Advanced continuation track for those with a cyber foundation
Offensive Cyber Course - Web Application Penetration Testing
Explore. Verify. Document.
An advanced Web PT track that delves into Web application penetration testing: from understanding the application structure and client-server communication, through systematic work according to OWASP Top 10 and practice in PortSwigger labs, to a concluding project and writing a professional PT report.
150 academic hours
22 lessons
Designed for those with a prior foundation
Practice with:HTML · CSS · JavaScript · HTTP · OWASP Top 10 · PortSwigger · Web PT
Designed for graduates of HPI's basic cyber course or those with equivalent knowledge in networks, Linux, operating systems, and cyber fundamentals.
Hands-On practice in secure lab environments
Web PT methodology and OWASP Top 10
Concluding project and professional PT report
Get the syllabus and check eligibility
Leave your details and we'll get back to you for a short call to check if your prior knowledge is suitable for the advanced track.
Training scope
150 academic hours
Number of lessons
22
Professional modules
6
Why study this track
Your next step in the offensive cyber world
This track is designed to transform a prior cyber foundation into focused capabilities in Web application security testing, through systematic practice, work in a legal environment, and professional documentation of findings.
Focused specialization in Web application security
Delve into the structure of Web applications, client-server communication, authentication and authorization mechanisms, and points where vulnerabilities may arise. The focus is on a systematic understanding of the application and the security impact of each component.
Practical work in secure labs
Practice controlled testing processes in PortSwigger Web Security Academy labs and in environments defined for learning. Work is done within a Scope and authorization, with an emphasis on legal, accurate, and responsible testing.
Web PT Project and Professional Report
Perform an end-to-end capstone project in a controlled lab environment: define a testing process, collect Evidence, validate findings, and write a PT report including severity, impact, Remediation recommendations, and an Executive Summary.
Foundation for development in Web PT and AppSec
Build a practical foundation for further development in directions such as Junior Web Penetration Tester, Application Security / AppSec, and continued specialization in penetration testing. Actual integration depends on knowledge, practice, experience, and employer requirements.
Before You Decide
An advanced track requires the right starting point. Let's truly check it
We have compiled the important questions about prior knowledge, practice, legality, and the track's outcomes, so you can understand if this is the right professional stage for you.
01
Why does the track require prior knowledge?
This is a continuation track focused on Web application security, and therefore does not start from the fundamentals of computers, networks, and operating systems.
To dedicate learning time to Web PT, the track assumes a basic familiarity with networks, Linux, operating systems, cyber fundamentals, and technical thinking. There is no requirement to be HPI graduates, but equivalent knowledge that allows understanding communication processes, permissions, and system behavior is required.
The suitability call is designed to check the starting point and confirm that the track progresses at a pace suitable for you. If you don't yet have such a foundation, you can start with HPI's cyber course for beginners.
There is no need to be software developers, but a willingness to understand how client-side code affects application behavior and its security is required.
The track includes HTML and CSS fundamentals as well as JavaScript in the context of Web Security. The goal is not to turn participants into Front-End developers, but to enable them to read page structure, understand forms, DOM, user input, and client-side logic.
Prior development knowledge can help, but it is not listed as an admission requirement. What is required is a technical basis, learning ability, and willingness to practice security-related concepts and code.
03
Can I start without prior Web PT experience?
Yes, as long as you have the required cyber and infrastructure foundation. Prior experience in application penetration testing is not a condition.
The track was built to transition those with a cyber foundation into the world of Web PT. Learning begins with Web fundamentals, continues to architecture, HTTP, and databases, and only then progresses to testing methodology, OWASP Top 10, and labs.
There is no need to arrive with prior experience in PortSwigger or in performing Web tests, but consistent practice, patience, and the ability to connect knowledge from the course with new technical processes are required.
04
What do you actually practice?
You practice how to systematically analyze a Web application, work with Proxy tools, identify risks, validate findings, and document them.
During the track, you will practice in controlled environments analyzing Requests and Responses, working with Headers, Cookies, and Sessions, examining Authentication and Access Control, and identifying risks related to Injection, client-side, Business Logic, Misconfiguration, and Insecure Design.
The practice includes PortSwigger Web Security Academy labs, collecting Evidence, carefully validating findings, rating severity, examining business impact, and formulating Remediation recommendations.
05
Where and how are tests performed legally?
Tests are performed only in lab environments or on systems for which explicit authorization and a defined Scope exist.
Penetration testing does not grant permission to test any site or system. During the track, work is done in secure labs and scenarios defined for learning. Any professional testing outside the lab requires explicit approval, clear work boundaries, and adherence to the authorization terms.
Do not test third-party systems, public services, or assets not owned by you without authorization. Offensive thinking is taught here to improve security, not to perform unauthorized activity.
06
What does the Web PT Capstone Project look like?
The project connects the testing phases into an end-to-end process in a controlled lab environment.
In the capstone project, you will implement a testing methodology on a Web application in a lab, document the workflow, collect Evidence, and present verified findings.
For each finding, a description, severity, potential impact, evidence, and remediation recommendations will be defined. The deliverable will include a structured PT report, an Executive Summary for managerial audiences, technical documentation, and a concluding presentation.
07
What facts and deliverables can be checked in advance?
The track includes 150 academic hours, 22 lessons, six modules, labs, a capstone project, and a professional PT report.
The program structure is documented and clear: six modules spread across 22 lessons, totaling 150 academic hours. The content progresses from Web and JavaScript fundamentals to HTTP, databases, testing tools, OWASP Top 10, PortSwigger labs, and a capstone project.
Upon completion, a certificate of completion from HPI College is awarded. Combined with the knowledge from the basic course, the program provides focused preparation for content relevant to CEH. The exam and certification itself are provided by the external certifying body and are not automatically included in the price.
Details regarding the cohort, price, days, hours, and format will be provided by a study advisor.
08
Who is the track suitable for, and who is it less suitable for?
The track is suitable for individuals with a technical foundation who are willing to practice and delve deeper. It is less suitable for those looking for shortcuts, a certificate only, or unauthorized activity.
The track may be suitable for you if:
You have completed a basic cyber course or acquired equivalent knowledge.
You have a foundation in networks, Linux, operating systems, and cybersecurity fundamentals.
You want to specialize in Web application security.
You are willing to practice between sessions and tackle technical material.
You understand that testing is performed only with authorization and in authorized environments.
You are looking for practical skills and not just a certificate.
It's worth pausing and checking suitability if:
You still lack a foundation in cyber and infrastructure.
You are not interested in consistent practice.
You expect job guarantees, salary, or exam passage.
The goal is to test systems without authorization.
Want to check if your prior knowledge is suitable for the track?
Tell us about your background in cyber, networks, and Linux, and what professional direction you want to advance in. We will get back to you for a short call, review the track requirements, and help you understand if this is the right starting point.
No obligation · Short call · Personal response from HPI team
Practical Deliverables
What You Will Build During the Track
Instead of general promises, the track focuses on practice and deliverables that demonstrate how you approach Web testing in a structured manner.
Documented Practice in PortSwigger Labs
Working on selected labs from the PortSwigger Web Security Academy, including analyzing application behavior, documenting testing phases, and understanding the impact of common Web vulnerabilities.
End-to-End Web PT Project
A capstone test of a Web application in a controlled environment: defining a workflow, examining application components, verifying findings, and systematically collecting Evidence.
Professional PT Report and Portfolio
A structured report including findings, severity, impact, evidence, Remediation recommendations, an Executive Summary, and technical documentation. This deliverable can serve as a basis for showcasing acquired skills, with no guarantee of job placement.
Want to check if your prior knowledge suits the program?
Tell us about your background in cyber, networks, and Linux, and which professional direction you want to pursue. We'll get back to you for a short chat, review the program requirements, and help you understand if this is the right starting point.
No obligation · Short call · Personal response from the HPI team
Curriculum
Six professional modules, 22 lessons, and 150 academic hours – from Web fundamentals to a Penetration Testing project and professional PT report.
What to take from the course next
Professional Development Directions
Junior Web Penetration Tester.
Application Security / AppSec.
Further specialization in Penetration Testing.
Entry-level Security Research, depending on knowledge and employer requirements.
These are possible development directions, not a guarantee of employment. Actual integration depends on knowledge, practice, prior experience, and employer requirements.
Tools, Methodologies, and Deliverables
HTML, CSS, and JavaScript.
HTTP and Client–Server architecture.
Cookies, Sessions, and Authentication.
SQL and databases in a security context.
Proxy tools for Web testing.
OWASP Top 10.
PortSwigger Web Security Academy.
Evidence collection and finding verification.
Severity rating and business impact.
Remediation recommendations.
Executive Summary.
Web PT project and professional report.
Certificate and Professional Advancement
HPI Certificate and Focused Preparation for CEH Content
Completion Certificate for 150 Academic Hours
Upon completion of the program and meeting its requirements, you will receive a completion certificate from HPI College for 150 academic hours, including study, practical exercises, and guided homework.
Focused preparation for CEH-relevant content
Combining knowledge from the basic cybersecurity course – Networks, Linux, Operating Systems, Cyber Fundamentals, Python, SOC, and Infrastructure Penetration Testing – the advanced program delves into content from Web PT relevant for CEH preparation.
The CEH exam and certification itself are provided by the external certifying body and subject to its requirements. There is no guarantee of passing the exam. The cost of the exam, registration, and exam voucher are not automatically included in the course price, unless explicitly stated otherwise in writing for the specific cohort.
FAQs – Web PT Offensive Cyber Course
Important answers regarding admission requirements, curriculum, practice, project, and professional progression.
Web Application Penetration Testing is a proactive and controlled testing process for Web applications and websites aimed at identifying vulnerabilities, verifying their impact, and recommending how to fix them. The test examines, among other things, the communication between the browser and the server, authentication and authorization mechanisms, input handling, business logic, and security configurations. Professional testing is performed only in an authorized environment and within a defined Scope.
The course is suitable for graduates of HPI's basic cybersecurity course or those with equivalent knowledge in networks, Linux, operating systems, cyber fundamentals, and technical thinking. It is intended for those who want to delve into Web application penetration testing and develop towards directions such as Web PT or AppSec.
Completion of HPI's basic cybersecurity course or equivalent knowledge in networks, Linux, operating systems, and cyber fundamentals is required. Basic technical ability, willingness to work with English terms, and dedication to practice are also required. Suitability is checked during a conversation with the HPI team before registration.
No. There is no requirement to have prior experience in Web application penetration testing. The program teaches the fundamentals of Web, architecture, and testing methodology before moving on to advanced practice. However, it assumes an existing foundation in cyber and infrastructure.
There is no requirement to master them at a professional development level. The track includes HTML and CSS fundamentals, as well as JavaScript in the context of Web Security. Prior knowledge may make it easier, but the goal is to teach the structure and logic needed to understand and test Web applications – not to train Front-End developers.
The 22 lessons are divided into six modules: Web PT fundamentals; HTML and CSS; JavaScript in a security context; Web architecture, HTTP, SQL and databases; Testing tools, methodology, OWASP Top 10 and PortSwigger labs; and a culminating Web PT project with professional report writing.
Yes. The track includes hands-on practice in secure lab environments, working with Proxy tools for Web testing, analyzing Requests and Responses, PortSwigger labs, evidence collection, finding validation, and a capstone project. The actual extent of practice also depends on your investment and practice between sessions.
PortSwigger Web Security Academy is a learning environment that includes study materials and dedicated labs for Web application security. Within the track, selected labs are used to practice topics such as Authentication, Access Control, Injection, client-side risks, and business logic in a dedicated environment.
Practice in the course is conducted in controlled lab environments or on systems explicitly configured for learning purposes. No testing should be performed on a real system without explicit permission and an approved Scope. The course does not grant permission to test third-party websites, services, or systems.
The project includes an end-to-end Web testing process in a controlled lab environment: planning the workflow, examining the application, implementing OWASP methodology, collecting Evidence, validating findings, ranking severity, assessing impact, and formulating Remediation recommendations.
A professional PT report includes a clear description of the testing Scope, validated findings, severity level, potential impact, Evidence, and Remediation recommendations. Additionally, it includes an Executive Summary for a managerial audience and technical documentation allowing teams to understand the problem and advance remediation.
Infrastructure PT typically focuses on networks, servers, services, operating systems, and infrastructure configurations. Web PT focuses on the application layer: HTTP, authentication and authorization mechanisms, input handling, Sessions, business logic, and the communication between the client, server, and database. Knowledge in both areas is complementary.
The track provides a foundation for further development into paths such as Junior Web Penetration Tester, Application Security / AppSec, continued specialization in penetration testing, and entry-level Security Research. Suitability for and acceptance into a role depend on knowledge, practice, experience, and employer requirements.
Yes. Upon completion of the track and meeting its requirements, a certificate of completion is awarded by HPI College for 150 academic hours. This is an HPI completion certificate and does not replace external certifications such as CEH.
Combined with the knowledge from the basic cyber course, the advanced track provides focused preparation for content relevant to the CEH certification, including controlled offensive thinking, Web testing, methodology, vulnerabilities, and documentation of findings. The exam and certification themselves are administered by the external certifying body.
Not automatically. The exam, registration, exam cost, and exam voucher are not considered included unless explicitly stated in writing in the price quote or registration agreement for the specific cohort. Please confirm details with a study advisor before registering.
No. The course provides training, practice, and professional deliverables, but it does not guarantee placement, a specific salary, or acceptance into a role. Professional success depends on the level of knowledge, amount of practice, individual performance, prior experience, and employer requirements.
For further reading
Continue learning in the Knowledge Hub
Three supplementary guides on Web PT methodology, OWASP, and writing professional reports.