like to have a customized version for your company recorded as a set of chapters and lessons for your in-house video-based electronic learning platform: Let’s talk
I can record a customized training session (without participants) and provide you with professionally cut chapters exported as SCORM (useful for import into LMS systems), MPEG, and other formats. This package includes digital training slides and the runnable training environment for local offline training. If you and all participants prefer to record a live training while being held, this is also possible and would produce a video handout of the full course.
That way, several companies have successfully enriched their own internal video-based training offers with my hands-on security workshops imported into their own electronic learning platforms.
