VAPT Course Syllabus
The full module by module syllabus for the Techonquer Certified VAPT Expert program. Published in full, on the page, because a syllabus behind an email gate tells you nothing about whether the course is worth your money.
Three months, live, Friday to Sunday. Taught by Chitra Karanam. New to the subject? Read what is VAPT first.
On this page
- Module 1: Foundations
- Module 2: Reconnaissance and Enumeration
- Module 3: Vulnerability Assessment
- Module 4: Web Application Security
- Module 5: Network Penetration Testing
- Module 6: Active Directory
- Module 7: API Security
- Module 8: AI and LLM Security
- Module 9: Reporting
- Tools covered
- Assessment
- Practise the syllabus free
VAPT Course Syllabus
12 sections, published in full on this page with no email gate.
Module 1: Foundations
- Networking fundamentals: TCP/IP, the three way handshake, DNS, HTTP and HTTPS
- Linux for security: permissions, processes, services, cron, file system layout
- Windows fundamentals: services, registry, user and group model
- Virtual lab setup and safe testing practice
- Scoping, authorisation and rules of engagement
Module 2: Reconnaissance and Enumeration
- Passive reconnaissance and OSINT
- Subdomain enumeration and asset discovery
- Port scanning, service and version detection with Nmap
- Content discovery and directory brute forcing
- Technology fingerprinting
Module 3: Vulnerability Assessment
- Automated scanning and what it does and does not find
- Triage: separating real findings from scanner noise
- CVSS scoring and adjusting for business context
- Building an accurate asset inventory
Module 4: Web Application Security
- Burp Suite in depth: Proxy, Repeater, Intruder, Comparer, extensions
- SQL injection: error based, union based, blind and time based
- Cross site scripting: reflected, stored and DOM based
- Broken access control and insecure direct object references
- Authentication and session management attacks
- Server side request forgery
- File upload vulnerabilities
- Business logic flaws
- The OWASP Top 10, exploited rather than read
Module 5: Network Penetration Testing
- Service exploitation with Metasploit
- Password attacks and credential reuse
- Linux privilege escalation
- Windows privilege escalation
- Pivoting and tunnelling into internal networks
Module 6: Active Directory
- Domain enumeration and attack path mapping with BloodHound
- Kerberoasting and AS-REP roasting
- Credential harvesting
- DCSync and replication abuse
- Delegation and ACL based escalation
- Lateral movement techniques
Module 7: API Security
- REST and GraphQL testing methodology
- Broken object level authorisation
- Broken authentication and JWT attacks
- Excessive data exposure and mass assignment
- Rate limiting and resource consumption
- The OWASP API Security Top 10
Module 8: AI and LLM Security
- Direct and indirect prompt injection
- Model extraction and training data leakage
- Agent and tool abuse
- Retrieval poisoning
- Scoping an AI security assessment by model capability
Module 9: Reporting
A graded module, not an appendix. This is the part almost every program skips and the part clients actually pay for.
- Report structure and the three audiences it serves
- Writing business impact rather than technical description
- Reproduction steps a developer can follow unassisted
- Evidence handling and redaction
- Severity rating with defensible reasoning
- Remediation guidance specific to the client stack
- Retest procedure
Tools covered
| Phase | Tools |
|---|---|
| Reconnaissance | Nmap, Amass, Subfinder, httpx, Gobuster |
| Scanning | Nessus, OpenVAS, Nikto, OWASP ZAP |
| Web | Burp Suite, SQLmap, ffuf |
| Network | Metasploit, CrackMapExec, Hydra |
| Active Directory | BloodHound, Impacket, Rubeus |
| Traffic | Wireshark, tcpdump |
Assessment
- Practical lab assessments at the end of each major module
- One full penetration test with a graded written report
- Seventy percent attendance required for certification
- Certificate carries a unique ID verifiable at certificate.techonquer.org
Practise the syllabus free
Hacklido covers much of modules 2, 4 and 7 at no cost. Work through it before enrolling to confirm the level is right for you.
Verify every module below against your actual delivered curriculum before publishing. A syllabus page that does not match what you teach is a refund request waiting to happen.
Live Programs
Every guide on this site maps to a live, instructor led program.
Related Guides
Other pages worth reading before you decide.
Free VAPT Practice Labs
Browser based, no payment, progression path from zero
GuideOSCP Preparation Syllabus
Windows privesc, buffer overflow, AD and the graded report
GuideSOC Analyst Syllabus
SIEM, log analysis, detection engineering, incident response
GuideCyber Security Courses Online
All live programs, batch format, certification and placement
Frequently Asked Questions
How long is the VAPT course?
Three months of live sessions running Friday, Saturday and Sunday, plus lifetime access to recordings for revision.
Is there a prerequisite for the VAPT syllabus?
No. Module 1 covers networking, Linux and Windows fundamentals from scratch. Prior exposure helps but is not required.
Does the syllabus cover AI security?
Yes. Module 8 covers prompt injection, model extraction, agent abuse and retrieval poisoning, and how to scope an AI assessment by model capability.
Is report writing included?
Yes, as a graded module with a full written report submission. Most programs omit this entirely, and it is the skill that decides seniority.
Which tools will I learn?
Nmap, Burp Suite, Metasploit, SQLmap, BloodHound, Impacket, Wireshark, Nessus, OWASP ZAP and the supporting reconnaissance toolchain.
Can I see the syllabus before paying?
You are reading it. The full module list is published on this page with no email gate.
The syllabus is public for a reason
A syllabus behind an email gate tells you nothing about whether the course is worth your money. Read all nine modules above, then decide.
Enroll in TCVE