Burp Suite Certified (BSCP)
The BSCP (Burp Suite Certified Practitioner) by PortSwigger certifies practical web hacking skill using Burp Suite, based on the excellent (and free) Web Security Academy. It’s affordable, very practical, and one of the best ways to demonstrate real web competence.
What it is
Section titled “What it is”- a PRACTICAL web hacking certification by PortSwigger (the Burp creators)- it relies on the Web Security Academy (free labs) as study material- a hands-on exam: exploit real web applications using Burp Suite- affordable and highly valued for reflecting current, real web skillWhat it covers
Section titled “What it covers”- the whole web spectrum of the Academy: SQLi, XSS, SSRF, auth, access control, deserialization, SSTI, prototype pollution, CORS, etc. (maps to this wiki's whole Web area)- advanced Burp use (Repeater, Intruder, extensions) -> see tool-burp- chaining vulns to achieve the goal (stealing a specific user's data)The exam
Section titled “The exam”- practical (4h): two applications; in each, escalate from anonymous user to admin and exfiltrate a target user's data (pattern: foothold -> escalate -> exfiltrate)- timed and demanding on time management; requires fluency with Burp- you must find AND exploit live, not answer a testHow to prepare
Section titled “How to prepare”- complete the PortSwigger Web Security Academy (it's FREE and it's the syllabus)- master Burp thoroughly (tool-burp) and the Academy's exploitation patterns- practice the "mystery labs" (no category hint) -> they simulate the exam- review this wiki's whole Web areaProfessional value
Section titled “Professional value”- demonstrates real PRACTICAL WEB SKILL, not theory -> very useful for web pentester/bug bounty- excellent value for money; top-tier free material- a good step before or alongside the OSCP for the web part; a base for OSWEBlue Team / career
Section titled “Blue Team / career”- The BSCP validates practical web hacking with Burp on the best free material out there (the Academy).
- Ideal for web pentester / bug bounty (bb-*) due to its realism and focus.
- Preparing it = mastering the whole Web area and Burp (Burp Suite) thoroughly.
- Affordable and an excellent step toward the OSWE and a complement to the OSCP.
Tips and common mistakes
Section titled “Tips and common mistakes”- Work through the entire Web Security Academy: the exam comes straight from it, don’t skip labs.
- Manage both phases under the time limit; get the foothold before you escalate.
- Prepare a reusable payload collection in Burp beforehand; improvising costs points.
- Practice exfiltrating the admin credential/flag, not just finding the bug.
Testing checklist
Section titled “Testing checklist”- Complete the PortSwigger Web Security Academy (free)
- Master Burp Suite thoroughly (Burp Suite)
- Review the wiki’s whole Web area
- Practice “mystery labs” (no category hint)
- Exam pattern: foothold → escalate to admin → exfiltrate
- Time management (4h exam)
- Next step: OSWE (OSWE) for white-box