Skip to content

Burp Suite Certified (BSCP)

The BSCP (Burp Suite Certified Practitioner) by PortSwigger certifies practical web hacking skill using Burp Suite, based on the excellent (and free) Web Security Academy. It’s affordable, very practical, and one of the best ways to demonstrate real web competence.

- a PRACTICAL web hacking certification by PortSwigger (the Burp creators)
- it relies on the Web Security Academy (free labs) as study material
- a hands-on exam: exploit real web applications using Burp Suite
- affordable and highly valued for reflecting current, real web skill
- the whole web spectrum of the Academy: SQLi, XSS, SSRF, auth, access control, deserialization,
SSTI, prototype pollution, CORS, etc. (maps to this wiki's whole Web area)
- advanced Burp use (Repeater, Intruder, extensions) -> see tool-burp
- chaining vulns to achieve the goal (stealing a specific user's data)
- practical (4h): two applications; in each, escalate from anonymous user to admin
and exfiltrate a target user's data (pattern: foothold -> escalate -> exfiltrate)
- timed and demanding on time management; requires fluency with Burp
- you must find AND exploit live, not answer a test
- complete the PortSwigger Web Security Academy (it's FREE and it's the syllabus)
- master Burp thoroughly (tool-burp) and the Academy's exploitation patterns
- practice the "mystery labs" (no category hint) -> they simulate the exam
- review this wiki's whole Web area
- demonstrates real PRACTICAL WEB SKILL, not theory -> very useful for web pentester/bug bounty
- excellent value for money; top-tier free material
- a good step before or alongside the OSCP for the web part; a base for OSWE
  • The BSCP validates practical web hacking with Burp on the best free material out there (the Academy).
  • Ideal for web pentester / bug bounty (bb-*) due to its realism and focus.
  • Preparing it = mastering the whole Web area and Burp (Burp Suite) thoroughly.
  • Affordable and an excellent step toward the OSWE and a complement to the OSCP.
  • Work through the entire Web Security Academy: the exam comes straight from it, don’t skip labs.
  • Manage both phases under the time limit; get the foothold before you escalate.
  • Prepare a reusable payload collection in Burp beforehand; improvising costs points.
  • Practice exfiltrating the admin credential/flag, not just finding the bug.
  • Complete the PortSwigger Web Security Academy (free)
  • Master Burp Suite thoroughly (Burp Suite)
  • Review the wiki’s whole Web area
  • Practice “mystery labs” (no category hint)
  • Exam pattern: foothold → escalate to admin → exfiltrate
  • Time management (4h exam)
  • Next step: OSWE (OSWE) for white-box