Structured training

Bug Bounty Learning Paths

Follow a structured curriculum from security fundamentals to focused vulnerability reasoning. Each path combines concepts, guided drills, quizzes, and progress tracking.

A structured approach to security learning

Random tutorials and scattered write-ups leave gaps. BountyLabs learning paths organize topics into a logical sequence so you build skills progressively, practise with guided scenarios, and verify understanding before moving forward.

Progressive difficulty

Each path starts with core concepts and builds toward advanced techniques. Drills increase in complexity as you progress.

Hands-on practice

Apply what you learn in guided simulated-response drills. Submit answers, receive feedback, and review explanations.

Track your progress

See completion percentages, quiz scores, and mastery levels across each path. Identify weak areas and revisit modules as needed.

Featured learning paths

Choose a path based on your current skill level and goals. Paths connect concepts, quizzes, and relevant guided drills.

W

1. Web Security Foundations

Build a solid understanding of how the web works before diving into vulnerabilities. This path covers HTTP request and response mechanics, input handling and encoding, authentication fundamentals, session management, Same-Origin Policy, CORS misconfigurations, and Content Security Policy directives.

  • HTTP methods, headers, status codes, and cookies
  • Input encoding, decoding, and sanitization patterns
  • Authentication flows and session token handling
  • CORS policies and common misconfiguration patterns
  • Content Security Policy directives and bypass awareness
Beginner Core concepts Guided practice
B

2. Bug Bounty Beginner Path

Start your bug bounty journey with a clear workflow. Learn how to read program scopes, perform structured reconnaissance, identify common vulnerability patterns, use essential tooling, and write your first report with proper evidence and impact reasoning.

  • Understanding scope, rules of engagement, and safe harbor
  • Subdomain enumeration, directory brute-forcing, and tech fingerprinting
  • Identifying low-hanging vulnerabilities in target applications
  • Essential tooling: Burp Suite, browser dev tools, and CLI utilities
  • First report workflow: finding, reproducing, documenting, and submitting
Beginner Hunter workflow Guided practice
X

3. XSS Path

Deep-dive into Cross-Site Scripting across all contexts. Practice reflected, stored, and DOM-based XSS exploitation. Learn CSP bypass techniques, explore mutation XSS in modern frameworks, and understand how to demonstrate real impact beyond alert boxes.

  • Reflected XSS in URL parameters, headers, and form inputs
  • Stored XSS in comments, profiles, and user-generated content
  • DOM-based XSS via sinks like innerHTML, eval, and document.write
  • CSP bypass techniques including dangling markup and JSONP
  • Mutation XSS in HTML parsers and sanitization libraries
Intermediate Browser security Guided practice
I

4. IDOR and Access Control

Learn to identify and exploit broken access control vulnerabilities. Understand object ownership models, test authorization on API endpoints, and escalate privileges horizontally and vertically. Practice finding IDORs in REST APIs, file handlers, and admin panels.

  • Object ownership and reference patterns in web applications
  • Horizontal privilege escalation across user accounts
  • Vertical privilege escalation from user to admin roles
  • Authorization bypass via parameter tampering and path traversal
  • Testing access control on API endpoints and resource URLs
Intermediate Authorization Guided practice
S

5. SSRF Path

Master Server-Side Request Forgery from basic to advanced. Identify request sinks in web applications, exploit cloud metadata endpoints, chain SSRF with other vulnerabilities, and detect blind SSRF using out-of-band techniques. Understand DNS rebinding attacks.

  • Identifying request sinks: URL fetchers, image processors, webhooks
  • Cloud metadata exploitation on AWS, GCP, and Azure
  • DNS rebinding to bypass IP-based restrictions
  • Blind SSRF detection using out-of-band callbacks
  • SSRF chaining with file read, RCE, and internal service discovery
Intermediate Server-side Guided practice
Q

6. SQL Injection Path

Learn SQL injection from detection to exploitation. Practice authentication bypass, extract data with union-based injection, infer data through blind and time-based techniques, and understand how to write parameterized queries that prevent injection.

  • Detection via error-based, boolean-based, and time-based indicators
  • Authentication bypass through login forms and API endpoints
  • Union-based injection for data extraction
  • Blind SQL injection with conditional responses and timing
  • Writing parameterized queries and ORM best practices
Intermediate Injection Guided practice
A

7. API Security Path

Focus on modern API security vulnerabilities. Test for Broken Object-Level Authorization (BOLA), exploit mass assignment flaws, identify rate limiting weaknesses, and explore GraphQL-specific attack surfaces including introspection, batching, and nested query abuse.

  • Broken Object-Level Authorization (BOLA) in REST APIs
  • Mass assignment via hidden parameters and schema manipulation
  • Rate limiting bypass and resource exhaustion techniques
  • GraphQL introspection, batching attacks, and nested query abuse
  • API authentication flaws including JWT and OAuth misconfigurations
Intermediate REST & GraphQL Guided practice
R

8. Report Writing Path

A great finding with a poor report gets closed as informational. Learn to collect reproducible evidence, analyze real-world impact, write clear remediation guidance, and follow responsible disclosure timelines. Practice with templates and real-world examples.

  • Evidence collection: screenshots, HTTP requests, and reproduction steps
  • Impact analysis with business context and attack scenarios
  • Remediation guidance tailored to the vulnerability class
  • Responsible disclosure timelines and communication etiquette
  • Report templates for different vulnerability types and programs
All levels Communication Templates

How learning paths work

Each path is a curated sequence of modules. Complete them in order or skip ahead if you already have the fundamentals covered.

Progress tracking

Your completion status syncs across devices. See which modules are done, which are in progress, and where you left off. XP and achievements unlock as you advance through each path.

Prerequisites

Paths are tagged with recommended prerequisites. The Web Security Foundations path is the starting point for all other tracks. Intermediate paths assume you are comfortable with HTTP, browser dev tools, and basic recon.

Estimated time

Use each path as a sequence, not a deadline. You can pause, resume, or revisit a guided drill whenever a concept needs more practice.

Who these paths are for

Whether you are starting from scratch or refining specific skills, there is a path designed for your level.

Complete beginners

New to security? Start with Web Security Foundations and the Bug Bounty Beginner Path. You will learn how the web works, how to think like a hunter, and how to write your first report. No prior security experience required.

Intermediate hunters

Already hunting but hitting walls? The XSS, IDOR, SSRF, SQL Injection, and API Security paths go deep into specific vulnerability classes. Fill knowledge gaps, learn advanced techniques, and practice in labs before testing on live programs.

Career changers

Transitioning into security from another field? The structured curriculum gives you a clear roadmap instead of piecing together random resources. Track your progress, build confidence through labs, and develop a portfolio of completed paths.

Start a learning path today.

Pick a path, complete guided drills, and track progress through structured practice.

Start Training