Vulnerability Assessment and Penetration Testing
Code: TBD · Credits: 4 · Hours: 60 · Type: ELECTIVE
VAPT is the practical end of offensive security. This elective covers the full engagement lifecycle — scoping, recon, exploitation, post-exploitation, reporting — with explicit attention to legal and ethical boundaries. Aligns with industry frameworks (PTES, OWASP WSTG, OSSTMM).
Key topics
- Engagement scoping, rules of engagement, legal authorisation in Nepal.
- Reconnaissance: passive (OSINT), active (port scan, banner grabbing).
- Vulnerability scanning: Nessus / OpenVAS / Nuclei, CVSS interpretation, false-positive triage.
- Exploitation: Metasploit, custom payload development, modern AV/EDR evasion.
- Post-exploitation: privilege escalation, lateral movement, persistence, data exfil.
- Web, network, mobile, cloud, wireless, social-engineering pentest tracks.
- Reporting: executive summary, technical findings, remediation guidance, retest plan.
Learning outcomes
By the end of this subject, a student should be able to:
- Run a 5-day external pentest end to end and deliver a board-ready report.
- Translate raw findings into prioritised remediation with cost/impact estimates.
- Defend ethical and legal limits to a stakeholder mid-engagement.
- Coordinate a coordinated-disclosure timeline with a vendor.
Further reading
- PTES Technical Guidelines.
- OWASP Web Security Testing Guide (WSTG).
- OSSTMM 3 — Open Source Security Testing Methodology Manual.
- The Hacker Playbook 3 — Peter Kim.
Chapter notes
Detailed chapter-by-chapter notes for this subject are still being written. The topic outline above mirrors the published syllabus. If you'd like to help draft a chapter, see the contributing guide.
· min read