Skip to content

VAPT

A working methodology for vulnerability assessment and penetration testing: scope, phases, reporting, and a running list of study resources.

· Updated Jul 12, 2026


On this page

Vulnerability Assessment and Penetration Testing

How to handle Network VAPT

  1. Scope
    1. List of Network Devices Routers, Laptop, Desktop, Firewall, IDS, Access point, IPS
    2. Network Architecture Diagram
    3. Type of Testing:
      1. VA (with/without Credentials)
      2. VAPT
  2. Kick-off Meeting with client
    1. Number of locations
    2. Number of VLAN's
    3. List of Public IP
    4. List of Internal IP
    5. VPN Access/Remote Desktop
      1. I5, 8g, SSD, Good Internet
  3. Phase 1 Testing
    1. Testing Schedule
    2. Nessus, Nmap, Wireshark/Metasploit(PT)
    3. Report writing
  4. Patching
  5. Report Discussion
  6. Retesting

Finish

https://tryhackme.com/hacktivities https://academy.tcm-sec.com/courses

Reverse Engineering

API Security

Resources

Books

  • Hacking APIs

Broken Object Level Authorization

also known as IDOR

Types of Access Control

  • Role based

  • Discretionary(Cloud Share)

  • Attribute based(Rare in webapps)

  • Mess with cookies

  • Access something without login

  • Access other users resources

  • Admin function as regular user