Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Web Reconnaissance & Fuzzing: Shodan, Censys, Wfuzz & Nuclei
New
Rating: 4.5 out of 5(1 rating)
100 students

Web Reconnaissance & Fuzzing: Shodan, Censys, Wfuzz & Nuclei

Learn Web Recon, Subdomain Enumeration, Fuzzing, Wfuzz, WAF Detection & Nuclei for Ethical Hacking
Last updated 10/2026
English

What you'll learn

  • Understand reconnaissance and its role in ethical hacking
  • Learn how Shodan can be used for security reconnaissance
  • Use the Shodan web interface and CLI
  • Understand subdomain enumeration techniques
  • Learn how Certificate Transparency can reveal subdomains
  • Discover subdomains using Shodan, Censys, and VirusTotal
  • Explore Sublist3r and SubBrute for subdomain enumeration
  • Use Wayback URLs for historical web reconnaissance
  • Understand automated approaches to XSS discovery
  • Understand web fuzzing and how the fuzzing process works
  • Learn about wordlists and their importance
  • Identify potential vulnerabilities through fuzzing
  • Explore advanced Wfuzz techniques

Course content

6 sections • 21 lectures • 3h 40m total length
  • Introduction0:21

    Before beginning the course, review the important information about learning and practicing cybersecurity responsibly. This lecture sets expectations for using reconnaissance, enumeration, fuzzing, and vulnerability discovery techniques only in authorized environments.

  • What is Reconnaissance (Basics Explained)3:49

    Learn the fundamentals of reconnaissance and understand its importance in cybersecurity and ethical hacking. This lecture introduces the basic concept of gathering information about a target and explains how reconnaissance fits into a security assessment.

Requirements

  • Basic understanding of computers and the internet is recommended.
  • Familiarity with basic cybersecurity or ethical hacking concepts is helpful but not required.
  • Basic Linux and command-line knowledge is beneficial for the practical demonstrations.
  • Learners should have a computer with internet access for following the hands-on demonstrations.
  • No prior experience with Shodan, Censys, VirusTotal, Wfuzz, or Nuclei is required.
  • The course is suitable for beginners who want to build practical web reconnaissance and security testing skills.

Description

Learn practical web reconnaissance, subdomain enumeration, fuzzing, and vulnerability discovery techniques in this hands-on cybersecurity course.

This course introduces you to the fundamentals of reconnaissance and gradually moves into practical techniques used to discover and analyze publicly accessible web assets in authorized security testing environments.

You will begin by understanding what reconnaissance is and how it fits into the ethical hacking process. You will then explore Shodan, including its graphical interface and command-line usage, to understand how internet-facing information can be identified and analyzed.

The course also covers subdomain enumeration and several techniques for discovering subdomains using Certificate Transparency, Shodan, Censys, and VirusTotal. You will also explore Sublist3r and SubBrute to understand additional approaches to subdomain discovery.

Next, you will learn how WaybackURLs can support reconnaissance and how historical web information can be useful during security assessments. The course then introduces automated XSS discovery and moves into the fundamentals of web fuzzing.

You will learn what fuzzing is, how the fuzzing process works, why wordlists are important, and how fuzzing can help identify potential vulnerabilities. Practical demonstrations with Wfuzz cover both basic and advanced techniques.

The course also introduces techniques for identifying web application firewalls (WAFs) and demonstrates how Nuclei can be used to assist with vulnerability discovery.

By the end of the course, you will have a stronger understanding of practical reconnaissance and web security workflows and the tools commonly used during authorized security assessments.

This course is suitable for cybersecurity students, ethical hacking learners, aspiring penetration testers, bug bounty beginners, and security enthusiasts who want to develop practical reconnaissance and web testing skills.

All techniques should be used responsibly and only against systems you own or have explicit permission to test.

Who this course is for:

  • Beginners who want to learn practical web reconnaissance and enumeration techniques.
  • Cybersecurity and ethical hacking students looking to develop hands-on skills.
  • Aspiring penetration testers who want to understand reconnaissance, subdomain enumeration, and web fuzzing.
  • Bug bounty beginners interested in discovering web assets and potential security vulnerabilities.
  • Security professionals who want to learn tools such as Shodan, Censys, VirusTotal, Wfuzz, and Nuclei.
  • Anyone interested in learning practical reconnaissance and vulnerability discovery techniques in authorized security testing environments.