Web // Application Attack Surface

Application Security

Application trust boundaries, workflow abuse and exploit classes that keep surfacing during real assessments.

13 notesselected referencestechnical reference map

Domain overview

Application work is about state, trust, identity and business actions. This domain stays focused on reproducible proof, useful remediation and the patterns that repeatedly produce serious findings.

Related certification context

These paths map closely to application-security work covered on this page.

Selected public references

Topic index

brief

Introduction

Application work is about trust boundaries, state handling and the business logic that decides what a caller is allowed to do. The domain is built around reproducible validation, useful remediation language and references that stay relevant during a live assessment.

3 focus points0 links
brief

OWASP Top 10 And Web Application Pentesting Theory

Application work is about trust boundaries, state handling and the business logic that decides what a caller is allowed to do. The domain is built around reproducible validation, useful remediation language and references that stay relevant during a live assessment.

6 focus points4 links
brief

Web Application Pentesting Practice

Application work is about trust boundaries, state handling and the business logic that decides what a caller is allowed to do. The domain is built around reproducible validation, useful remediation language and references that stay relevant during a live assessment.

10 focus points7 links
brief

Browser Exploitation Framework (Beef)

Application work is about trust boundaries, state handling and the business logic that decides what a caller is allowed to do. The domain is built around reproducible validation, useful remediation language and references that stay relevant during a live assessment.

1 focus point0 links
brief

Burp Suite Professional

Application work is about trust boundaries, state handling and the business logic that decides what a caller is allowed to do. The domain is built around reproducible validation, useful remediation language and references that stay relevant during a live assessment.

10 focus points6 links
brief

Web Application Firewall Bypass

Application work is about trust boundaries, state handling and the business logic that decides what a caller is allowed to do. The domain is built around reproducible validation, useful remediation language and references that stay relevant during a live assessment.

10 focus points32 links
brief

Web Vulnerability Assessment (Burp Enterprise)

Application work is about trust boundaries, state handling and the business logic that decides what a caller is allowed to do. The domain is built around reproducible validation, useful remediation language and references that stay relevant during a live assessment.

2 focus points1 link
brief

Web Vulnerability Assessment With Acunetix

Application work is about trust boundaries, state handling and the business logic that decides what a caller is allowed to do. The domain is built around reproducible validation, useful remediation language and references that stay relevant during a live assessment.

2 focus points1 link
brief

Web Vulnerability Assessment With Netsparker

Application work is about trust boundaries, state handling and the business logic that decides what a caller is allowed to do. The domain is built around reproducible validation, useful remediation language and references that stay relevant during a live assessment.

2 focus points1 link
brief

Web Vulnerability Assessment With Intruder.Io

Application work is about trust boundaries, state handling and the business logic that decides what a caller is allowed to do. The domain is built around reproducible validation, useful remediation language and references that stay relevant during a live assessment.

2 focus points1 link
brief

Web Vulnerability Assessment With Rapid7 Appspider

Application work is about trust boundaries, state handling and the business logic that decides what a caller is allowed to do. The domain is built around reproducible validation, useful remediation language and references that stay relevant during a live assessment.

1 focus point0 links
brief

Quick Reference

Application work is about trust boundaries, state handling and the business logic that decides what a caller is allowed to do. The domain is built around reproducible validation, useful remediation language and references that stay relevant during a live assessment.

10 focus points0 links
brief

Ewpt - Web Pentesting Certification

Application work is about trust boundaries, state handling and the business logic that decides what a caller is allowed to do. The domain is built around reproducible validation, useful remediation language and references that stay relevant during a live assessment.

2 focus points1 link