BootcampUpcoming

Bug Hunting & Ethical Hacking Bootcamp

Ever wondered how ethical hackers and bug hunters earn from home — by discovering vulnerabilities and reporting them to companies like Google, Microsoft, GitHub, and thousands of modern web applications?

Tue, 01 Sep - Sat, 10 Oct 2026Kathmandu

bootcampbug-bountyethical-hackingtrainingAI security

At a glance

30 days · + 1 week bonus mentorshipCertificate included

About

Course details

Learn ethical hacking and bug bounty hunting through a structured, hands-on program guided by two working security researchers with a combined 19+ years of hacking and vulnerability research experience. This bootcamp takes you from the fundamentals of web applications and reconnaissance to discovering high-value bugs, validating them, and reporting professionally to companies and organizations.

It is not just training — it is a practical path into a cybersecurity career.

Why this bootcamp exists

Most ethical hacking and bug bounty courses teach tools. Students spend weeks on Burp Suite, Nuclei, and dozens of recon commands — yet still struggle to find their first valid vulnerability.

Successful bug hunters are not successful because they know more tools. They succeed because they understand how applications are built, where developers make mistakes, how businesses operate, and how to think like an investigator.

This is not a course about learning tools. Tools change every year; methodology does not. This bootcamp is created to teach that methodology.

Tools change. Payloads change. Methodologies evolve. Learn how to build your own bug hunting methodology that will continue to work long after today's techniques become outdated.

What makes this bootcamp different

  • Independent researchers, not tool runners: Most courses teach you how to run tools in artificial labs. We build independent, high-earning security researchers.
  • 19+ years of combined field experience: Led by two active security researchers — one with over a decade of real-world exploitation and defense experience, the other a CVE-credited researcher with Hall of Fame recognition from Apple, Microsoft, and Dell.
  • Behind-the-scenes report vault: Deconstruct 500+ real bug reports. Study exact triager dialogues and learn how to negotiate, report, and escalate bounties from N/A to Critical.
  • Live sites, not lab sandboxes: Practice and demonstration happen on permitted live sites — not a separate lab stack or only generic TryHackMe / HackTheBox puzzles.
  • 2026 curriculum: Modern coverage of APIs, business logic, authentication, authorization, server-side and client-side vulnerabilities, plus AI & LLM security. Content stays current with how bugs are found today — not only what worked in 2020.
  • Hands-on accountability: Daily practical deliverables with direct instructor reviews to keep you on track.
  • Zero to independent researcher: A structured roadmap from foundational concepts to hunting independently and earning bounties.

Program at a glance

30Core curriculum days
20+Vulnerability classes covered
500+Real bug reports in the research vault
+ 1 weekBonus — personal mentorship & live hunting
+ 3 daysOptional AI & LLM security bonus track

The hunting loop

Every day maps to one stage of a real hunt:

  1. Recon: know what exists before you test it
  2. Rank: turn assets into an ordered attack plan
  3. Hunt: work a vulnerability class with a proven method
  4. Validate: pass the seven-question gate before anything becomes a report
  5. Report: prove impact; never forecast it

Day 30 runs the entire loop solo against a live permitted target.

What you'll get

  • A proven research methodology: The complete vulnerability research workflow refined through 19+ years of combined practical cybersecurity experience, from reconnaissance and attack-surface mapping to validation, impact assessment, and responsible disclosure.
  • Daily live-site practice: Practical exercises, instructor demonstrations on live sites, daily deliverables, and instructor feedback, with a lighter Practice Consolidation & Review day built into every week so pace never outruns retention.
  • Live hunting experience: A supervised capstone against a permitted live target covering the full lifecycle from reconnaissance to submission-ready reporting.
  • Professional reporting framework: Report templates, validation checklists, CVSS scoring guidance, and reporting methodologies inspired by real-world security programs.
  • Exclusive research library: Carefully selected private and public vulnerability reports, security research papers, triage discussions, and real-world case studies.
  • Modern security testing toolkit: Industry-standard tools and workflows for recon, web application security, API testing, authentication, business logic, AI & LLM security, and validation.
  • Direct instructor mentorship: Personalized guidance, technical feedback, report reviews, and practical insights from experienced security researchers throughout the bootcamp.
  • Bonus week: work with instructors like teammates: One week of personal mentorship after the 30-day core: engage practically with instructors as if you are researching together, with a path toward real-world bug bounty submissions.
  • Career-ready skills: The investigative mindset, structured methodology, and practical experience required for bug bounty hunting, responsible disclosure, application security, and offensive security careers.
  • Internship opportunity for top performers: Students who consistently demonstrate exceptional technical ability, professionalism, and commitment may be invited to interview for internship opportunities at Trinity Technology Pvt. Ltd. (subject to performance and position availability).
  • Certificate of completion: A professional certificate recognizing successful completion of the Bug Hunting & Ethical Hacking Bootcamp.

How you'll report

Every finding leaves through the same structure:

FieldWhat it must contain
SummaryOne sentence — what the bug is and what it lets an attacker do, stated as fact
DescriptionWhere the flaw lives, why the current control fails, what a correct control looks like
Steps to reproduceNumbered, copy-pasteable steps with real request/response pairs
ImpactWhat was actually demonstrated — never "may lead to" or "could potentially"
Severity & CVSSFull vector string plus the reasoning behind each metric
RemediationOne concrete fix, stated the way an engineer would want to receive it

Standing rules for the cohort

  1. No report leaves without the validation gate. If a finding can't answer all seven questions, it goes back to the hunt.
  2. Scope is read before recon starts — every time.
  3. Every report carries its own CVSS vector. Students propose severity; they don't wait to be told.
  4. Prove it, don't forecast it.

Tools you'll actually use

Recon & fingerprinting — subfinder, amass, crt.sh, httpx, nmap, katana, gau, waybackurls, dnsReaper, subjack

Exploitation — Burp Suite, Turbo Intruder, jwt_tool, sqlmap, graphw00f, InQL, LinkFinder, SecretFinder

Practice & demonstration — Permitted live sites under instructor guidance (no separate lab environment for this cohort)

AI & LLM (bonus) — Live or instructor-led demos on real AI-facing targets, plus prompt/response transcript review

Research library

Study carefully selected private and public vulnerability reports, triage conversations, and research papers — not just bug titles. Case studies are drawn from programs and research involving Stripe, Shopify, GitLab, X / Twitter, Starbucks, Mozilla, TikTok, Curve, Zomato, Ubiquiti, Basecamp, Omise, Zenly, Khan Academy, Grab, Unikrn, Glovo, WakaTime, Legal Robot, curl, MTN Group, Automattic, Algolia, Linktree, Logitech, HackerOne's own program, and foundational PortSwigger research.

Who this bootcamp is for

Cybersecurity is not reserved for computer science graduates or experienced penetration testers. Many of today's successful security researchers started with curiosity, determination, and a willingness to keep learning.

Whether you are teaching yourself cybersecurity, transitioning into a security career, or helping your organization build stronger security capabilities, this bootcamp provides a practical, structured path to real-world vulnerability research.

This bootcamp is a strong fit for

  • Aspiring ethical hackers & bug hunters — A complete roadmap from your first HTTP request to your first professional vulnerability report.
  • Students & fresh graduates — Practical application security skills that go beyond classroom theory, with portfolio work for internships and cybersecurity careers.
  • Self-taught learners — A proven path, expert mentorship, and hands-on experience if YouTube, blogs, and Discord left you unsure what to learn next.
  • IT professionals & career changers — Modern offensive security skills for system administrators, network engineers, QA engineers, developers, and others moving into cybersecurity.
  • Developers, DevOps & QA engineers — Learn how attackers find weaknesses in modern applications so you can build, test, and maintain software with security in mind.
  • Corporate teams & organizations — Practical application security knowledge for development, QA, DevOps, and security teams to improve secure development and vulnerability awareness.
  • Anyone passionate about cybersecurity — No previous bug bounty experience or professional hacking knowledge required.

You'll feel right at home if…

  • You believe learning comes from building, testing, and investigating — not just watching videos.
  • You want to understand how professional security researchers think, not simply how to run security tools.
  • You enjoy solving problems, asking questions, and digging deeper to understand why vulnerabilities exist.
  • You're ready to invest time in developing practical, career-ready cybersecurity skills.
  • You want to graduate with a repeatable methodology, hands-on experience, and the confidence to investigate modern applications independently.

No prior bug bounty experience is required. Curiosity, consistency, and a willingness to learn are the only prerequisites. We'll help you build the rest.

Teaching philosophy

Don't just memorize tools or copy someone else's methodology. Learn how to build your own investigative mindset. The results may come slower at first, but the skills you develop will stay with you throughout your cybersecurity career.

Bonus week — Personal mentorship & live bug hunting

After the 30-day core, learning does not stop at the classroom.

All students get one bonus week of personal mentorship — engaging with instructors in practice as if you are working together on the same research team. This is hands-on collaboration, not another lecture block.

During this week, you'll have the opportunity to:

  • Work with instructors like teammates — Hunt, discuss, and iterate side by side with personal mentorship from practitioners.
  • Apply skills on permitted live targets — Use professional bug hunting methodology on real-world-style assessments.
  • Collaborative research — Recon, attack-surface investigation, and discovery with instructors and fellow students.
  • Validate & polish findings — Verify bugs, cut false positives, strengthen evidence, and prepare submission-ready reports.
  • Path to real-world bug bounties — A genuine opportunity to pursue live program submissions and, where findings hold up, earn from real-world bug bounty work.

This bonus week bridges live-site practice and working as a researcher — with the potential to turn practice into real bounty outcomes.

Outstanding performers during the research week may also be considered for internship opportunities at Trinity Technology Pvt. Ltd., subject to performance and position availability.

Week themes

WeekTheme
01–0530-day core — foundations through capstone hunt
BonusAI & LLM security (optional)
Bonus1 week — personal mentorship & live bounty pathway

Outcome: leave after 30 days of structured training plus a mentorship week where you practice with instructors as collaborators — ready to hunt independently, with a real shot at bug bounty submissions.

Syllabus

What you'll learn

7 modules · 37 sessions — expand a week to see daily topics and labs.

  • Day 01 — How the Web Actually Works (HTTP, cookies, sessions, Burp Suite)
  • Day 02 — Reading a Program's Scope Like a Lawyer
  • Day 03 — Recon Pipeline: Subdomains, Live Hosts, Fingerprinting
  • Day 04 — JS & Endpoint Mining
  • Day 05 — Building the Attack Surface Map
  • Day 06 — Practice Consolidation & Review: recon walkthrough on live targets, peer review of Days 01–05 deliverables

Instructors

  • Sujan Thapa Magar
  • Shankar Acharya

Learn from practitioners

Sujan Thapa Magar (lead) with Shankar Acharya

Sujan Thapa Magar

Sujan Thapa Magar

Lead

Lead Instructor — Offensive Security Researcher

Offensive security researcher and security consultant with 13+ years of practical cybersecurity experience in vulnerability research, web application security, and offensive security. He has reported 1000+ valid vulnerabilities across 100+ organizations spanning web apps, APIs, authentication, business logic, cloud, and AI security. This bootcamp is built on that research — every methodology, workflow, and reporting technique comes from real responsible disclosure, not classroom theory.

Shankar Acharya

Shankar Acharya

Co-instructor

Co-instructor — Offensive Security & Application Security (Co-founder & CTO, Trinity Technology)

Cybersecurity engineer and offensive security researcher with 6+ years of hands-on experience breaking web, mobile, API, and desktop systems. He holds Bug Bounty Hall of Fame recognition from Apple, Microsoft, Dell, and 100+ other organizations, has 3 published CVEs to his name, and carries the eWPTXv2 and CASA certifications. His work spans penetration testing, secure code review, application security architecture, AI/ML and cloud (AWS) security, and IoT/hardware research — Flipper Zero, USB Rubber Ducky, and automotive key systems among them. He leads live-site practice and demonstration, report review, and hunting sessions in this cohort from that same working practice.

FAQ

Frequently asked questions

Aspiring ethical hackers and bug hunters, students and fresh graduates, self-taught learners, IT professionals and career changers, developers / DevOps / QA engineers, corporate teams building security maturity, and anyone curious about cybersecurity. No prior bug bounty experience is required — curiosity, consistency, and a willingness to learn are the prerequisites.