
Burp Suite Certified Practitioner - Portswigger - My notes - Guide
This repo contains each cheatsheet along with its respective most important labs.
Each topic includes its own cheatsheet/methodology, the most relevant labs, and useful resources.
⭐This is the result of months of work — I hope you find it helpful. If you do, please leave a star. ⭐
❗This repository contains my own cheatsheets and methodologies for the exam — not PortSwigger's. You may consult PortSwigger's resources if you wish, but the files here are my personal notes.
❗I highly recommend creating your own cheatsheets. This repository is intended to help others, provide examples, show the overall organization, and demonstrate my work and methodologies.
💡🤓 This repository is a summary of all my Obsidian notes for the BSCP. I learned a lot while creating it because I focused on making it as clear and didactic as possible, fully internalizing all the concepts to be able to explain them correctly.
The following are basic resources offered by PortSwigger for the exam:
The exam consists of 2 machines, each with 3 phases, and a duration of 4 hours.
⚠️ This is a reference — please, always verify and research on your own.
❗ Remember: You should probably chain multiple vulnerabilities.
| Category | Stage 1 | Stage 2 | Stage 3 |
|---|
| XSS | 🟢 | 🟢 | 🟡 |
| DOM | 🟢 | 🟢 | 🟡 |
| SQL Injection | 🔴 | 🟢 | 🟡 |
| NoSQL Injection | 🔴 | 🟢 | 🟡 |
| CSRF | 🟢 | 🟢 | 🔴 |
| SSRF | 🔴 | 🟡 | 🟢 |
| Authentication | 🟢 | 🟢 | 🔴 |
| OAuth | 🟢 | 🟢 | 🔴 |
| OS Command Injection | 🔴 | 🔴 | 🟢 |
| Web Cache Poisoning | 🟢 | 🟢 | 🔴 |
| Web Cache Deception | 🟢 | 🟢 | 🔴 |
| File Upload | 🔴 | 🔴 | 🟢 |
| Host Header Injection | 🟡 | 🟡 | 🟢 |
| Insecure Deserialization | 🔴 | 🔴 | 🟢 |
| HTTP Request Smuggling | 🟢 | 🟢 | 🔴 |
| API | 🟢 | 🟢 | 🔴 |
| CORS | 🟢 | 🟢 | 🔴 |
| Prototype Pollution | 🟢 | 🟢 | 🟢 |
| JWT | 🟢 | 🟢 | 🔴 |
| GraphQL - API Endpoints | 🟢 | 🔴 | |
| XML - XXE | 🔴 | 🟡 | 🟢 |
| SSTI | 🔴 | 🔴 | 🟢 |
| Broken Access Control | 🔴 | 🟢 | 🔴 |
| Path Traversal | 🔴 | 🔴 | 🟢 |
| Race Condition | 🟢 | 🟢 |