PortSwigger → AYSEC Mapping

The free PortSwigger Web Security Academy mapped to AppSec modules.

PortSwigger Web Security Academy — Mapping to AYSEC Modules

PortSwigger publishes a 100% free, world-class web AppSec curriculum at https://portswigger.net/web-security. Every AYSEC AppSec module should reference these labs.


Why This Matters


All Topic Areas Mapped

AYSEC-106 Module 04 — Authentication

PortSwigger Auth labs:

AYSEC-106 Module 04 — JWT Attacks

AYSEC-106 Module 05 — Access Control / IDOR

AYSEC-106 Module 06 — SQL Injection

Apprentice tier:

Practitioner tier:

Expert tier:

AYSEC-106 Module 07 — XSS

Apprentice tier (~10 labs):

Practitioner tier (~15 labs):

Expert tier:

AYSEC-106 Module 07 — CSRF

AYSEC-106 Module 07 — CORS

AYSEC-106 Module 08 — SSRF

AYSEC-106 Module 08 — XXE

AYSEC-106 Module 08 — File Upload

AYSEC-106 Module 08 — Deserialization

AYSEC-106 Module 09 — SSTI

AYSEC-106 Module 09 — Race Conditions

AYSEC-106 Module 09 — Business Logic

AYSEC-106 Module 10 — APIs

AYSEC-106 Module 11 — HTTP Request Smuggling

AYSEC-106 Module 11 — Web Cache Poisoning


How to Use

For every AYSEC-106 module, after the "Hands-On" task, list:

Promote PortSwigger as the mandatory practice — it's free and best-in-class.


Total Coverage

PortSwigger publishes ~250 labs across 30+ topics. They map to:

Completing all Practitioner labs is the path to the Burp Suite Certified Practitioner exam.


Total Time Estimate

For a determined student:

Around 530 hours of free, top-quality lab work. Track this in your AYSEC progress.