Skip to main content

Vulnerability Assessment and Penetration Testing

Code: TBD · Credits: 4 · Hours: 60 · Type: ELECTIVE

VAPT is the practical end of offensive security. This elective covers the full engagement lifecycle — scoping, recon, exploitation, post-exploitation, reporting — with explicit attention to legal and ethical boundaries. Aligns with industry frameworks (PTES, OWASP WSTG, OSSTMM).

Key topics

  • Engagement scoping, rules of engagement, legal authorisation in Nepal.
  • Reconnaissance: passive (OSINT), active (port scan, banner grabbing).
  • Vulnerability scanning: Nessus / OpenVAS / Nuclei, CVSS interpretation, false-positive triage.
  • Exploitation: Metasploit, custom payload development, modern AV/EDR evasion.
  • Post-exploitation: privilege escalation, lateral movement, persistence, data exfil.
  • Web, network, mobile, cloud, wireless, social-engineering pentest tracks.
  • Reporting: executive summary, technical findings, remediation guidance, retest plan.

Learning outcomes

By the end of this subject, a student should be able to:

  • Run a 5-day external pentest end to end and deliver a board-ready report.
  • Translate raw findings into prioritised remediation with cost/impact estimates.
  • Defend ethical and legal limits to a stakeholder mid-engagement.
  • Coordinate a coordinated-disclosure timeline with a vendor.

Further reading

  • PTES Technical Guidelines.
  • OWASP Web Security Testing Guide (WSTG).
  • OSSTMM 3 — Open Source Security Testing Methodology Manual.
  • The Hacker Playbook 3 — Peter Kim.

Chapter notes

Detailed chapter-by-chapter notes for this subject are still being written. The topic outline above mirrors the published syllabus. If you'd like to help draft a chapter, see the contributing guide.

· min read