Vulnerability Assessment and Penetration Testing
Code: TBD · Credits: 4 · Hours: — · Type: COURSE
Course-based track capstone. A hands-on VAPT subject that builds on Y2P1's Elective IV option of the same name (if taken), but with stronger emphasis on real-engagement experience: scoping a deliverable, working under time pressure, and producing a report that a stakeholder will actually act on.
Key topics
- Engagement lifecycle revisited: scoping, ROE, legal framing in Nepal.
- Recon at scale: subdomain enumeration, certificate transparency, content discovery.
- Network, web, mobile, cloud, AD pentest tracks — pick one to deep-dive.
- Modern evasion: TLS-encrypted C2, in-memory execution, AMSI bypass.
- Reporting workflows: Faraday, Dradis, custom templates.
- Post-engagement: remediation tracking, retest discipline, knowledge transfer.
- Building / sustaining a small VAPT team.
Learning outcomes
By the end of this subject, a student should be able to:
- Lead a one-week internal pentest of a Nepali bank or telco.
- Discover and report a previously-unknown vulnerability in a real codebase.
- Produce a board-ready VAPT report with defensible severity ratings.
- Mentor a junior tester through their first engagement.
Further reading
- PTES Technical Guidelines, OWASP WSTG, OSSTMM 3.
- Red Team Field Manual + Blue Team Handbook.
- HackTheBox / OffSec OSCP / PortSwigger labs.
- The Hacker Playbook 3.
Chapter notes
Detailed chapter-by-chapter notes for this subject are still being written. The topic outline above mirrors the published syllabus. If you'd like to help draft a chapter, see the contributing guide.
· min read