
OSWA — Foundational Web Application Assessments (WEB-200)
Foundational web pentest credential — black box.
OSWA bridges the gap between CEH-level web knowledge and the elite OSWE. Black-box testing of realistic web apps with all major attack classes plus modern web vulnerabilities.
What is the OSWA certification?
The Offensive Security Web Assessor (OSWA, OffSec) certifies black-box web-application assessment skills — finding and exploiting common web vulnerabilities without source access. Macksofy runs an OSWA exam-prep bootcamp with practical web-testing labs in India.
Outcomes — concrete, measurable.
Every capability you walk away with, mapped to the cybersecurity domains and the career roles they unlock in India + UAE.
- Conduct end-to-end web application assessmentsCapability·Foundational60%
- Exploit OWASP Top 10 plus SSRF, IDOR, JWT issuesOffensive·Practitioner77%
- Pass the 24-hour OSWA examCapability·Specialist94%
- Capability2
- Offensive1
- Web Application Pen-Tester₹10–18 LPA2–4 years
- Application Security Engineer₹15–25 LPA3–5 years
Is OSWA right for you?
- Web pentesters
- Application security engineers
- Bug bounty beginners
What we assume you know
- Basic web app fundamentals
- OWASP Top 10 conceptual familiarity
14 modules. 60-day OffSec lab + 24-hour exam.
Search modules and topics, and switch between Split and Track views to see how every module flows into the next.
Module 01 · Tools for the Web Assessor
- 01Burp Suite Pro proxy & repeater
- 02ffuf, gobuster, sqlmap basics
- 03Browser DevTools workflows
Module 02 · Cross-Site Scripting — Introduction & Discovery
- 01Reflected, stored, DOM-based XSS
- 02Sources & sinks
- 03Auto-discovery techniques
Module 03 · Cross-Site Scripting — Exploitation & Case Study
- 01Cookie theft & session hijacking
- 02Bypassing Content Security Policy
- 03Real-world case study
Module 04 · Cross-Origin Attacks
- 01CORS misconfiguration exploitation
- 02CSRF (Cross-Site Request Forgery)
- 03SameSite cookie nuances
- 04Postmessage abuse
Module 05 · Introduction to SQL
- 01Database fundamentals
- 02Common SQL syntax across MySQL / MSSQL / Postgres
- 03Reading database schema
Module 06 · SQL Injection
- 01In-band, blind, time-based SQLi
- 02Second-order SQLi
- 03sqlmap automation
- 04WAF bypass patterns
Module 07 · Directory Traversal Attacks
- 01Linux & Windows path traversal
- 02URL encoding bypass
- 03Sensitive-file enumeration
Module 08 · XML External Entities (XXE)
- 01In-band & out-of-band XXE
- 02Blind XXE
- 03SSRF via XXE
Module 09 · Server-Side Template Injection (SSTI)
- 01Discovery techniques
- 02Jinja2, Twig, FreeMarker exploitation
- 03Sandboxing escapes
Module 10 · Command Injection
- 01OS command injection vectors
- 02Argument injection
- 03Time-based blind detection
Module 11 · Server-Side Request Forgery (SSRF)
- 01Internal-port discovery
- 02Cloud-metadata service abuse
- 03Filter bypass techniques
Module 12 · Insecure Direct Object Reference (IDOR / BOLA)
- 01IDOR discovery
- 02Mass-assignment patterns
- 03Authorization-logic flaws
Module 13 · Assembling the Pieces (capstone)
- 01End-to-end web assessment
- 02Reporting per OffSec standards
- 0324-hour exam preparation
Macksofy bootcamp · Modern API testing
- 01REST + GraphQL + gRPC fuzzing
- 02JWT alg-confusion attacks
- 03OAuth 2.0 / OIDC flow attacks
The same toolkit our consultants use on real engagements.
Not academic exercises. The tools below are exactly what Macksofy consultants run on paying client engagements every week — so the muscle memory you build in class carries straight into your first job.
What roles open up after you complete this.
| Role | Salary band | Experience |
|---|---|---|
| Web Application Pen-Tester | ₹10–18 LPA | 2–4 years |
| Application Security Engineer | ₹15–25 LPA | 3–5 years |
We don’t promise jobs. We open doors.
Macksofy's placement desk works directly with 80+ hiring partners across India and the UAE. Resume coaching, mock interviews and direct intros included.
- 1:1 resume + LinkedIn rewrite with our hiring desk
- Mock interviews with active practitioners
- Direct intros to BFSI, fintech and Big-4 partners
- UAE placement support (Dubai, Abu Dhabi)
Things students ask before enrolling.

OSWP — Foundational Wireless Network Attacks (PEN-210)
Master Wi-Fi attacks. Earn OSWP.

SOC-200 — Foundational Defensive Operations & Analysis (OSDA)
OffSec's blue-team flagship.

OSCC — CyberCore Security Essentials (SEC-100)
OffSec's entry point into the cybersecurity career stack.
Macksofy delivers this work to the following standards and regulator requirements. Definitions and controls are sourced from the issuing bodies below.
Get a fixed-price proposal in 48 hours.
Tell us about your security need — pentest, audit, training or a wider engagement. A senior consultant will reply within a few business hours.
- CERT-In Empanelled
- EC-Council ATC · CompTIA Authorized
- Thousands of professionals trained
- India + UAE engagements
