I built upon web security skills built in Burp Suite Web Academy to practice against a vulnerable web application.
Used docker to host a local version and then used Burp Suite to test the application.