c0c0n 2026

c0c0n is a 19 years old platform that is aimed at providing opportunities to showcase, educate, understand and spread awareness on Information Security, data protection, and privacy...

Venue & Date

c0c0n 3-Day Professional Training

HackTheWeb: Pentest Smarter with AI

Objective

Modern application security fails not because of single bugs, but because data moves in unexpected ways and traditional testing methods can't keep up. This intensive, lab-first course teaches you to map an application's data flow, identify high-value attack points, and execute real exploit chains that automated scans never find while leveraging AI to accelerate every phase of your workflow

Designed for pentesters and security engineers with 1–3 years experience, this program builds both skill and mindset. You'll work through 30+ realistic labs spanning 8+ distinct web and API applications, using mind maps, data-flow diagrams, and Opencode workflows with an Opencode Go subscription to guide discovery. Every module pairs theory with hands-on labs so you practise the exact steps attackers use from reconnaissance to privilege escalation and data exfiltration.

What makes this course different:
  • Data-Flow First: Use mind maps and flow diagrams to locate where sensitive data moves and how it can be abused.
  • AI-Augmented Testing: Learn when and how to use Opencode for payload generation, harness building, wordlist creation, and vulnerability analysis - without over-relying on automation.
  • Mindset Training: Not just checklists - you’ll learn how attackers think and how to structure tests that find logic and design weaknesses.
  • Lab Intensity: 30+ real-world labs across 8+ applications (frontend, API, microservices) - practice chaining vulnerabilities end-to-end.
  • Actionable Outcomes: Walk away with a repeatable methodology, exploit recipes, and reporting guidance that gets developer buy-in.
COURSE HIGHLIGHTS
  • 30+ real-world labs across 8+ applications– exploit vulnerabilities in environments that mirror today’s web and API stacks.
  • Data-flow driven bug hunting– trace how data moves through apps to uncover hidden attack paths scanners miss.
  • AI-integrated pentesting workflow- set up Opencode with an Opencode Go subscription, use it alongside Burp Suite, and apply AI for recon, payload crafting, and vulnerability analysis.
  • Mind maps & attacker’s mindset– build repeatable frameworks and think like an adversary, not a checklist.
  • Exploit chaining & Burp Suite simplified– combine vulnerabilities into high-impact attacks using practical tools and techniques.
  • Actionable takeaways– walk away with a field-tested methodology, reusable mind maps, and skills you can apply immediately.

We will cover topics (not limited to):

  • Mapping the Data Flow– tracing requests, responses, and tokens to spot weak links
  • AI-Assisted Reconnaissance & Subdomain Enumeration
  • Security Misconfiguration & Cloud Storage Hunting
  • Authentication Attacks (JWT, 2FA bypass, password reset flaws)
  • Authorization Testing (IDOR, privilege escalation, SSRF)
  • Advanced Injection Attacks (SQLi, XXE, XSS, template injection, deserialization)
  • Cryptographic Failures (padding oracle, weak encryption)
  • Business Logic & Workflow Exploitation
  • Autonomous Pentesting Agents (opensource tools etc)
  • Automated Reporting with AI

Course Content

Syllabus
Introduction to Web app testing
  • OWASP Top 10 and where it fits in real testing
  • Proxies, requests, responses, cookies, tokens, and sessions
  • How a pentest actually flows: recon -> mapping -> hypothesis -> testing -> validation -> reporting
AI for Pentesting Without the Hype
  • Where AI helps: summarization, pattern finding, payload variation, test planning, reporting
  • Where AI fails: hallucinated bugs, unsafe assumptions, missing context
  • Human-in-the-loop testing model
  • Local vs cloud AI and why this workshop uses Opencode + Opencode Go
Introduction to AI for Pentesting
  • What is AI?
  • Integrate with web pentesting
  • Understanding agents and subagents
  • Understanding skills
  • Understanding AI orchestration or harness
  • Local vs cloud
Setting Up Your AI Infra
  • Opencode + Opencode Go subscription setup
  • First useful pentest prompt
  • Understanding the working architecture
    • Agents and subagents
      • Orchestrator
      • Explorer
      • Enumerator
      • Exploitor
      • Validator
  • Skills, MCPs, and tool access in practical terms
Burp + Opencode Workflow
  • Burp proxy setup
  • Burp MCP introduction
  • Sending crawl/proxy context to Opencode
  • Running a test crawl on the target app
  • Building
    • Sitemap
    • Endpoint inventory
    • Parameter inventory
    • Role map
    • Happy flows
    • Initial attack hypotheses
Information Gathering
  • Search engine discovery and exposed assets
  • Subdomain enumeration
  • Application and framework fingerprinting
  • Tech stack profiling with AI
  • Prioritizing targets using data flow and attack surface
Security Misconfiguration and Deployment Testing
  • Platform misconfiguration checks
  • Cloud storage exposure checks
  • Subdomain takeover checks
  • AI-assisted evidence collection and validation
The AI-Assisted Pentesting Loop
  • What to test first and why
    • Authentication -> authorization -> input handling -> session -> business logic
  • Capture and review proxy logs in Burp
  • Turn proxy logs into a test plan
  • Build sitemap, endpoint inventory, role map, and happy flows
  • Create vulnerability heatmaps using Opencode + Burp logs
  • Generate test hypotheses with Opencode
  • Validate manually
  • Save evidence
Identity and Authentication Testing
  • Account enumeration
  • Default credential hunting
  • Login brute force and lockout behavior
  • Password reset testing
  • JWT analysis and attacks
  • 2FA bypass testing
  • Using AI to identify endpoints, generate test cases, and speed up validation
Authorization Testing
  • Role and privilege mapping
  • Access control test matrix
  • IDOR hunting with AI-assisted endpoint and parameter analysis
  • Privilege escalation testing
  • Directory traversal
  • SSRF
Input Validation/Injection Testing

Note: The whole flow is learning the vulnerability first and then using AI capabilities to hunt for it.

  • SQL injection vulnerabilities
    • Time-based SQL injection
    • Automated hunting for SQL using AI
    • Data exfiltration via blind OOB SQL injection
    • Using AI to find OOB SQL vulnerabilities
  • XML injection vulnerabilities
    • Vanilla XXE attack
    • Data exfiltration via blind XXE attacks using AI
  • Template injection attacks
  • Exploiting file upload functionalities
  • Deserialization attacks
Session Management Testing

Note: The whole flow is learning the vulnerability first and then using AI capabilities to hunt for it.

  • Testing login and logout session functionality
  • Cookie attribute review
  • AI-assisted session weakness analysis
Cryptographic Failures
  • Hunting for cryptographic endpoints using AI and exploiting
    • Padding oracle attacks
    • Weak encryption detection and exploitation using AI
Software Supply Chain Security
  • Identifying vulnerable third-party applications and libraries assisted with AI to attack
    • PHP Symphony
    • Vulnerable third-party libraries
  • Case studies: Log4J / Log4Shell
Business Logic Testing
  • Using happy flow to generate test cases using AI
  • Building hypothesis for AI to test application for business logic flaws
  • Using AI to find bugs in
    • Coupon functionality abuse
    • Payment gateways abuse
Automating Complete Pentest + Human in the Loop Using AI
  • Autonomous pentesting agents
    • Demo: Transilience CommunityTools, etc.
  • AI-powered pentesting assistants
    • Demo of open-source tools
Reporting
  • Reporting pitfalls
  • Evidence quality
  • Writing impact clearly
  • Creating reusable report templates
  • Using AI to draft reports without inventing facts
  • Final lab: turn confirmed findings into a professional report
Training Format Note
  • Two parallel Opencode sessions per demo:
    • Session 1: Assistant (planning, explanation, review)
    • Session 2: Pentesting agent (execution against the target)
Pre-requisite

  • Basic understanding of Pentesting
  • Familiarity with HTTP/HTTPS protocols and web architecture
  • Prior experience with at least one vulnerability class (SQLi, XSS, etc.)

Who Should Attend

  • Pentesters, Red Teamers, and Bug Bounty Hunters (1–3 years’ experience) who want to move beyond surface-level bugs into real exploit chains
  • AppSec Engineers, SOC Analysts, and DevSecOps Professionals seeking attacker-mindset skills to uncover what scanners miss.
  • Developers & Security Researchers eager to understand and defend against real-world exploitation of design flaws, workflows, and misconfigurations.

Participant's Requirements

What Students Should Bring:
To get the most out of the hands-on labs, please come prepared with the following:

  • Administrator (admin) privileges on your laptop - required to install VirtualBox and Burp Suite and Kali Linux image.
  • Laptop and subscription requirements for the labs:
    • CPU - Minimum 4 cores (Intel i5 / AMD Ryzen 5)
    • Active Opencode Go subscription 10$ - required for the AI-assisted exercises throughout the workshop
    • Opencode installed and signed in before the workshop
  • Minimum 32 GB RAM (recommended) - Heavy VMs perform best with more memory.
  • At least 80 GB free disk space - we’ll provide a custom Kali Linux .ova (preloaded with tools) that needs room to import and run.
  • Reliable internet access needed for Opencode, some labs, updates, and downloads.
  • Virtualization support / VirtualBox installed - so you can load the supplied Kali .ova
  • Please purchase a 10$ Subscription of OpenCode Go rate limits will apply. Here: https://opencode.ai/go

We supply the Kali .ova and step-by-step setup instructions. If you hit any setup snags, bring your charger and we’ll help you get everything running before the labs start

What to expect

  • 30% theory and 70% Hands-on
  • Focuses on the Web application Pentesting in modern days.
  • Focuses on a black/grey box pentest, keeping in mind helping bug bounty hunters understand application workflows to find improved Business logic flaws
  • AI as a force multiplier, use Opencode throughout the course for recon, payload generation, WAF bypass, and reporting with a "trust but verify" mindset
  • Designed with Data Flow analysis to understand the endpoints that could have potential vulnerabilities
  • Designed with the state of the art lab with simulated real world applications and more than 30+ exercises to perform
  • Take-home resources leave with mind maps, AI prompt templates, exploit recipes, and a methodology you can use on your next engagement.

Trainer(s)

Dhruv Shah

Founder/ Technical Head
TCP Infosec LLP

Partners

Together with organizations that support collaboration, innovation and a stronger cybersecurity community.