Introducing the course
Performance Testing & Pentest: Enterprise Standard Process 2026 is a comprehensive course for QA engineers, DevOps Engineers, Security Engineers and Software Architects who want to master performance testing and penetration testing processes according to international standards.
Why is Performance Testing & Pentest needed?
- Performance Testing: Ensure the system meets SLO/SLA, detect bottlenecks before production, and accurately plan capacity
- Penetration Testing: Detect security vulnerabilities against hackers, comply with compliance (PCI DSS, ISO 27001), protect customer data
Course includes
- 30 lessons divided into 6 parts, from foundation to advanced
- Part 1-2: Performance Testing — k6, Gatling, Artillery, Cloud-native testing, Chaos Engineering
- Part 3-4: Penetration Testing — OWASP Top 10, Burp Suite, Metasploit, Cloud/K8s security
- Part 5: Red/Blue/Purple Team, Bug Bounty, Compliance frameworks
- Part 6: Professional reporting, CVSS v4.0, automated reporting, capstone project
Knowledge required
- Basic knowledge of Linux, Networking (TCP/IP, HTTP/HTTPS)
- Understanding of Web Application architecture
- Experience using command line
- Docker and basic knowledge of Cloud (AWS/Azure/GCP) is an advantage
Tools used
| Field | Tools |
|---|---|
| Performance Testing | k6, Gatling, Artillery, Locust |
| Observability | Grafana, Prometheus, Jaeger, OpenTelemetry |
| Chaos Engineering | Litmus Chaos, Chaos Mesh, Gremlin |
| Reconnaissance | Nmap, Amass, Subfinder, Nuclei, Shodan |
| Web App Testing | Burp Suite Pro, OWASP ZAP, SQLMap, ffuf |
| Exploitation | Metasploit, Sliver, BloodHound, Impacket |
| Cloud Security | Prowler, ScoutSuite, CloudFox, Trivy, Falco |
| Reporting | Pwndoc, PlexTrac, Dradis, Grafana Reports |