Bug Bounty Course in Assam
Bug bounty hunting means finding real vulnerabilities in live programs on platforms like HackerOne, Bugcrowd and Intigriti, then writing a report good enough to be paid for. This track covers reading scope, recon at scale, the bug classes that are actually rewarded — access control, IDOR, SSRF, chained XSS, business logic — duplicate avoidance and report craft.
Last updated: 6 August 2026
What this track will not do for you
Most hunters earn nothing for their first several months, and many never earn consistently. Duplicates, out-of-scope rejections and informative closures are the normal experience, not bad luck. Payouts are unpredictable and cannot be budgeted against. Treat bounties as a public portfolio that makes you employable, not as an income replacement.
Who this is for
Suited to people who already understand web applications and can self-drive for months without a syllabus pushing them. Not suited to anyone who needs predictable monthly income soon, or who has not yet done a structured web security course — hunting without fundamentals mostly produces duplicates, informative closures and frustration.
Prerequisites: Working knowledge of HTTP, cookies and sessions, and at least a theoretical grasp of the OWASP Top 10. Comfort with Burp Suite proxy and repeater, basic Linux, and one scripting language. You also need your own machine, a stable connection and about ten focused hours a week — casual hunting produces nothing.
The picture in Assam
Tea is Assam’s signature industry, with hundreds of estates across Upper Assam and the Barak Valley, alongside some of India’s oldest oilfields and refineries at Digboi, Guwahati, Bongaigaon and Numaligarh. Guwahati is the commercial gateway for the entire northeast — wholesale trade, hospitals, colleges, logistics and a growing services and IT base. Rice, bamboo, silk and river tourism fill out the rest.
Guwahati is a genuine urban market with fibre, hosting infrastructure and ordinary UPI use. Beyond it, connectivity thins across char areas, tea garden lines and hill districts, and seasonal flooding takes out both roads and networks. Assamese and Bengali typing is common on phones. Traders across the northeast routinely buy from Guwahati wholesalers over WhatsApp rather than any portal.
Sectors hiring for this in Assam
Main centres: Guwahati · Silchar · Dibrugarh · Jorhat · Nagaon · Tinsukia
Bug Bounty Course syllabus
10 weeks · 60 hours (live online, or at the Hisar campus). Every module is hands-on — you work on your own machine from Assam, never against systems you do not own.
01. Programs, scope and the rules you must not break
- VDP vs paid programs, and which to start on
- Reading scope and out-of-scope lines carefully
- Safe harbour, disclosure policy and what breaks it
- Duplicate risk, signal and reputation on platforms
- Testing intensity limits and avoiding denial of service
02. Recon at scale
- Subdomain enumeration with subfinder and amass
- Certificate transparency, DNS records and ASN pivoting
- Probing and screenshotting live hosts with httpx
- Content discovery with ffuf and curated wordlists
- Mining JavaScript files for endpoints, parameters and keys
03. The bug classes that get paid
- IDOR and broken access control across roles and tenants
- SSRF, including cloud metadata endpoints
- Authentication, password reset and 2FA bypass chains
- Full account takeover chains from low-severity parts
- Subdomain takeover and forgotten infrastructure
04. Web depth for hunters
- Stored and DOM XSS in modern JavaScript applications
- CSRF where SameSite does not save the application
- SQL injection in real stacks, and when sqlmap is a bad idea
- File upload, path traversal and object storage misconfiguration
- Race conditions and business logic abuse in payment flows
05. API and mobile attack surface
- REST and GraphQL enumeration and introspection
- Mass assignment and over-permissive object serialisation
- JWT flaws, key confusion and expiry handling
- Rate limit and WAF bypass within program rules
- Extracting hidden endpoints from mobile applications
06. Report craft and income reality
- Minimal reproducible steps a triager can follow
- Impact narrative — why the business should care
- CVSS sanity checks and avoiding severity inflation
- Proof-of-concept screenshots and short videos
- Tracking hours, findings and payouts honestly for a year
Tools used
Where this leads
| Role | Typical band |
|---|---|
| Application Security Analyst | roughly ₹4–9 LPA range |
| Web Penetration Tester | roughly ₹3.5–8 LPA range |
| Security Consultant (VAPT firm) | roughly ₹4–10 LPA range |
| Bug bounty payouts (side income) | extremely variable — many hunters earn nothing for months; individual valid criticals can pay from a few thousand rupees to lakhs, but this is not a salary |
Salary bands are indicative ranges across India and vary widely with skill, city and employer. Public aggregators disagree considerably on specialist roles, so treat any single figure — including these — as a range, not a promise. We do not guarantee placement.
Fees
These are our published course fees. Specialist tracks like the bug bounty course are quoted on the counselling call, because the right scope depends on what you already know — we will not sell you six months of content to teach you something you can cover in six weeks.
| Cyber Security Course | 3–4 months | ₹15,000 |
| Ethical Hacking Course (CEH-aligned) | 6 months | ₹60,000 |
| Digital Forensics | 2 months / 35 hours | ₹10,999 |
| CCNA Networking | 2 months / 45 hours | ₹8,999 |
EMI available. No separate lab, material or certificate charges. Vendor exam vouchers (EC-Council, OffSec, CompTIA, AWS, Microsoft) are bought from the vendor — we do not resell them.
Bug Bounty Course in Assam — FAQs
Is the Bug Bounty Course worth doing from Assam?
▾
What do I need to know before starting?
▾
What will this NOT do for me?
▾
How much can I realistically earn from bug bounty in the first year?
▾
Bug bounty ke liye Burp Suite Pro kharidna zaroori hai?
▾
Do you give me targets or a private program to test on?
▾
Will this course get me a job even if I never earn a bounty?
▾
We have no office in Assam
Cyber Defence has one campus — Red Square Market, Hisar, Haryana 125001 — and teaches Assam live online. We do not list addresses we do not have, we publish no star ratings because we have no verified review corpus, and we do not guarantee placement.
We issue a Cyber Defence certificate with a public verification link. We are not an authorised training centre for EC-Council, OffSec, CompTIA, AWS or Microsoft, and we do not resell their exam vouchers.
Ask whether this track is right for you
Free call with Amit Kumar. If a shorter track or a different starting point suits you better, that is what you will hear.
Call +91 75175 72000