Loading...
Please wait a moment
Founded by passionate advocates of learning and innovation, Learni set out to make professional training accessible to everyone, everywhere in the world. Our team works in the largest cities such as Paris, Lyon, Marseille, and internationally, to support talents and organizations in their skills development.
Which format do you prefer?
30 free minutes with a training advisor — no commitment.
Loading available slots...
Cybersecurity training in Sheffield in November 2026 with Learni. Certified, expert trainers, eligible for employer funding. Free quote.
Cybersecurity training in Brighton in July 2026 with Learni. Certified, expert trainers, eligible for employer funding. Free quote.
Cybersecurity training in Oklahoma City in December 2026 with Learni. Certified, expert trainers, eligible for employer funding. Free quote.
Professional Training training in New York in September 2026 with Learni. Certified, expert trainers, eligible for employer funding. Free quote.
The Training Bug Bounty - Hunting Zero-Day Vulnerabilities training is delivered in-person or remotely (blended-learning, e-learning, virtual classroom, remote in-person). At Learni, a Qualiopi-certified training organization, each program is designed to maximize skills acquisition, regardless of the training mode chosen.
The trainer alternates between demonstrative, interrogative, and active methods (through practical exercises and/or real-world scenarios). This pedagogical approach ensures concrete and directly applicable learning in the workplace.
To ensure the quality of the Training Bug Bounty - Hunting Zero-Day Vulnerabilities training, Learni provides the following teaching resources:
For in-house training at a location external to Learni, the client ensures and commits to having all necessary teaching materials (IT equipment, internet connection...) for the proper conduct of the training action in accordance with the prerequisites indicated in the communicated training program.
The assessment of skills acquired during the Training Bug Bounty - Hunting Zero-Day Vulnerabilities training is carried out through:
Learni is committed to the accessibility of its professional training programs. All our training programs are accessible to people with disabilities. Our teams are available to adapt teaching methods to your specific needs. Do not hesitate to contact us for any accommodation request.
Learni training programs are available for inter-company and intra-company settings, both in-person and remote. Registration is possible up to 48 business hours before the start of training. Our programs are eligible for OPCO, Pôle emploi, and FNE-Formation funding. Contact us to discuss your training project and funding possibilities.
Immersion in passive reconnaissance techniques to identify hidden subdomains and sensitive endpoints, use of tools like Amass and Subfinder to map real target perimeters, practical exercises on live bug bounty programs like HackerOne, construction of a personalized scope with prioritization of high-value assets, analysis of bug histories to anticipate recurring vulnerabilities, and development of a documented preliminary reconnaissance report.
In-depth exploration of polyglot XSS injections and DOM-based attacks with contextual payloads, SSRF chaining for out-of-band RCE via Burp Collaborator, detection of massive IDORs on GraphQL APIs, practical workshops on vulnerable labs inspired by recent HackerOne reports, development of Python scripts for automated fuzzing, WAF bypass testing with mutation techniques, and production of a video PoC demonstrating the business impact of a critical vulnerability.
Analysis of OAuth 2.0 flaws such as redirect URI manipulation and token theft, decryption and forgery of JWTs with tools like jwt_tool, exploitation of logic flaws in multi-factor authentication flows, simulations on real REST/GraphQL APIs with Postman and Burp, development of automated Bash exploits for mass hunting, evaluation of impact on user data confidentiality, and creation of a report template for enterprise programs.
Mastery of vulnerability chaining to escalate from low to critical severity, integration of Nuclei and FFUF for scalable scans on thousands of endpoints, creation of custom YAML templates based on recent CVEs, workshops on simulated bug bounty CTFs with real scoring, workflow optimization via Docker and GitHub Actions for hunting CI/CD, post-exploitation persistence and lateral movement testing, and code review by the trainer to refine PoCs.
Writing impactful reports with CVSS triage, clear methodology, and reproduction steps, bounty negotiation using best practices from top hunters, review of recent disclosures on HackerOne and Intigriti, handling triages and false positives, workshops on GDPR compliance and private contracts, simulation of a pitch to an enterprise client for internal programs, and post-training action plan to launch profitable hunting with ROI tracking.
Target audience
Pentesters, security researchers, and cybersecurity experts aiming to advance their skills in paid bug hunting
Prerequisites
Advanced experience in web pentesting, mastery of Burp Suite, in-depth knowledge of OWASP Top 10 and vulnerability exploitation
Loading...
Please wait a moment





























