VAPT Course Syllabus

The full module by module syllabus for the Techonquer Certified VAPT Expert program. Published in full, on the page, because a syllabus behind an email gate tells you nothing about whether the course is worth your money.

#VAPT#TCVE#WebPentest#ActiveDirectory#APISecurity
Overview

Three months, live, Friday to Sunday. Taught by Chitra Karanam. New to the subject? Read what is VAPT first.

Full breakdown

VAPT Course Syllabus

12 sections, published in full on this page with no email gate.

01

Module 1: Foundations

  • Networking fundamentals: TCP/IP, the three way handshake, DNS, HTTP and HTTPS
  • Linux for security: permissions, processes, services, cron, file system layout
  • Windows fundamentals: services, registry, user and group model
  • Virtual lab setup and safe testing practice
  • Scoping, authorisation and rules of engagement
02

Module 2: Reconnaissance and Enumeration

  • Passive reconnaissance and OSINT
  • Subdomain enumeration and asset discovery
  • Port scanning, service and version detection with Nmap
  • Content discovery and directory brute forcing
  • Technology fingerprinting
03

Module 3: Vulnerability Assessment

  • Automated scanning and what it does and does not find
  • Triage: separating real findings from scanner noise
  • CVSS scoring and adjusting for business context
  • Building an accurate asset inventory
04

Module 4: Web Application Security

  • Burp Suite in depth: Proxy, Repeater, Intruder, Comparer, extensions
  • SQL injection: error based, union based, blind and time based
  • Cross site scripting: reflected, stored and DOM based
  • Broken access control and insecure direct object references
  • Authentication and session management attacks
  • Server side request forgery
  • File upload vulnerabilities
  • Business logic flaws
  • The OWASP Top 10, exploited rather than read
05

Module 5: Network Penetration Testing

  • Service exploitation with Metasploit
  • Password attacks and credential reuse
  • Linux privilege escalation
  • Windows privilege escalation
  • Pivoting and tunnelling into internal networks
06

Module 6: Active Directory

  • Domain enumeration and attack path mapping with BloodHound
  • Kerberoasting and AS-REP roasting
  • Credential harvesting
  • DCSync and replication abuse
  • Delegation and ACL based escalation
  • Lateral movement techniques
07

Module 7: API Security

  • REST and GraphQL testing methodology
  • Broken object level authorisation
  • Broken authentication and JWT attacks
  • Excessive data exposure and mass assignment
  • Rate limiting and resource consumption
  • The OWASP API Security Top 10
08

Module 8: AI and LLM Security

  • Direct and indirect prompt injection
  • Model extraction and training data leakage
  • Agent and tool abuse
  • Retrieval poisoning
  • Scoping an AI security assessment by model capability
09

Module 9: Reporting

A graded module, not an appendix. This is the part almost every program skips and the part clients actually pay for.

  • Report structure and the three audiences it serves
  • Writing business impact rather than technical description
  • Reproduction steps a developer can follow unassisted
  • Evidence handling and redaction
  • Severity rating with defensible reasoning
  • Remediation guidance specific to the client stack
  • Retest procedure
10

Tools covered

PhaseTools
ReconnaissanceNmap, Amass, Subfinder, httpx, Gobuster
ScanningNessus, OpenVAS, Nikto, OWASP ZAP
WebBurp Suite, SQLmap, ffuf
NetworkMetasploit, CrackMapExec, Hydra
Active DirectoryBloodHound, Impacket, Rubeus
TrafficWireshark, tcpdump
11

Assessment

  • Practical lab assessments at the end of each major module
  • One full penetration test with a graded written report
  • Seventy percent attendance required for certification
  • Certificate carries a unique ID verifiable at certificate.techonquer.org
12

Practise the syllabus free

Hacklido covers much of modules 2, 4 and 7 at no cost. Work through it before enrolling to confirm the level is right for you.

Enrol in the VAPT program

Verify every module below against your actual delivered curriculum before publishing. A syllabus page that does not match what you teach is a refund request waiting to happen.

Frequently Asked Questions

How long is the VAPT course?

Three months of live sessions running Friday, Saturday and Sunday, plus lifetime access to recordings for revision.

Is there a prerequisite for the VAPT syllabus?

No. Module 1 covers networking, Linux and Windows fundamentals from scratch. Prior exposure helps but is not required.

Does the syllabus cover AI security?

Yes. Module 8 covers prompt injection, model extraction, agent abuse and retrieval poisoning, and how to scope an AI assessment by model capability.

Is report writing included?

Yes, as a graded module with a full written report submission. Most programs omit this entirely, and it is the skill that decides seniority.

Which tools will I learn?

Nmap, Burp Suite, Metasploit, SQLmap, BloodHound, Impacket, Wireshark, Nessus, OWASP ZAP and the supporting reconnaissance toolchain.

Can I see the syllabus before paying?

You are reading it. The full module list is published on this page with no email gate.

The syllabus is public for a reason

A syllabus behind an email gate tells you nothing about whether the course is worth your money. Read all nine modules above, then decide.

Enroll in TCVE