Progressive difficulty
Each path starts with core concepts and builds toward advanced techniques. Drills increase in complexity as you progress.
Follow a structured curriculum from security fundamentals to focused vulnerability reasoning. Each path combines concepts, guided drills, quizzes, and progress tracking.
Random tutorials and scattered write-ups leave gaps. BountyLabs learning paths organize topics into a logical sequence so you build skills progressively, practise with guided scenarios, and verify understanding before moving forward.
Each path starts with core concepts and builds toward advanced techniques. Drills increase in complexity as you progress.
Apply what you learn in guided simulated-response drills. Submit answers, receive feedback, and review explanations.
See completion percentages, quiz scores, and mastery levels across each path. Identify weak areas and revisit modules as needed.
Choose a path based on your current skill level and goals. Paths connect concepts, quizzes, and relevant guided drills.
Build a solid understanding of how the web works before diving into vulnerabilities. This path covers HTTP request and response mechanics, input handling and encoding, authentication fundamentals, session management, Same-Origin Policy, CORS misconfigurations, and Content Security Policy directives.
Start your bug bounty journey with a clear workflow. Learn how to read program scopes, perform structured reconnaissance, identify common vulnerability patterns, use essential tooling, and write your first report with proper evidence and impact reasoning.
Deep-dive into Cross-Site Scripting across all contexts. Practice reflected, stored, and DOM-based XSS exploitation. Learn CSP bypass techniques, explore mutation XSS in modern frameworks, and understand how to demonstrate real impact beyond alert boxes.
Learn to identify and exploit broken access control vulnerabilities. Understand object ownership models, test authorization on API endpoints, and escalate privileges horizontally and vertically. Practice finding IDORs in REST APIs, file handlers, and admin panels.
Master Server-Side Request Forgery from basic to advanced. Identify request sinks in web applications, exploit cloud metadata endpoints, chain SSRF with other vulnerabilities, and detect blind SSRF using out-of-band techniques. Understand DNS rebinding attacks.
Learn SQL injection from detection to exploitation. Practice authentication bypass, extract data with union-based injection, infer data through blind and time-based techniques, and understand how to write parameterized queries that prevent injection.
Focus on modern API security vulnerabilities. Test for Broken Object-Level Authorization (BOLA), exploit mass assignment flaws, identify rate limiting weaknesses, and explore GraphQL-specific attack surfaces including introspection, batching, and nested query abuse.
A great finding with a poor report gets closed as informational. Learn to collect reproducible evidence, analyze real-world impact, write clear remediation guidance, and follow responsible disclosure timelines. Practice with templates and real-world examples.
Each path is a curated sequence of modules. Complete them in order or skip ahead if you already have the fundamentals covered.
Your completion status syncs across devices. See which modules are done, which are in progress, and where you left off. XP and achievements unlock as you advance through each path.
Paths are tagged with recommended prerequisites. The Web Security Foundations path is the starting point for all other tracks. Intermediate paths assume you are comfortable with HTTP, browser dev tools, and basic recon.
Use each path as a sequence, not a deadline. You can pause, resume, or revisit a guided drill whenever a concept needs more practice.
Whether you are starting from scratch or refining specific skills, there is a path designed for your level.
New to security? Start with Web Security Foundations and the Bug Bounty Beginner Path. You will learn how the web works, how to think like a hunter, and how to write your first report. No prior security experience required.
Already hunting but hitting walls? The XSS, IDOR, SSRF, SQL Injection, and API Security paths go deep into specific vulnerability classes. Fill knowledge gaps, learn advanced techniques, and practice in labs before testing on live programs.
Transitioning into security from another field? The structured curriculum gives you a clear roadmap instead of piecing together random resources. Track your progress, build confidence through labs, and develop a portfolio of completed paths.
Pick a path, complete guided drills, and track progress through structured practice.
Start Training