Skip to main content

Vulnerability Assessment and Penetration Testing

Code: TBD · Credits: 4 · Hours: — · Type: COURSE

Course-based track capstone. A hands-on VAPT subject that builds on Y2P1's Elective IV option of the same name (if taken), but with stronger emphasis on real-engagement experience: scoping a deliverable, working under time pressure, and producing a report that a stakeholder will actually act on.

Key topics

  • Engagement lifecycle revisited: scoping, ROE, legal framing in Nepal.
  • Recon at scale: subdomain enumeration, certificate transparency, content discovery.
  • Network, web, mobile, cloud, AD pentest tracks — pick one to deep-dive.
  • Modern evasion: TLS-encrypted C2, in-memory execution, AMSI bypass.
  • Reporting workflows: Faraday, Dradis, custom templates.
  • Post-engagement: remediation tracking, retest discipline, knowledge transfer.
  • Building / sustaining a small VAPT team.

Learning outcomes

By the end of this subject, a student should be able to:

  • Lead a one-week internal pentest of a Nepali bank or telco.
  • Discover and report a previously-unknown vulnerability in a real codebase.
  • Produce a board-ready VAPT report with defensible severity ratings.
  • Mentor a junior tester through their first engagement.

Further reading

  • PTES Technical Guidelines, OWASP WSTG, OSSTMM 3.
  • Red Team Field Manual + Blue Team Handbook.
  • HackTheBox / OffSec OSCP / PortSwigger labs.
  • The Hacker Playbook 3.

Chapter notes

Detailed chapter-by-chapter notes for this subject are still being written. The topic outline above mirrors the published syllabus. If you'd like to help draft a chapter, see the contributing guide.

· min read