BRISTLEBACK PENETRATION TESTING BBPT · ADVANCED PROGRAM

Learn to test systems.
Understand how they break.

Develop practical penetration-testing skills through structured methodology, hands-on labs, realistic attack scenarios and professional reporting.

13Modules
4Levels
LabsPractical work
2Learning modes

THE RIGHT FOUNDATION

Build the capability behind the tools.

BBPT takes you from penetration-testing fundamentals to full-scope assessment through a structured progression of methodology, technical skills, practical labs and professional reporting.

01

What you'll learn

Reconnaissance, vulnerability assessment, network and web application testing, privilege escalation, Active Directory, pivoting, post-exploitation, exploit modification and professional reporting.

02

Who is this for?

Cybersecurity learners, IT professionals, system and network administrators, and technically inclined learners who want practical penetration-testing capability.

03

Prerequisites

A basic understanding of computers, networking and operating systems is recommended. Stronger foundations can be developed through Bristleback foundation programs.

Explore foundations →

THE BBPT PATH

From foundations to full-scope penetration testing.

A four-level progression covering methodology, technical skills and professional practices.

LEVEL 1

Pentesting Foundations

01Module 01 — Penetration Testing Methodology9 topics
  • Penetration testing concepts and lifecycle
  • Types of penetration tests
  • Black-box, grey-box and white-box testing
  • Scope and Rules of Engagement
  • Legal and ethical considerations
  • Assessment methodology
  • Attack surface
  • Evidence collection
  • Documentation and note-taking
02Module 02 — Reconnaissance & OSINT13 topics
  • Passive reconnaissance
  • Active reconnaissance
  • OSINT methodology
  • WHOIS and DNS
  • Subdomain discovery
  • DNS enumeration
  • Search-engine reconnaissance
  • Google dorking
  • Email and username enumeration
  • Technology identification
  • Shodan and similar sources
  • Target profiling
  • Attack-surface mapping
03Module 03 — Vulnerability Assessment11 topics
  • Vulnerability vs. exploit vs. risk
  • Vulnerability scanning
  • Nmap
  • Service and version detection
  • NSE
  • Vulnerability scanners
  • CVE/CVSS
  • Manual vulnerability verification
  • False positives
  • Vulnerability prioritization
  • Mapping vulnerabilities to exploitation opportunities
LEVEL 2

Core Penetration Testing

04Module 04 — Network Penetration Testing18 topics
  • Network discovery
  • Port scanning
  • TCP/UDP scanning
  • Service enumeration
  • Banner grabbing
  • FTP
  • SSH
  • SMB
  • SMTP
  • SNMP
  • HTTP/HTTPS
  • Database services
  • Network-service vulnerabilities
  • Password attacks
  • Exploitation
  • Metasploit
  • Manual exploitation
  • Post-exploitation basics
05Module 05 — Web Application Penetration Testing30 topics
  • HTTP/HTTPS fundamentals
  • HTTP requests and responses
  • Cookies and sessions
  • Authentication and authorization
  • Burp Suite
  • Web reconnaissance
  • Directory and file discovery
  • Parameter discovery
  • SQL injection
  • XSS
  • CSRF
  • IDOR/BOLA
  • Authentication attacks
  • Session attacks
  • Access-control vulnerabilities
  • Command injection
  • File inclusion
  • Path traversal
  • File-upload vulnerabilities
  • XXE
  • SSRF
  • SSTI
  • Deserialization
  • CORS
  • Security headers
  • API security
  • JWT
  • GraphQL basics
  • Business-logic vulnerabilities
  • Vulnerability chaining
06Module 06 — Linux Privilege Escalation18 topics
  • Linux enumeration methodology
  • Users and groups
  • File permissions
  • SUID/SGID
  • Sudo
  • Capabilities
  • Cron jobs
  • PATH hijacking
  • Environment variables
  • Writable files/directories
  • Services
  • Processes
  • Credentials
  • SSH keys
  • Kernel exploits
  • Automated enumeration tools
  • Manual privilege escalation
  • Root access
07Module 07 — Windows Privilege Escalation19 topics
  • Windows enumeration methodology
  • Users and groups
  • File and directory permissions
  • Services
  • Scheduled tasks
  • Registry
  • PATH vulnerabilities
  • Unquoted service paths
  • DLL hijacking
  • Weak service permissions
  • Windows tokens
  • Token impersonation
  • Named pipes
  • Credentials
  • PowerShell
  • Windows privilege escalation tools
  • Kernel exploits
  • Manual privilege escalation
  • SYSTEM access
LEVEL 3

Advanced Penetration Testing

08Module 08 — Active Directory Penetration Testing31 topics
  • Active Directory architecture
  • Domains, forests and trusts
  • Domain Controllers
  • Users, groups and computers
  • LDAP
  • SMB
  • Kerberos
  • NTLM
  • AD enumeration
  • BloodHound
  • PowerView
  • LDAP enumeration
  • SMB enumeration
  • Password attacks
  • Password spraying
  • Kerberoasting
  • AS-REP Roasting
  • LLMNR/NBT-NS poisoning
  • Responder
  • NTLM relay
  • Pass-the-Hash
  • Pass-the-Ticket
  • Credential harvesting
  • ACL abuse
  • Delegation attacks
  • Privilege escalation
  • Lateral movement
  • Remote execution
  • Domain compromise
  • Post-exploitation
  • Attack-path analysis
09Module 09 — Pivoting & Tunneling13 topics
  • Network segmentation
  • Internal network discovery
  • Pivot hosts
  • Port forwarding
  • Local and remote port forwarding
  • SOCKS proxies
  • Proxychains
  • SSH tunneling
  • Chisel
  • Ligolo-ng
  • Accessing internal services
  • Multi-hop pivoting
  • Pivoting during AD attacks
10Module 10 — Post-Exploitation & Lateral Movement16 topics
  • Situational awareness
  • Host enumeration
  • Credential discovery
  • Credential dumping
  • Password hashes
  • Secrets and tokens
  • Lateral movement
  • Remote services
  • Windows remote execution
  • Linux remote access
  • Data discovery
  • Sensitive information identification
  • Persistence concepts
  • Cleanup
  • Maintaining operational security
  • Evidence preservation
11Module 11 — Exploit Development & Modification15 topics
  • Understanding public exploits
  • Reading exploit code
  • Exploit modification
  • Python-based exploit modification
  • Fuzzing concepts
  • Buffer overflows
  • Stack fundamentals
  • Registers
  • EIP/RIP
  • Bad characters
  • Shellcode concepts
  • Debugging
  • Mona
  • Basic exploit development
  • Adapting exploits to different targets
LEVEL 4

Professional Penetration Testing

12Module 12 — Professional Pentest Reporting17 topics
  • Evidence collection
  • Screenshots
  • Proof of concept
  • Vulnerability description
  • Reproduction steps
  • Technical impact
  • Business impact
  • Risk rating
  • CVSS
  • Remediation
  • Executive summary
  • Technical findings
  • Attack narrative
  • Attack-chain documentation
  • Professional report structure
  • Client communication
  • Retesting and remediation verification
13Module 13 — Full-Scope Penetration Test16 topics
  • Scope interpretation
  • Reconnaissance
  • Enumeration
  • Vulnerability identification
  • Exploitation
  • Privilege escalation
  • Credential discovery
  • Lateral movement
  • Pivoting
  • Internal network assessment
  • Web application assessment
  • Active Directory compromise
  • Evidence collection
  • Attack-chain construction
  • Risk assessment
  • Professional reporting

PRACTICAL LEARNING

Don't just learn the technique. Learn how to investigate.

Work through guided labs and realistic security scenarios where you identify targets, investigate weaknesses, exploit vulnerabilities, escalate privileges and document findings.

>_

Reconnaissance

Discover and profile targets.

>_

Enumeration

Identify services, technologies and attack surfaces.

>_

Exploitation

Validate vulnerabilities through controlled exploitation.

>_

Privilege Escalation

Move from initial access toward higher privileges.

>_

Lateral Movement

Understand how attackers move through environments.

>_

Professional Reporting

Turn technical findings into clear security reports.

05 · PRICING

BBPT course fee.

The standard BBPT course fee is ₹44,000. Learning-mode offers are calculated automatically from the standard fee. The course fee is collected in two equal instalments.

FULL COURSE FEE

₹44,000

Standard fee for the complete BBPT programme.

Full price
ONLINE · 40% OFF

₹26,400

Save ₹17,600 · 2 equal instalments of ₹13,200

Online offer
OFFLINE · 10% OFF

₹39,600

Save ₹4,400 · 2 equal instalments of ₹19,800

Offline offer
Two equal instalments.Coming Soon · Batch allocation is confirmed before payment and course commencement.₹44,000 standard

REFUND & CANCELLATION

Four Learning Satisfaction Checkpoints. You stay in control.

The course fee for the selected learning mode is collected in two equal instalments. At 25%, 50%, 75% and 100% of syllabus coverage, you can assess whether the learning delivered so far is satisfactory. If you are not satisfied, the applicable Learning Satisfaction Checkpoint refund is available and you may exit. No certificate is issued for an unsatisfied exit.

25% LEARNING SATISFACTION CHECKPOINT

Not satisfied → 100% of 1st instalment

Exit the programme. No certificate is issued.

50% LEARNING SATISFACTION CHECKPOINT

Not satisfied → 50% of 1st instalment

Exit the programme. If satisfied, pay the 2nd instalment and continue.

75% LEARNING SATISFACTION CHECKPOINT

Not satisfied → 100% of 2nd instalment

Exit the programme. No certificate is issued.

100% LEARNING SATISFACTION CHECKPOINT

Not satisfied → 50% of 2nd instalment

Exit the programme. If satisfied, the programme is completed and a Certificate of Completion is issued.

Two instalments · four Learning Satisfaction Checkpoints.The checkpoint refund is calculated against the relevant equal instalment of the selected learning mode. See the full Refund & Cancellation Policy for complete terms and examples.

CHOOSE HOW YOU LEARN

Learn online. Learn in the classroom.

Choose the mode that fits you. Batch availability depends on learner demand and confirmed scheduling.

Teaching languages: English and Tamil.

01

Online

Live online learning from wherever you are, with instructor-led sessions and guided practical work.

02

Offline

Classroom learning in Puducherry when an offline batch is confirmed.

03

Flexible

Prefer either mode? Tell us your preference during registration and we will consider you for the next suitable batch.

BATCH AVAILABILITY

Find a learning slot that works for you.

Programs will be allocated to the slot with sufficient demand. Once a batch is confirmed, its dedicated batch page will publish the confirmed schedule.

SLOT 01Awaiting allocationNo batch assigned yet
SLOT 02Awaiting allocationNo batch assigned yet
SLOT 03Awaiting allocationNo batch assigned yet
SLOT 04Awaiting allocationNo batch assigned yet

CERTIFICATION & REGISTRATION

Ready to start BBPT?

Register your interest, tell us your preferred learning mode and schedule, and we'll consider you for the next suitable batch. Payment is collected only after your batch is confirmed.

BBPT Certification

Certificate issuance will be based on the defined completion requirements for the program, including the required learning and practical components.

Coming Soon