Exploit OWASP Top 10 from byte level
IDOR, SSRF, SSTI, deserialisation, OAuth abuse, JWT confusion — written by hand against real lab apps. Not Burp button-clicks.
Training · Pentest · Web · Mobile · Network · AD · Cloud
A pentest programme that trains the five surfaces a working pentester actually gets scoped against. Real exploits, run on lab-isolated targets. The rules of engagement, write-ups, and re-test discipline a paying client expects — not an afterthought bolted on at the end. It finishes on a single 24-hour multi-surface capstone.
The training gap
Most certifications still teach one kind of target — a Linux box, a buffer overflow, a local privilege escalation — and grade you on it in isolation. That was a reasonable model fifteen years ago, when a perimeter was a perimeter. It isn't the job any more. A single engagement letter today will routinely name a web application, its mobile client, the flat network sitting behind it, the Active Directory that authenticates all of it, and the cloud tenant it runs on — and expect you to be credible on every one of them, inside the same scope and the same report.
Three ways that gap shows up
01
You pass on a network track, you walk into a web-app scope. You pass on a web track, the engagement letter names "the corporate AD environment". The mismatch is structural.
02
Cloud-pentest content is barely covered in the canonical certifications. Active-Directory attack chains live almost entirely in community write-ups, not curricula.
03
Scoping, rules of engagement, evidence handling, and writing for the person who actually reads the report. This is half the job, and it is the half most training leaves you to figure out on your first real engagement — usually the hard way.
Five surfaces
Each surface gets a three-week module. Five modules make fifteen weeks; week sixteen is a 24-hour multi-surface capstone — one engagement letter scoped across at least three of the five surfaces at once.
What you do on the programme
IDOR, SSRF, SSTI, deserialisation, OAuth abuse, JWT confusion — written by hand against real lab apps. Not Burp button-clicks.
Static and dynamic analysis on iOS and Android. TLS pinning bypass. Local-storage extraction. Native-library RE. Build the attacker workflow you will actually use on an engagement.
Recon, service enumeration, exploitation, pivoting, tunnelling — without tripping the EDR you would meet in production. Living-off-the-land where it matters.
Kerberoasting. AS-REP roasting. ACL abuse. BloodHound graph reasoning. Privilege escalation from a low-priv user to Domain Admin — and learn what the SOC saw on the way.
AWS IAM-policy abuse paths. Azure managed-identity escapes. GCP service-account chaining. Container and k8s escape. The fastest-changing attack surface and the one you will be scoped against.
Every module ends in a real pentest report — executive summary, technical narrative, risk-ranked findings, retest scope, evidence pack. Reports are what clients actually pay for, and the one skill self-taught testers almost never practise.
Sample week · Active Directory · week 10 of 16
A representative AD week. By Friday, you have walked an AD attack path from a single phished domain user account to full domain dominance — and, more importantly, you can explain every hop to the blue team in the debrief.
Monday
LDAP enumeration. SMB share triage. Service-account discovery. BloodHound ingestion. By end of day: a graph of the domain with the shortest path to DA flagged.
Tuesday
Kerberoasting. AS-REP roasting against pre-auth-disabled accounts. Offline cracking. Practical thresholds — what kind of service account is realistically crackable and what is not.
Wednesday
GenericAll, GenericWrite, WriteDACL, ForceChangePassword — the misconfigurations that make a DA path two hops shorter. Identify, exploit, document.
Thursday
Pass-the-hash, pass-the-ticket, overpass-the-hash. Each technique demonstrated alongside the EDR / SIEM events it generates. You learn the attack and the trace in the same hour.
Friday morning
You receive a fresh, unbriefed AD lab and a single phished user account. You have 90 minutes to reach Domain Admin. Document the path.
Friday afternoon
A blue-team instructor walks the cohort through the telemetry generated during Friday's capstone. Each cohort member must explain which of their actions were noisiest — and why they made them anyway.
Tooling coverage
Burp Suite, ZAP, sqlmap, nuclei, ffuf, gobuster — and writing your own Burp extensions for the cases the off-the-shelf tooling does not cover.
Frida, Objection, MobSF, jadx, apktool, and Ghidra for iOS native libraries, with SSL Kill Switch for pinning — down to the custom Frida scripts you write when a target fights back.
nmap, masscan, Metasploit, Impacket, Responder, Chisel, Ligolo-ng, evilginx for relay attacks.
BloodHound and SharpHound, mimikatz, Rubeus, Certify and Certipy, CrackMapExec, NetExec, and ldapdomaindump — the chain that turns one foothold into a domain.
Pacu for AWS, Stormspotter and MicroBurst for Azure, ScoutSuite and Prowler across providers, cloudfox for IAM paths, and kubeaudit for Kubernetes.
Ghidra, x64dbg, radare2, and IDA Free for static work; gdb and pwndbg at runtime — plus ROP gadget hunting and symbolic execution where it earns its keep.
A report template library — executive summary, technical narrative, risk ranking, retest scope — and the workflow to assemble a clean, defensible evidence pack behind every finding.
Scope-fence discipline, kill-switch protocols, customer-communication cadence, emergency-stop language — drilled in the classroom, not improvised on your first live engagement.
What you walk away with
A 24-hour multi-surface capstone in week 16. Pass to certify; the rubric mirrors the discipline of a real engagement.
Five module reports plus your capstone report — proper format, written for the reader who signs it off, findings ranked the way a client expects. A portfolio you can put in front of an interviewer.
The kill-chain logs you produce feed straight into an AttackWiz BAS scenario (see Products) — so the offensive work you practise here and the continuous validation on the blue side speak one vocabulary.
The Cyberange consulting team, sovereign red-team cells, BFSI internal offensive teams, MSSP testing desks — reached through a referral pipeline, not another job portal.
Drilled against
Practice
"The exploit is the easy part. The engagement letter, the scope-fence, the rules of engagement, the kill switch, and the report are the discipline. Anyone can pop a shell. Far fewer can do it inside a scope and write a report that gets paid for."
Weekend and weekday cohorts. Corporate cohorts on request. Workload is real — budget twelve to fifteen hours per week outside the cohort sessions.