OffSec OSWA Study Roadmap
Last updated: March 30, 2026
Domain Weight Distribution
Week-by-Week Study Plan
Domain 1: Web app architecture — HTTP protocol, Burp Suite setup, proxy configuration
Domain 1: Application mapping — Technology fingerprinting, endpoint enumeration, API testing
Domain 2: XSS fundamentals — Reflected, stored, DOM-based XSS identification
Domain 2: Advanced XSS — Filter bypass, CSP evasion, payload crafting, cookie theft
Domain 3: SQL injection basics — Detection, UNION-based, error-based extraction
Domain 3: Advanced SQLi — Blind techniques (boolean/time-based), sqlmap, WAF bypass
Domain 4: Authentication attacks — Bypass techniques, brute force, credential stuffing
Domain 4: Session attacks — Fixation, hijacking, JWT attacks, CSRF exploitation
Domain 5: File inclusion — LFI/RFI exploitation, PHP wrappers, log poisoning
Domain 5: Server-side attacks — SSRF, file upload exploits, command injection, XXE
Lab Practice: Full web application assessments, timed exercises, report writing
Final Review: Weak areas, mock exam practice, exam preparation
Free Resources
Related Tools
OffSec OSWA Study Guide
Complete exam objectives and domain breakdown
✅Study Tracker
Track objective completion with progress dashboard
💰Cost Calculator
Total cost breakdown and ROI analysis
🧪Practice Quiz
Test your knowledge with free practice questions
FixTheVuln Store
Get the OffSec OSWA Study Planner
Fillable PDF with 12-week schedule, domain trackers, flashcard templates, and progress tracking.
Get the Study Planner — $5.99