Cyber Defence
Recon, valid bugs and reports that get triaged — with an honest view of what bounty income looks like. · Live online across Delhi

Bug Bounty Course in Delhi

Bug bounty hunting means finding real vulnerabilities in live programs on platforms like HackerOne, Bugcrowd and Intigriti, then writing a report good enough to be paid for. This track covers reading scope, recon at scale, the bug classes that are actually rewarded — access control, IDOR, SSRF, chained XSS, business logic — duplicate avoidance and report craft.

Last updated: 6 August 2026

What this track will not do for you

Most hunters earn nothing for their first several months, and many never earn consistently. Duplicates, out-of-scope rejections and informative closures are the normal experience, not bad luck. Payouts are unpredictable and cannot be budgeted against. Treat bounties as a public portfolio that makes you employable, not as an income replacement.

Who this is for

Suited to people who already understand web applications and can self-drive for months without a syllabus pushing them. Not suited to anyone who needs predictable monthly income soon, or who has not yet done a structured web security course — hunting without fundamentals mostly produces duplicates, informative closures and frustration.

Prerequisites: Working knowledge of HTTP, cookies and sessions, and at least a theoretical grasp of the OWASP Top 10. Comfort with Burp Suite proxy and repeater, basic Linux, and one scripting language. You also need your own machine, a stable connection and about ten focused hours a week — casual hunting produces nothing.

The picture in Delhi

Delhi is a trading and services economy rather than a manufacturing one. Wholesale concentrates in Chandni Chowk, Sadar Bazar, Gandhi Nagar for garments and Nehru Place for electronics and IT. Karol Bagh handles jewellery, apparel and the automobile trade. Around that sit professional services, hospitals, coaching, government contracting, hospitality and one of the densest startup and agency populations in India.

Connectivity is effectively saturated, card and UPI usage is high, and customers compare on Google, Zomato, Practo, JustDial and Instagram before they ever call. Quick-commerce and food delivery reset expectations for response time across every category. Traditional wholesale markets now run parallel direct-to-consumer and marketplace channels, and many family firms hired their first digital staff only recently.

Sectors hiring for this in Delhi

Wholesale and retail tradeProfessional and financial servicesIT services and startupsHealthcareHospitality and eventsEducation and coaching

Main centres: New Delhi · Dwarka · Rohini · Karol Bagh · Laxmi Nagar · Pitampura

Bug Bounty Course syllabus

10 weeks · 60 hours (live online, or at the Hisar campus). Every module is hands-on — you work on your own machine from Delhi, never against systems you do not own.

01. Programs, scope and the rules you must not break

  • VDP vs paid programs, and which to start on
  • Reading scope and out-of-scope lines carefully
  • Safe harbour, disclosure policy and what breaks it
  • Duplicate risk, signal and reputation on platforms
  • Testing intensity limits and avoiding denial of service

02. Recon at scale

  • Subdomain enumeration with subfinder and amass
  • Certificate transparency, DNS records and ASN pivoting
  • Probing and screenshotting live hosts with httpx
  • Content discovery with ffuf and curated wordlists
  • Mining JavaScript files for endpoints, parameters and keys

03. The bug classes that get paid

  • IDOR and broken access control across roles and tenants
  • SSRF, including cloud metadata endpoints
  • Authentication, password reset and 2FA bypass chains
  • Full account takeover chains from low-severity parts
  • Subdomain takeover and forgotten infrastructure

04. Web depth for hunters

  • Stored and DOM XSS in modern JavaScript applications
  • CSRF where SameSite does not save the application
  • SQL injection in real stacks, and when sqlmap is a bad idea
  • File upload, path traversal and object storage misconfiguration
  • Race conditions and business logic abuse in payment flows

05. API and mobile attack surface

  • REST and GraphQL enumeration and introspection
  • Mass assignment and over-permissive object serialisation
  • JWT flaws, key confusion and expiry handling
  • Rate limit and WAF bypass within program rules
  • Extracting hidden endpoints from mobile applications

06. Report craft and income reality

  • Minimal reproducible steps a triager can follow
  • Impact narrative — why the business should care
  • CVSS sanity checks and avoiding severity inflation
  • Proof-of-concept screenshots and short videos
  • Tracking hours, findings and payouts honestly for a year

Tools used

Burp Suite (Community or Pro)Caidoffufsubfinderamasshttpxnucleijwt_toolPostmangau / Wayback tooling

Where this leads

RoleTypical band
Application Security Analystroughly ₹4–9 LPA range
Web Penetration Testerroughly ₹3.5–8 LPA range
Security Consultant (VAPT firm)roughly ₹4–10 LPA range
Bug bounty payouts (side income)extremely variable — many hunters earn nothing for months; individual valid criticals can pay from a few thousand rupees to lakhs, but this is not a salary

Salary bands are indicative ranges across India and vary widely with skill, city and employer. Public aggregators disagree considerably on specialist roles, so treat any single figure — including these — as a range, not a promise. We do not guarantee placement.

Fees

These are our published course fees. Specialist tracks like the bug bounty course are quoted on the counselling call, because the right scope depends on what you already know — we will not sell you six months of content to teach you something you can cover in six weeks.

Cyber Security Course3–4 months₹15,000
Ethical Hacking Course (CEH-aligned)6 months₹60,000
Digital Forensics2 months / 35 hours₹10,999
CCNA Networking2 months / 45 hours₹8,999

EMI available. No separate lab, material or certificate charges. Vendor exam vouchers (EC-Council, OffSec, CompTIA, AWS, Microsoft) are bought from the vendor — we do not resell them.

Bug Bounty Course in Delhi — FAQs

Is the Bug Bounty Course worth doing from Delhi?

Bug bounty hunting means finding real vulnerabilities in live programs on platforms like HackerOne, Bugcrowd and Intigriti, then writing a report good enough to be paid for. This track covers reading scope, recon at scale, the bug classes that are actually rewarded — access control, IDOR, SSRF, chained XSS, business logic — duplicate avoidance and report craft. Locally, Connectivity is effectively saturated, card and UPI usage is high, and customers compare on Google, Zomato, Practo, JustDial and Instagram before they ever call. The employers who value this here sit in wholesale and retail trade, professional and financial services, it services and startups. Classes are live online, so where in Delhi you live changes nothing about the teaching, the labs or the certificate.

What do I need to know before starting?

Working knowledge of HTTP, cookies and sessions, and at least a theoretical grasp of the OWASP Top 10. Comfort with Burp Suite proxy and repeater, basic Linux, and one scripting language. You also need your own machine, a stable connection and about ten focused hours a week — casual hunting produces nothing.

What will this NOT do for me?

Most hunters earn nothing for their first several months, and many never earn consistently. Duplicates, out-of-scope rejections and informative closures are the normal experience, not bad luck. Payouts are unpredictable and cannot be budgeted against. Treat bounties as a public portfolio that makes you employable, not as an income replacement.

How much can I realistically earn from bug bounty in the first year?

Honestly, possibly zero. A realistic first year is a handful of valid low and medium findings, a lot of duplicates, and enough public reports to strengthen a job application. Anyone promising a monthly bounty income to a beginner is selling you something. We would rather you get an appsec job and hunt on weekends.

Bug bounty ke liye Burp Suite Pro kharidna zaroori hai?

Shuru me bilkul nahi. Community edition me repeater, proxy aur decoder sab hai — bas active scanner nahi hai, aur waise bhi acche bugs manual testing se milte hain. Jab aapki pehli kuch bounties aa jayein, tab Pro ka licence lena samajhdari hai, pehle nahi.

Do you give me targets or a private program to test on?

No, and no legitimate trainer can. Programs choose their own researchers, and testing anything outside a published scope is illegal. What we do give you is lab environments for practice, a repeatable recon methodology, and review of your draft reports before you submit them.

Will this course get me a job even if I never earn a bounty?

That is the intended outcome for most learners. The recon, web depth and report writing here map directly to application security and VAPT interviews. We issue a Cyber Defence certificate with a public verification link, but your write-ups and lab evidence carry more weight with interviewers than any certificate.

We have no office in Delhi

Cyber Defence has one campus — Red Square Market, Hisar, Haryana 125001 — and teaches Delhi live online. We do not list addresses we do not have, we publish no star ratings because we have no verified review corpus, and we do not guarantee placement.

We issue a Cyber Defence certificate with a public verification link. We are not an authorised training centre for EC-Council, OffSec, CompTIA, AWS or Microsoft, and we do not resell their exam vouchers.

Ask whether this track is right for you

Free call with Amit Kumar. If a shorter track or a different starting point suits you better, that is what you will hear.

Call +91 75175 72000