Skip to content
Macksofy Technologies
OSWA — Foundational Web Application Assessments (WEB-200)
OffSec
OSWA / WEB-200
Hands-on certification bootcamp
OSWA / WEB-200Intermediate

OSWA — Foundational Web Application Assessments (WEB-200)

Foundational web pentest credential — black box.

OSWA bridges the gap between CEH-level web knowledge and the elite OSWE. Black-box testing of realistic web apps with all major attack classes plus modern web vulnerabilities.

60-day OffSec lab + 24-hour exam 14 modules Hybrid · Macksofy mentorship + OffSec course
In short

What is the OSWA certification?

The Offensive Security Web Assessor (OSWA, OffSec) certifies black-box web-application assessment skills — finding and exploiting common web vulnerabilities without source access. Macksofy runs an OSWA exam-prep bootcamp with practical web-testing labs in India.

What you’ll be able to do

Outcomes — concrete, measurable.

Every capability you walk away with, mapped to the cybersecurity domains and the career roles they unlock in India + UAE.

Capability Profile
  • Conduct end-to-end web application assessments
    Capability·Foundational
    60%
  • Exploit OWASP Top 10 plus SSRF, IDOR, JWT issues
    Offensive·Practitioner
    77%
  • Pass the 24-hour OSWA exam
    Capability·Specialist
    94%
Capability Mix
  • Capability
    2
  • Offensive
    1
Roles & salary bands
  • Web Application Pen-Tester
    ₹10–18 LPA
    2–4 years
  • Application Security Engineer
    ₹15–25 LPA
    3–5 years
Who it’s for

Is OSWA right for you?

  • Web pentesters
  • Application security engineers
  • Bug bounty beginners
Before you start

What we assume you know

  • Basic web app fundamentals
  • OWASP Top 10 conceptual familiarity
Curriculum

14 modules. 60-day OffSec lab + 24-hour exam.

Search modules and topics, and switch between Split and Track views to see how every module flows into the next.

Modules
14
Topics
44
Module 01 / 14 · OSWA

Module 01 · Tools for the Web Assessor

  • 01
    Burp Suite Pro proxy & repeater
  • 02
    ffuf, gobuster, sqlmap basics
  • 03
    Browser DevTools workflows
Tools you’ll operate

The same toolkit our consultants use on real engagements.

Not academic exercises. The tools below are exactly what Macksofy consultants run on paying client engagements every week — so the muscle memory you build in class carries straight into your first job.

Tooling stack
Burp Suite ProffufsqlmapJWT_toolPostman
Career outcomes

What roles open up after you complete this.

RoleSalary bandExperience
Web Application Pen-Tester₹10–18 LPA2–4 years
Application Security Engineer₹15–25 LPA3–5 years
Placement support

We don’t promise jobs. We open doors.

Macksofy's placement desk works directly with 80+ hiring partners across India and the UAE. Resume coaching, mock interviews and direct intros included.

  • 1:1 resume + LinkedIn rewrite with our hiring desk
  • Mock interviews with active practitioners
  • Direct intros to BFSI, fintech and Big-4 partners
  • UAE placement support (Dubai, Abu Dhabi)
FAQ

Things students ask before enrolling.

Standard OffSec WEB-200 + 60-day lab + exam bundle is ~₹1,70,000. Through Macksofy the same official bundle — course, 60-day lab and exam voucher — is ₹1,45,000 (15% off, EMI available). The Macksofy API & modern-web bootcamp and mentor support is a separate add-on, quoted on top.
Highly recommended. OSWA builds the black-box methodology and OWASP Top 10+ confidence you'll need for OSWE's source-code work. Skipping straight to OSWE leaves most candidates struggling with case-study triage.
OSWA is the OffSec-stamped, hands-on web pentest credential — strongest brand for hiring. eWPT (eLearnSecurity) is solid foundational alternative. BSCP (PortSwigger) is exam-only methodology check. OSWA wins on hiring recognition; many AppSec analysts pair OSWA with BSCP.
Yes — OSWA is a real practical credential that opens junior / mid web pentest doors at consultancies and product security teams. Pair with bug-bounty practice for fastest career acceleration.
24-hour proctored hands-on exam against multiple realistic web applications, followed by a professional report. You must compromise the targets and document findings to OffSec's reporting standards. Macksofy's bootcamp includes one full mock 24-hour exam.
Web Application Pen-Tester (₹10–18 LPA at 2–4 years), Application Security Analyst (₹8–14 LPA at 1–3 years), Bug-Bounty Hunter (variable, top earners ₹50 LPA+). UAE bands add 30–40% premium. Common employers: PwC, EY, Deloitte web teams, Indian consultancies, BFSI AppSec.
Yes — we add a dedicated module on REST + GraphQL + gRPC fuzzing, JWT alg-confusion attacks and OAuth 2.0 / OIDC flow attacks beyond the official OSWA syllabus.
Most learners progress to OSWE (WEB-300) for source-code review or to OSCP+ for breadth into network pentest. Bug-bounty specialisation is also a strong path — OSWA + active HackerOne / Bugcrowd profile lands product-security interviews fast.
Yes — live online OSWA cohorts pan-India plus corporate AppSec batches on-site in Delhi, Bengaluru, Hyderabad, Pune, Chennai and Dubai.
References & standards

Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.

Talk to us

Get a fixed-price proposal in 48 hours.

Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.

CERT-In Empanelled
Information Security Auditor · India
  • CERT-In Empanelled
  • EC-Council ATC · CompTIA Authorized
  • Thousands of professionals trained
  • India + UAE engagements