Course Overview

Application security testing helps organizations identify vulnerabilities throughout the software development lifecycle before they can be exploited. Combining static analysis, security-focused debugging, dynamic testing, and penetration testing enables security teams to detect weaknesses earlier, validate them in runtime environments, and improve secure software development practices. This course begins with application security fundamentals, the OWASP Top 10, SDLC security testing, SAST, SpotBugs, CVSS scoring, and manual secure code review. It then covers security-focused debugging, runtime analysis, authentication flow debugging, exploit analysis, DevSecOps integration, and CodeQL. Learners progress to DAST, OWASP ZAP, hybrid testing, PTES, Burp Suite, WebGoat exploitation, authentication and session testing, business logic vulnerabilities, race conditions, and injection attacks. The course concludes with executive security reporting, risk quantification, remediation planning, vulnerability assessments, penetration testing and DevSecOps case studies, ISTQB security testing standards, and career development. You will learn to identify, analyze, exploit, document, and remediate application security vulnerabilities using SAST, debugging, DAST, and penetration testing techniques.

What You Will Learn

  • Implement automated (SAST/DAST) and manual testing techniques to identify web application vulnerabilities and improve security posture.
  • Apply advanced debugging techniques and security-focused analysis to diagnose, isolate, and resolve critical vulnerabilities in application code.
  • Execute penetration testing engagements to simulate real-world attack scenarios and validate application security controls.
  • Produce security reports with technical findings, business impact, and actionable remediation strategies for diverse stakeholders.

Program Curriculum

  • Introduction to Course
  • Module Introduction
  • Intro to Application Security
  • Security Testing in the SDLC
  • OWASP Top 10 Deep Dive
  • SAST Fundamentals and Tool Selection
  • Hands-on SAST with SpotBugs
  • SAST Results Analysis & CVSS Scoring
  • Manual Security Code Review Process
  • OWASP Code Review Tools Workshop
  • Security Audit Standards & Compliance
  • Chapter 1 Quiz

  • Module Introduction
  • Systematic Debugging for Security
  • White-box Debugging Techniques
  • Runtime Security Analysis
  • Authentication Flow Debugging
  • Interactive Debugging in Web Applications
  • Advanced Exploit Analysis
  • DevSecOps Pipeline Integration
  • CodeQL and Advanced Static Analysis
  • Security Test Automation Architecture
  • Chapter 2 Quiz

  • Module Introduction
  • DAST Methodology and Black-box Testing
  • ZAP Professional Workshop
  • Hybrid Testing: Automated and Manual Techniques
  • Penetration Testing Methodology
  • Burp Suite Professional Techniques
  • WebGoat Exploitation Laboratory
  • Authentication & Session Security Testing
  • Business Logic & Race Condition Testing
  • Injection Attack Mastery
  • Chapter 3 Quiz

  • Module Introduction
  • Executive Security Reporting
  • CVSS Scoring and Risk Quantification
  • Remediation Strategy Development
  • Complete Vulnerability Assessment
  • Enterprise Penetration Testing Case Study
  • DevSecOps Transformation Case Study
  • ISTQB Security Testing Standards
  • Career Development in Security Testing
  • Building Security Culture
  • Course Wrap-up Video
  • Chapter 4 Quiz
Load more modules

Instructor

Team

Starweaver delivers 10x better-trained employees and students through scalable, activity-based online learning combined with live human-to-human instruction. With 70–85% course completion rates, we go beyond passive content libraries by focusing on real skill-building and professional competency. Our mission is to transform technologists into world-class experts and business professionals into tech-savvy leaders. Starweaver connects learners with a global network of live instructors and peers, driving higher engagement, satisfaction, and achievement. Our proprietary tools blend guided self-learning with real-time collaboration, ensuring learners stay motivated, capable, and truly job-ready.

Join over 1 Million professionals from the most renowned Companies in the world!

certificate

Fastest Way to Level Up Your Cybersecurity Skills

Invest in your future with flexible subscription plans that give you access to the world’s largest online cybersecurity course library. Whether you're exploring cybersecurity courses for beginners or advancing your expertise,
access in-demand courses, practical labs, and CTF challenges designed to support continuous learning.

Monthly Plans
Annual Plans
Save 20% with our annual plans!

Pro

Build your cybersecurity skills with 900+ bite-sized courses and curated learning paths designed for continuous learning.

$ 69.00
Billed monthly or $599.00 billed annually

What is included

  • 880+ Premium Short Courses
  • 70+ Structured Learning Paths
  • Validation of Completion with all courses and learning paths
  • New Courses added every month
Early Access Offer

Pro +

Develop real-world cybersecurity skills through hands-on labs and CTF challenges designed for practical learning.

$ 79.00
Billed monthly or $699.00 billed annually

Everything in Pro, Plus:

  • 1600+ Hands-on lab exercises with guided instructions
  • 150+ CTF Challenges with detailed walkthroughs
  • New Hands-on Labs and Challenges added every month

Related Courses

1 of 50