Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
BSCP-EXAM-GUIDE-BY-N3OARI-2026 — Burp Suite Certified Practitioner - Portswigger - My notes - Guide | Kitploit
Tools/GitHubGitHub/n3oari/bscp-exam-guide-by-n3oari-2026
Web SecurityPenetration TestingLearning & EducationCurated ResourcesLearning Paths & CoursesLabs & Practice
GitHubn3oari/bscp-exam-guide-by-n3oari-2026

BSCP-EXAM-GUIDE-BY-N3OARI-2026

Burp Suite Certified Practitioner - Portswigger - My notes - Guide

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
27510 days agoReviewed by Kitploit

README.MD (MARCH 2026)

This repo contains each cheatsheet along with its respective most important labs.

Each topic includes its own cheatsheet/methodology, the most relevant labs, and useful resources.


⭐This is the result of months of work — I hope you find it helpful. If you do, please leave a star. ⭐


❗This repository contains my own cheatsheets and methodologies for the exam — not PortSwigger's. You may consult PortSwigger's resources if you wish, but the files here are my personal notes.

❗I highly recommend creating your own cheatsheets. This repository is intended to help others, provide examples, show the overall organization, and demonstrate my work and methodologies.

💡🤓 This repository is a summary of all my Obsidian notes for the BSCP. I learned a lot while creating it because I focused on making it as clear and didactic as possible, fully internalizing all the concepts to be able to explain them correctly.


The following are basic resources offered by PortSwigger for the exam:

  • usernames wordlist
  • passwords wordlist
  • delimiters wordlist (web cache deception)

The exam consists of 2 machines, each with 3 phases, and a duration of 4 hours.

  • 1: Access any user account.
  • 2: Elevate privileges or compromising the administrator account.
  • 3: Exfiltrate contents of /home/carlos/secret and submit solution

Some utilities

  • Most Important HTTP Headers
  • HTB machines I recommended for each topic
  • REGEX explanation (util to interpreter code)
  • js-beautify (util to interpreter code)
  • URL validation bypass cheat sheet (SSRF)

Enumeration & Web Discovery

  • API testing / recon
  • Obfuscation payloads (escape bypass)

PHASE 1 → Obtain Inicial User

  • XSS / DOM vulnerabilities
  • Authentication / Brute-Force
  • OAuth
  • Host Header Injection
  • Web Cache Poisoning
  • Web Cache Deception
  • HTTP Request Smuggling

PHASE 2 → Elevate Privileges

  • SQL Injection
  • NoSQL Injection
  • Client Side Request Forgery (CSRF)
  • Cross-Origin Resource Sharing (CORS)
  • Prototype Pollution
  • Authentication -> Password Reset
  • JWT
  • GraphQL API

PHASE 3 → Exfiltrate Data

  • XML - XXE Injection
  • Server Side Request Forgery (SSRF)
  • Path Traversal
  • OS - Command Injection
  • Deserialization Insecure
  • File Uploads (Web Shell)
  • Server Side Template Injection (SSTI)

OTHERS

  • Race Condition
  • Clickjacking


⚠️ This is a reference — please, always verify and research on your own.

❗ Remember: You should probably chain multiple vulnerabilities.



Contact me!

Discord


Download Tool
CategoryStage 1Stage 2Stage 3
XSS🟢🟢🟡
DOM🟢🟢🟡
SQL Injection🔴🟢🟡
NoSQL Injection🔴🟢🟡
CSRF🟢🟢🔴
SSRF🔴🟡🟢
Authentication🟢🟢🔴
OAuth🟢🟢🔴
OS Command Injection🔴🔴🟢
Web Cache Poisoning🟢🟢🔴
Web Cache Deception🟢🟢🔴
File Upload🔴🔴🟢
Host Header Injection🟡🟡🟢
Insecure Deserialization🔴🔴🟢
HTTP Request Smuggling🟢🟢🔴
API🟢🟢🔴
CORS🟢🟢🔴
Prototype Pollution🟢🟢🟢
JWT🟢🟢🔴
GraphQL - API Endpoints🟢🔴
XML - XXE🔴🟡🟢
SSTI🔴🔴🟢
Broken Access Control🔴🟢🔴
Path Traversal🔴🔴🟢
Race Condition🟢🟢