Web / AppSec roadmap

Secure web apps, APIs, client-side code, and auth flows. Start with PortSwigger Academy, then add CTF-style labs and secure code review.

4 courses22 resourcesPenetration tester

Step-by-step path

  1. HTTP, browsers, auth, and APIs
  2. OWASP Top 10 labs with Burp
  3. Secure code review and report writing
  4. Build a portfolio artifact and publish a short writeup.