Ideal for teams that…
Application and infrastructure security — a workshop for technical teams.
Basic programming skills in Java, PHP, or .NET
Basic knowledge of JavaScript
Basic knowledge of SQL
Basic knowledge of IT solution architecture
Basic knowledge of web applications
Basic understanding of operating systems and computer networks
What we actually do
- · Web application security fundamentals
- · Web application architecture
- · OWASP Top 10 (2021)
- · CWE / CVE / CVSS – vulnerability classification and scoring
- · Information gathering techniques
- · Enumeration methods
- · Tools used in reconnaissance
- · Network traffic analysis
- · FTP vs HTTP vs HTTPS
- · GET request modification
- · POST / PUT / DELETE request modification
- · SQL Injection (SQLi) – SQL and NoSQL
- · OS Command Injection (OSi)
- · Unrestricted File Upload (UFU)
- · Log content exposure
- · Open source code leaks
- · Low hanging fruit vulnerabilities
- · Lack of proper error handling
- · TLS / SSL fundamentals
- · HTTP security headers
- · Same-Origin Policy (SOP)
- · Cross-Origin Resource Sharing (CORS)
- · Cross-Site Scripting (XSS)
- · XML External Entity (XXE)
- · XML Denial of Service
- · Cross-Site Request Forgery (CSRF)
- · Local File Inclusion (LFI)
- · Remote File Inclusion (RFI)
- · Directory Traversal (DT)
- · Brute Force (BF)
- · Insecure Direct Object Reference (IDOR)
- · Server-Side Template Injection (SSTI)
- · Server-Side Request Forgery (SSRF)
- · Denial of Service (DoS) and Application DoS
- · Vulnerable and outdated components
- · Authentication and authorization methods
- · Common API security vulnerabilities
- · OWASP API Security Top 10 (2019)
- · Web application fuzzing
- · Mobile application security basics
- · Using proxies in security testing
- · Reverse engineering fundamentals
From brief to retro in 30 days.
Brief & diagnosis
A call with the team lead + a short survey for participants. We define goals, gap and context.
Program customization
We adapt modules, case studies and code examples to your stack. Approval in 5 days.
Workshop
Trainer-led sessions, hands-on, code review. Mentor available between sessions too.
Retro + report
Outcome report for the team and lead. 30 days of consulting included.
Send a brief. We'll reply within 1 day.
After a short brief we'll prepare a program and a quote. No obligations — it's just a starting point.
Thank you!
We'll get back to you within 1 business day.
Other programs for teams
See all →AWS Cloud Security Training
Application and infrastructure security — a workshop for technical teams.
Azure Cloud Security Training
Application and infrastructure security — a workshop for technical teams.
Container Security Management Training
Application and infrastructure security — a workshop for technical teams.