
Before beginning the course, review the important information about learning and practicing cybersecurity responsibly. This lecture sets expectations for using reconnaissance, enumeration, fuzzing, and vulnerability discovery techniques only in authorized environments.
Learn the fundamentals of reconnaissance and understand its importance in cybersecurity and ethical hacking. This lecture introduces the basic concept of gathering information about a target and explains how reconnaissance fits into a security assessment.
Learn what Shodan is and how it can be used as part of a reconnaissance process. Understand the type of internet-facing information that can be discovered and how Shodan can help security professionals analyze an organization's exposed attack surface.
Explore Shodan through its graphical user interface with a practical demonstration. Learn how to navigate the platform and use its available search capabilities to support authorized reconnaissance activities.
Learn how to work with Shodan from the command line. This lecture introduces Shodan CLI usage and demonstrates how command-line tools can make reconnaissance workflows more efficient and repeatable.
Understand the fundamentals of subdomain enumeration and why discovering subdomains is an important part of web reconnaissance. Learn how identifying an organization's subdomains can help map its web-facing assets during an authorized security assessment.
Learn what Certificate Transparency is and how certificate information can assist with discovering domains and subdomains. Understand how publicly available certificate records can provide useful information during reconnaissance.
Learn how Shodan can be used to assist with subdomain discovery. Follow the demonstration to understand how information available through Shodan can contribute to building a broader picture of an organization's web assets.
Explore Censys as a reconnaissance resource for discovering information associated with internet-facing systems and domains. Learn how it can be used as part of an authorized subdomain enumeration workflow.
Learn how VirusTotal can provide useful information for reconnaissance and subdomain discovery. Understand how available domain-related information can help identify additional assets associated with a target.
Explore Sublist3r and SubBrute for subdomain enumeration. Learn how these tools can be incorporated into a reconnaissance workflow to identify additional subdomains during authorized security testing.
Learn how historical web information can support reconnaissance. Explore WaybackURLs and understand how previously accessible URLs and web resources can provide useful context when assessing an authorized target.
Learn about approaches for automating the discovery of potential XSS-related locations during web reconnaissance and security testing. This lecture demonstrates how automation can help identify areas that may require further manual security analysis.
Understand the fundamentals of web fuzzing and why fuzzing is useful during security testing. Learn the basic concept of sending different inputs to an application to identify unexpected behavior and potential security issues.
Explore the fuzzing process step by step. Learn how inputs, targets, responses, and results fit together in a structured fuzzing workflow for authorized web application testing.
Understand the role of wordlists in fuzzing and reconnaissance. Learn why selecting appropriate input values can significantly affect the effectiveness of a fuzzing process and how wordlists support systematic testing.
Learn how fuzzing can be used to identify potentially interesting application behavior and security weaknesses. Understand how fuzzing results can be analyzed to determine areas that require further investigation.
Get hands-on with Wfuzz and learn how it can be used for web fuzzing. Follow the practical demonstration to understand the tool's workflow and how it can support authorized web application security testing.
Build on the fundamentals of Wfuzz by exploring more advanced techniques. Learn how additional Wfuzz capabilities can be incorporated into a structured web fuzzing workflow during authorized security assessments.
Learn the fundamentals of web application firewall detection and understand how WAFs can influence web security testing. Explore techniques for identifying the presence and behavior of a WAF during an authorized assessment.
Learn how Nuclei can assist with vulnerability discovery through a template-based security testing approach. Understand how Nuclei can help identify potential security issues efficiently during authorized assessments and how its results can be used for further investigation.
Learn practical web reconnaissance, subdomain enumeration, fuzzing, and vulnerability discovery techniques in this hands-on cybersecurity course.
This course introduces you to the fundamentals of reconnaissance and gradually moves into practical techniques used to discover and analyze publicly accessible web assets in authorized security testing environments.
You will begin by understanding what reconnaissance is and how it fits into the ethical hacking process. You will then explore Shodan, including its graphical interface and command-line usage, to understand how internet-facing information can be identified and analyzed.
The course also covers subdomain enumeration and several techniques for discovering subdomains using Certificate Transparency, Shodan, Censys, and VirusTotal. You will also explore Sublist3r and SubBrute to understand additional approaches to subdomain discovery.
Next, you will learn how WaybackURLs can support reconnaissance and how historical web information can be useful during security assessments. The course then introduces automated XSS discovery and moves into the fundamentals of web fuzzing.
You will learn what fuzzing is, how the fuzzing process works, why wordlists are important, and how fuzzing can help identify potential vulnerabilities. Practical demonstrations with Wfuzz cover both basic and advanced techniques.
The course also introduces techniques for identifying web application firewalls (WAFs) and demonstrates how Nuclei can be used to assist with vulnerability discovery.
By the end of the course, you will have a stronger understanding of practical reconnaissance and web security workflows and the tools commonly used during authorized security assessments.
This course is suitable for cybersecurity students, ethical hacking learners, aspiring penetration testers, bug bounty beginners, and security enthusiasts who want to develop practical reconnaissance and web testing skills.
All techniques should be used responsibly and only against systems you own or have explicit permission to test.