Training
Workshops for developers, administrators and DevOps: classic or with an AI focus, with roughly half of the time spent on hands-on exercises.
Workshops take one to three days, and participants spend roughly half of that time on exercises. We put the agenda together with you, and the training takes place at your premises or in Bonn.
Which training is right for you?
Classic
Practical Web Security (classic)
For developers, administrators and DevOps who want to learn web security from the ground up, go deeper or bring their knowledge up to date.
Basic and advanced web security topics
An update on current attacks and the OWASP Top 10 (2025)
Every vulnerability worked through by hand
AI focus
Practical Web Security (AI focus)
For teams who mainly develop with AI agents or want to move to AI-assisted development.
AI as the interface to Burp Suite and other tools
Finding and fixing vulnerabilities with the agent
Securing your own AI development setup, from the sandbox to skills and MCP servers
Practical Web Security (classic)
Each vulnerability is explained, exploited by hand and fixed, using an intercepting proxy and the browser. The topics come from trainings we have already held for customers, and we put your agenda together from these building blocks.
Basics
Brief: HTTP basics and attack surface
The OWASP Top 10 (2025) and the OWASP Web Security Testing Guide (WSTG) as a common thread
Information gathering and information leakage
Security testing basics and tools: Burp Suite, browser developer tools, the WSTG as a checklist
Attacks on web applications
Broken access control: missing permission checks, IDOR, CSRF, SSRF
Path traversal and file inclusion (LFI/RFI)
Injection: cross-site scripting, SQL injection, code and command injection, CRLF and HTTP header injection
Logic errors and clickjacking
Denial of service
Defence
Session management
Password protection and authentication
Cryptographic functions and random numbers: common mistakes in practice
Error handling, logging and alerting
Hardening of configuration and server environment
Software supply chain and integrity: dependencies, build and CI/CD pipeline, deserialisation
In the development process
Insecure design
Threat modelling and the Secure Development Lifecycle (SDL) (three-day trainings only)
An overview of AI and security: AI features as a new attack surface, prompt injection, the OWASP Top 10 for LLM Applications
Practical Web Security (AI focus)
Every vulnerability is covered with theory and explanation, in as much depth as the group needs. The focus is on using AI as the interface to the tools, finding and fixing vulnerabilities with it, and securing your own agentic development setup. Every exercise follows the same loop: reconnaissance, finding, verifying, fixing and testing again. The AI assistant speeds up each step, and a person makes the decisions.
Basics and tools
Web security from scratch: HTTP, attack surface, the OWASP Top 10 (2025) and the WSTG
Agentic coding for beginners: how an AI agent calls tools, and what MCP is
AI as the interface to the tools: Burp Suite through its MCP server, scanners and command line tools through the agent
Using AI agents safely: scope, prompt injection from the target, confidential data, destructive actions
Understanding and finding vulnerabilities
Information gathering and information leakage
Injection: cross-site scripting, SQL, command and template injection, CRLF and HTTP header injection
Broken access control in web applications and APIs: IDOR/BOLA, missing function-level checks (BFLA), SSRF, path traversal, CSRF, clickjacking
Authentication, session management and logic errors
From black box to white box: source code analysis with AI and Semgrep, tracing findings back to their cause in the code
Further topics: denial of service, hardening, software supply chain, the OWASP Top 10 for LLM and agentic applications
Threat modelling and SDL (three-day trainings only)
Fixing with AI
Verify findings, review suggested fixes critically, write a regression test and test again
Case studies from cryptography and random numbers, error handling and logging, and authentication
Building your own tools: skills, subagents and slash commands for penetration testing and code analysis
Wrap-up: a small engagement in pairs, from finding to fix to report
Securing your own AI development setup
Threat model and real incidents: why the coding agent is a target
Sandbox and isolation: the agent in a sandbox, VM or devcontainer, with network access only to approved hosts
Credentials with minimal rights instead of long-lived tokens
Permissions, hooks and managed settings, and where their limits are
Vetting skills, plugins, MCP servers and cloned repositories before use
Writes only after approval, detection with telemetry and canary tokens
Requirements
Participants bring their own laptop. The practical examples run on a VM, either in the cloud or locally.
Participants receive all examples and training material in digital form.
Participants should be able to read code in a common programming language. Experience with the command line helps but is not required.
AI focus Experience with AI agents helps but is not required.
AI focus Your own AI subscription, such as Claude Max, is an advantage. Otherwise we provide suitable AI access during the training.
Format and location
- 1 to 3 days
-
usually two or three
- About 50% hands-on
-
theory and exercises alternate
- Ready-made lab
-
our own examples, DVWA and similar vulnerable applications
- Up to 8 people
-
the ideal group size, more by arrangement
- Location
-
in-house at your office, or in Bonn at the Taktsoft Campus
There is no fixed timetable: order and depth follow the group's questions. Theory comes in short blocks right before the exercise that needs it. Tools and AI agent are only ever pointed at the lab targets.
The training takes place at your premises or in Bonn at the Taktsoft Campus. All talks and trainings can be held in English or German.