WEB-200 · OSWA · Teams and individuals
WEB-200: what the course covers - and what we add.
WEB-200 is OffSec's black-box web course leading to OSWA: injection classes, authentication and session flaws, access control, SSRF, deserialisation and chaining multiple weaknesses.
Who it is for
People entering application security, developers with a security remit, and testers who want a structured route into web attacks.
Course content (official scope)
- →Injection and template attacks
- →Authentication, session, access control
- →SSRF and deserialisation
- →Chaining into impactful paths
- →Evidence handling in reports
Course content, labs and the OSWA exam are provided by OffSec. The official course description always takes precedence. This page reviewed: 2026-08-07.
What Exploit Labs adds
- +Exercises against your own technology stack
- +A bridge into OWASP ASVS and WSTG test routines
For security teams
Multiple people, role paths, reporting and procurement run through OffSec Learn Enterprise.
See Learn EnterpriseFor individual practitioners
Individual licence, access duration, exam attempts and preparation - start here.
See individual licences