VAPT — Vulnerability Assessment & Penetration Testing
Identify, exploit, and report vulnerabilities in systems and applications using offensive security methodologies aligned with industry standards.
Week 01 · 11–12 July 2026
Field ExerciseFoundations of Offensive Security
- Attacker Mindset & Ethics
- The Cyber Kill Chain
- Linux CLI Basics for Security
- Lab Environment Setup (Kali Linux + VirtualBox)
Engagement: set up Kali Linux, document the lab, execute reconnaissance commands, and submit an environment report.
Week 02 · 18–19 July 2026
Field ExerciseReconnaissance & OSINT
- Passive Reconnaissance Techniques
- Active Reconnaissance with Nmap
- OSINT Methodology & Tools
- DNS Enumeration & Subdomain Discovery
Engagement: deliver a structured reconnaissance report with discovered ports, services, versions, and OSINT findings.
Week 03 · 25–26 July 2026
Field ExerciseWeb Application Attacks
- OWASP Top 10 Vulnerabilities
- SQL Injection (manual & automated)
- Cross-Site Scripting (XSS)
- Burp Suite — Intercept, Repeater, Scanner
Engagement: exploit two vulnerabilities on the lab instance and submit a findings report with payloads and impact analysis.
Week 04 · 01–02 August 2026
Field ExerciseExploitation & Post-Exploitation
- Metasploit Framework — Modules, Payloads, Sessions
- Privilege Escalation Techniques
- Establishing Persistence
- Lateral Movement Fundamentals
Engagement: exploit a lab target, escalate privileges, and demonstrate post-exploitation evidence.
Week 05 · 08–09 August 2026
Field ExercisePentest Reporting & Professional Methodology
- Professional Pentest Report Structure
- CVSS Scoring & Risk Rating
- Actionable Remediation Advice
- Client Communication & Executive Summaries
Engagement: deliver a professional pentest report with executive summary, evidence, and remediation advice.
Week 06 · 15–16 August 2026
🎯 Final OperationFull Simulated Penetration Test Engagement
- End-to-End Black-Box VAPT
- Multi-Vector Attack Chains
- Full Professional Report Delivery
- Team Debrief & Evaluation
Final Operation: submit a complete VAPT report for review and scoring by the Rynex Security team.