Services

Training

Workshops for developers, administrators and DevOps: classic or with an AI focus, with roughly half of the time spent on hands-on exercises.

Workshops take one to three days, and participants spend roughly half of that time on exercises. We put the agenda together with you, and the training takes place at your premises or in Bonn.

Which training is right for you?

Classic

Practical Web Security (classic)

For developers, administrators and DevOps who want to learn web security from the ground up, go deeper or bring their knowledge up to date.

  • Basic and advanced web security topics

  • An update on current attacks and the OWASP Top 10 (2025)

  • Every vulnerability worked through by hand

To the agenda

AI focus

Practical Web Security (AI focus)

For teams who mainly develop with AI agents or want to move to AI-assisted development.

  • AI as the interface to Burp Suite and other tools

  • Finding and fixing vulnerabilities with the agent

  • Securing your own AI development setup, from the sandbox to skills and MCP servers

To the agenda

Practical Web Security (classic)

Each vulnerability is explained, exploited by hand and fixed, using an intercepting proxy and the browser. The topics come from trainings we have already held for customers, and we put your agenda together from these building blocks.

Basics

  • Brief: HTTP basics and attack surface

  • The OWASP Top 10 (2025) and the OWASP Web Security Testing Guide (WSTG) as a common thread

  • Information gathering and information leakage

  • Security testing basics and tools: Burp Suite, browser developer tools, the WSTG as a checklist

Attacks on web applications

  • Broken access control: missing permission checks, IDOR, CSRF, SSRF

  • Path traversal and file inclusion (LFI/RFI)

  • Injection: cross-site scripting, SQL injection, code and command injection, CRLF and HTTP header injection

  • Logic errors and clickjacking

  • Denial of service

Defence

  • Session management

  • Password protection and authentication

  • Cryptographic functions and random numbers: common mistakes in practice

  • Error handling, logging and alerting

  • Hardening of configuration and server environment

  • Software supply chain and integrity: dependencies, build and CI/CD pipeline, deserialisation

In the development process

  • Insecure design

  • Threat modelling and the Secure Development Lifecycle (SDL) (three-day trainings only)

  • An overview of AI and security: AI features as a new attack surface, prompt injection, the OWASP Top 10 for LLM Applications

Practical Web Security (AI focus)

Every vulnerability is covered with theory and explanation, in as much depth as the group needs. The focus is on using AI as the interface to the tools, finding and fixing vulnerabilities with it, and securing your own agentic development setup. Every exercise follows the same loop: reconnaissance, finding, verifying, fixing and testing again. The AI assistant speeds up each step, and a person makes the decisions.

Basics and tools

  • Web security from scratch: HTTP, attack surface, the OWASP Top 10 (2025) and the WSTG

  • Agentic coding for beginners: how an AI agent calls tools, and what MCP is

  • AI as the interface to the tools: Burp Suite through its MCP server, scanners and command line tools through the agent

  • Using AI agents safely: scope, prompt injection from the target, confidential data, destructive actions

Understanding and finding vulnerabilities

  • Information gathering and information leakage

  • Injection: cross-site scripting, SQL, command and template injection, CRLF and HTTP header injection

  • Broken access control in web applications and APIs: IDOR/BOLA, missing function-level checks (BFLA), SSRF, path traversal, CSRF, clickjacking

  • Authentication, session management and logic errors

  • From black box to white box: source code analysis with AI and Semgrep, tracing findings back to their cause in the code

  • Further topics: denial of service, hardening, software supply chain, the OWASP Top 10 for LLM and agentic applications

  • Threat modelling and SDL (three-day trainings only)

Fixing with AI

  • Verify findings, review suggested fixes critically, write a regression test and test again

  • Case studies from cryptography and random numbers, error handling and logging, and authentication

  • Building your own tools: skills, subagents and slash commands for penetration testing and code analysis

  • Wrap-up: a small engagement in pairs, from finding to fix to report

Securing your own AI development setup

  • Threat model and real incidents: why the coding agent is a target

  • Sandbox and isolation: the agent in a sandbox, VM or devcontainer, with network access only to approved hosts

  • Credentials with minimal rights instead of long-lived tokens

  • Permissions, hooks and managed settings, and where their limits are

  • Vetting skills, plugins, MCP servers and cloned repositories before use

  • Writes only after approval, detection with telemetry and canary tokens

Requirements

  • Participants bring their own laptop. The practical examples run on a VM, either in the cloud or locally.

  • Participants receive all examples and training material in digital form.

  • Participants should be able to read code in a common programming language. Experience with the command line helps but is not required.

  • AI focus Experience with AI agents helps but is not required.

  • AI focus Your own AI subscription, such as Claude Max, is an advantage. Otherwise we provide suitable AI access during the training.

Format and location

1 to 3 days

usually two or three

About 50% hands-on

theory and exercises alternate

Ready-made lab

our own examples, DVWA and similar vulnerable applications

Up to 8 people

the ideal group size, more by arrangement

Location

in-house at your office, or in Bonn at the Taktsoft Campus

There is no fixed timetable: order and depth follow the group's questions. Theory comes in short blocks right before the exercise that needs it. Tools and AI agent are only ever pointed at the lab targets.

The training takes place at your premises or in Bonn at the Taktsoft Campus. All talks and trainings can be held in English or German.

Let us talk about your application.

Reach us by e-mail, phone or the contact form. PGP-encrypted on request.