OffSec Authorized Training

OffSec Foundational Web Application Assessments with Kali Linux WEB-200 (OSWA) Training

WEB-200 teaches students how to discover and exploit common web vulnerabilities, and how to exfiltrate sensitive data from target web applications. Students will obtain a wide variety of skill sets and competencies for web app assessments. Students who complete the course and pass the associated exam earn the Offensive Security Web Assessor (OSWA) certification, demonstrating their ability to leverage modern web exploitation techniques on modern applications. A certified OSWA candidate is prepared to take on the Advanced Web Attacks and Exploitation (WEB-300) course.

LevelIntermediate
Duration5 Days
Experience4 years: Kali Linux
Average Salary$153,000
LabsYes

Offensive Security OSWA (WEB-200)

Course Overview
  • Tools for the Web Assessor
  • Cross Site Scripting (XSS) Introduction and Discovery
  • Cross Site Scripting (XSS) Exploitation and Case Study
  • Cross Origin Attacks
  • Introduction to SQL
  • SQL Injection (SQLi) and Case Study
  • Directory Traversal
  • XML External Entity (XXE) Processing
  • Server Side Template Injection (SSTI)
  • More Topics added monthly*

*The OffSec Training Library will be updated continuously with new Topics on an approximately monthly cadence. Not every course or content area will receive an update every month, but some course or content area will receive an update approximately monthly.

Course Outline
  • Module 1: Secrets of Success with WEB200
  • Module 2: Tools
  • Module 3: Cross-Site Scripting Introduction and Discovery
  • Module 4: Cross-Site Scripting Exploitation and Case Study
  • Module 5: Cross-Origin Attacks Same-
    • Origin Policy
  • Module 6: SQL Injection
  • Module 7: Directory Traversal Attacks
  • Module 8: XML External Entities
  • Module 9: Server-side Template Injection - Discovery and Exploitation
  • Module 10: Command Injection
  • Module 11: Server-side Request Forgery
  • Module 12: Insecure Direct Object Referencing
  • Module 13: Assembling the Pieces: Web Application Assessment Breakdown
Intended Audience
  • Students will obtain a wide variety of skill sets and competencies for Web App Assessments
  • Students will learn foundational Black Box enumeration and exploitation techniques
  • Students will leverage modern web exploitation techniques on modern applications

Job roles like: Web Penetration Testers, Pentesters, Web Application Developers, Application Security Analysts, Application Security Architects, and SOC Analysts and other blue team members

Anyone interested in expanding their understanding of Web Application Attacks, and/or Infra Pentesters looking to broaden their skill sets and Web App expertise

Prerequisites

All students are required to have:

  • All prerequisites for WEB-200 can be found within the Offsec
  • Fundamentals Program, included with a Learn One or
  • Learn Unlimited subscription

Prerequisite Topics include:

  • PEN-100: Web Application Basics
  • PEN-100: Linux 1 & 2
  • PEN-100: Networking Basics
Features
  • Course Materials
  • Active Student Forums
  • Access to Home Lab Setup

Also available in On-Demand formats below:

  • Learn One Package – $2,749
  • 1 year of access to the course of your choice
  • 2 exam attempts during your subscription
  • 365 days of lab access
  • Access to all 100-level content for 1 year
  • 1 year of unlimited access to all fundamental content and OffSec curated Learning Paths
  • PEN-103 + 1 KLCP exam attempt
  • PEN-210 + 1 OSWP exam attempt
  • Proving Grounds Practice labs
  • Learn More
  • OR
  • Learn Unlimited Package – $6,099
  • 1 year of access to unlimited course & content
  • Unlimited exam attempts during your subscription
  • 365 days of lab access
  • 1 year of unlimited access to all fundamental content and OffSec curated Learning Paths
  • Access to all 100-level content for 1 year
  • PEN-103 + unlimited KLCP exam attempts
  • PEN-210 + unlimited OSWP exam attempts
  • Proving Grounds Practice labs
  • 3 downloads of course material
  • Learn More
Follow-On Courses

PROUD OFFSEC PARTNERSHIP

We are proud to be an OffSec Learning, Government, and Channel Partner. We pride

ourselves on providing award winning boot camps and direct mentoring in our classrooms,

Online Live or at your location. The only immersive Authorized Instructor-Led OffSec

training available - join us today!

Related training topics

Get approved to attend

Justify your training

Use this sample request letter — copy it into an email to your manager and personalize the bracketed details to make the case for the time and budget.

Sample training request letter

Subject: Request for Penetration Testing & Red Teaming training from Applied Technology Academy

[Decision Maker Name],

I'm writing to request time and budget approval to complete Applied Technology Academy's course, OffSec Foundational Web Application Assessments with Kali Linux WEB-200 (OSWA) Training. The information below outlines how this training benefits our organization, the tasks I'll be able to perform after completing it, and relevant cost and funding details.

Course Description
WEB-200 teaches students how to discover and exploit common web vulnerabilities, and how to exfiltrate sensitive data from target web applications. Students will obtain a wide variety of skill sets and competencies for web app assessments. Students who complete the course and pass the associated exam earn the Offensive Security Web Assessor (OSWA) certification, demonstrating their ability to leverage modern web exploitation techniques on modern applications. A certified OSWA candidate is prepared to take on the Advanced Web Attacks and Exploitation (WEB-300) course. Applied Technology Academy is an award-winning, SBA-certified woman-owned training provider (est. 2008) whose instructors are active practitioners; the course is hands-on with virtual labs and a learn-by-doing methodology.

Course Objectives
Once I've completed the course, I'll have hands-on, job-ready skills in penetration testing & red teaming that I can apply immediately to our work.

Expected Organizational Benefits
After completing this course, I will be better equipped to apply these skills directly to our projects, reduce our reliance on outside expertise, strengthen our team's capabilities, and share what I learn with colleagues.

Expected Cost & Funding
Course fee: [request an itemized quote at the link below]. Applied Technology Academy supports multiple funding paths that may reduce or cover this cost: GSA MAS purchasing and government purchase orders, military credentialing funding (Army CA, AF COOL, CG COOL), VA GI Bill and VR&E, ATA Flexible Spending, and student financing. Private team cohorts are available if colleagues should attend with me.

Conclusion
This training provides practical, hands-on experience I can apply immediately to strengthen our work in penetration testing & red teaming. Additional course information is available at https://appliedtechnologyacademy.com/offsec-training/offsec-web-200-training/.

Thank you for your consideration,
[Your Name]

Design training around your team, not the other way around.

Talk to a training advisor about private cohorts, funding paths and program management.

Request a Quote Call 800.674.3550