HackproofHacks
Training

Learn ethical hacking
from scratch

Live mentorship, hands-on labs, and a structured roadmap, taught by a practising penetration tester. You don't need an IT background; the curriculum starts at zero and assumes nothing.

10,000+ Learners trained
212K+ Community audience
120+ Training hours

Every application is reviewed manually. About 29% of applicants are accepted.

Next cohort starts August 2026 · Capped at 20 students · Applications close when the batch fills

In their words

Students,
in their own words

Unedited messages from students mid-programme, screenshotted exactly as they were sent. Swipe through them, then read the full quotes below.

Tracks

Two ways
to learn

Both tracks cover the same curriculum. The difference is format, pace, and how much personal attention you get.

Group cohort · Starts August 2026

Batch Mentorship

A structured group cohort with live sessions, real-time Q&A, and peer learning. Cohorts are capped at 20 students so nobody gets lost in the crowd.

₹1,999 /month · 10-month live program

Comparable live bootcamps charge ₹40,000+ upfront. This is priced so students can actually pay: same instructor, no watered-down recordings.

  • Full curriculum from basics to advanced, no gaps skipped
  • Every live session taught by Hassan himself
  • Fixed schedule and curriculum
  • Max 20 students per cohort
  • 100+ hours of practical content
  • 80% of session time spent in hands-on labs
  • Chat support via Telegram
  • Bilingual instruction: English and Urdu/Hindi
  • Session recordings for every class
  • Certificate of completion

Best for

Career starters and structured learners

Apply
Private · Limited to 5 mentees

1:1 Mentorship

Private sessions with Hassan. You set the goal and he builds the roadmap around it, whether that's a first bug bounty or a senior pentest interview.

Custom pricing

Every 1:1 roadmap is different, so the price is set on a free 10-minute discovery call, and you'll get an exact quote before committing to anything.

  • Full curriculum, tailored to your goals and pace
  • Taught by Hassan himself, no outsourcing
  • Flexible timings that fit your schedule
  • Curriculum built around your goals rather than a fixed syllabus
  • 100+ hours of practical content
  • Private Telegram channel for async support
  • Bilingual instruction: English and Urdu/Hindi
  • Code review, methodology audits, and real-target walkthroughs
  • Portfolio building and mock interview rounds included

Hassan mentors at most 5 students at a time so each one gets real attention. 3 of 5 mentee slots are currently filled. Seats open as mentees graduate.

Best for

Fast-track growth and career pivots

Apply
Who it's for

Built for people
starting out

College students

You want practical skills before you graduate: real tools, real labs, and a portfolio you can show.

Career switchers

Coming from software development, IT support, or a completely different field, and looking for a way into security.

Freelancers and builders

You want to offer security services, hunt bug bounties, or protect what you've already built.

The only entry requirements are curiosity and consistency. No coding background, no IT degree. Apply here.

Roadmap

Four phases,
in a deliberate order

Every topic builds on the last, so you're never jumping around or guessing what to study next.

  1. 01

    Build your base

    Lab setup, Linux fundamentals, and networking basics. Everything you need before you touch a target.

    Kali Linux setup · Networking concepts · Linux CLI basics

  2. 02

    Learn how to find

    Reconnaissance, OSINT, scanning, and enumeration. The discipline of discovering attack surface.

    Recon methodology · OSINT techniques · Scanning & enumeration

  3. 03

    Learn how to test

    Web hacking, Burp Suite, OWASP vulnerabilities, API testing, and authentication flaws.

    Burp Suite mastery · OWASP Top 10 (2025) · API & auth testing

  4. 04

    Learn how to think

    Methodology, professional report writing, real engagement workflows, and career strategy.

    Testing methodology · Professional reporting · Bug bounty strategy

Curriculum

16 modules,
120+ hours, zero gaps

This is the whole curriculum, not a teaser. Expand any module to see exactly what's inside it before you commit to anything.

01

Introduction to Ethical Hacking

Core concepts, the attacker mindset, and the legal landscape before you touch a single tool.

  • What is ethical hacking & bug bounty?
  • Legal frameworks, responsible disclosure
  • Career paths: pentest, bug bounty, red team
  • Building the attacker's mindset from day one
02

Complete Hacking Lab Setup

Kali Linux, VMs, Burp Suite, and every tool you'll rely on throughout the course.

  • Installing Kali Linux & VirtualBox/VMware
  • Configuring Burp Suite & browser proxying
  • Setting up isolated test environments
  • Essential tools: nmap, ffuf, gobuster, sqlmap
03

Linux Mastery for Hackers

You can't hack systems you can't navigate. This module builds terminal fluency.

  • Terminal navigation & file system control
  • User permissions, privilege concepts & sudo abuse
  • Bash scripting for attack automation
  • Networking commands: netstat, curl, wget, ss
04

Networking Fundamentals

Every attack travels through a network. Understand what you're targeting before you exploit it.

  • TCP/IP model and packet flow
  • DNS resolution, HTTP/HTTPS mechanics
  • Proxies, firewalls, and NAT
  • Wireshark packet capture and traffic analysis
05

Reconnaissance & Information Gathering

Full recon methodology, end to end.

  • Passive vs. active reconnaissance
  • Subdomain enumeration with amass & subfinder
  • Port and service scanning with nmap
  • Directory brute-forcing with ffuf & gobuster
06

OSINT & Digital Intelligence

What public data reveals about a target, and how to gather it systematically.

  • Google dorking & advanced search operators
  • Shodan, Censys, and internet-wide scanning
  • Social engineering intelligence gathering
  • Finding exposed credentials and data leaks
07

Web Fundamentals for Hackers

Every web vulnerability lives in the HTTP layer. This module covers it thoroughly.

  • HTTP request/response structure & anatomy
  • Cookies, sessions, JWTs, and authentication tokens
  • Same-origin policy, CORS, and CSP bypass
  • Intercepting and modifying traffic in Burp Suite
08

Burp Suite Mastery

Proxy, repeater, intruder, scanner: every feature you'll use in real testing.

  • Proxy setup and live traffic interception
  • Repeater for manual request manipulation
  • Intruder for fuzzing, brute-force, and parameter tampering
  • Scanner, Collaborator, and extensions (Turbo Intruder, Autorize)
09

Web Application Attacks

SQLi, XSS, IDOR, SSRF, LFI: every class exploited hands-on in labs.

  • SQL injection: error-based, blind, time-based, OOB
  • Cross-Site Scripting (XSS): reflected, stored, DOM
  • Insecure Direct Object References (IDOR) & BOLA
  • SSRF, open redirects, path traversal, and file inclusion
10

OWASP Top 10 (2025)

Every critical category, demonstrated live rather than just defined.

  • A01 Broken Access Control & BOLA exploitation
  • A02 Cryptographic failures & weak cipher attacks
  • A03 Injection attacks: SQL, NoSQL, command injection
  • A07 Auth failures: session fixation, brute-force, MFA bypass
11

API Hacking

REST, GraphQL, and logic flaw exploitation covered in full.

  • REST API recon and endpoint enumeration
  • GraphQL introspection, query injection & batching attacks
  • OWASP API Top 10: every category exploited
  • Authentication bypass, rate-limit evasion, and mass assignment
12

Network Penetration Testing

Beyond the web: scan, enumerate, and exploit network services.

  • Network scanning & host discovery with nmap
  • Service exploitation with Metasploit
  • Password attacks: brute-force, credential stuffing
  • Post-exploitation: privilege escalation basics
13

Active Directory & Windows Attacks

AD is in every enterprise. Enumeration, lateral movement, and privilege escalation.

  • Active Directory structure and attack surface
  • BloodHound for AD enumeration and path mapping
  • Kerberoasting, Pass-the-Hash, and Pass-the-Ticket
  • Domain privilege escalation and persistence
14

Mobile Application Security

The Android attack surface: static analysis, dynamic testing, and API interception.

  • Setting up MobSF and Android emulator
  • APK reverse engineering and static analysis
  • Dynamic testing with Frida and objection
  • Intercepting mobile API traffic with Burp Suite
15

Advanced Bug Bounty Methodology

A structured approach to hunting beyond the basics.

  • Chaining vulnerabilities for maximum impact
  • Business logic flaw identification and exploitation
  • Program selection and scope analysis strategy
  • Automation with custom scripts and Nuclei templates
16

Professional Reporting & Career Launch

Finding bugs is half the job. Reporting, platforms, portfolio, and first clients.

  • Writing high-impact pentest reports
  • Bug bounty platforms: HackerOne, Bugcrowd, Intigriti
  • Building a portfolio that wins jobs and clients
  • Freelancing rates, proposals, and landing first clients
What you get

What comes with
every track

Non-IT backgrounds welcome

Zero experience required. We start from the very beginning.

Real-time Q&A

Ask questions live in every session, no waiting for a forum reply.

80% hands-on labs

Most of your time is spent inside actual tools, working on live targets.

Career direction

Freelancing, bug bounty, and internship paths are all covered.

120+ training hours

A structured curriculum where every module builds on the last.

Community support

An active Telegram group, with Hassan involved day to day.

Guided lab simulations

Scenarios modelled on engagements Hassan has actually run.

Structured pathway

Topics build on each other in a deliberate order.

Certificate on completion

A verifiable certificate for every track.

Apply

Apply for training

Fill in the form and Hassan will review your application personally. Most decisions go out within hours, always within 24. There's no auto-reject.

We look for seriousness, curiosity, and willingness to show up and practise, not prior experience. About 29% of applicants are accepted.

Preferred track *

Pricing: Batch Mentorship is ₹1,999/month for the 10-month program. 1:1 Mentorship is custom-priced, and you'll get an exact quote on a free 10-minute discovery call. Both are a fraction of what bootcamps charge for live mentorship from a practising penetration tester.

Applications are reviewed manually. Selection rate: 29%.

FAQ

Questions before you apply

Is the training suitable for beginners?

Yes. Our training is structured with beginner-to-advanced tracks. The batch mentorship starts from fundamentals and is designed for people with zero prior security experience. The 1:1 mentorship programme is customised to your current skill level and goals.

How many students are in each batch?

A maximum of 20 students per batch. This is a live, interactive cohort — not a passive video course. The 20-student cap ensures every student can ask questions, get personalised attention during sessions, and build real peer connections with motivated learners at the same stage.

Do sessions come with recordings?

Yes. Every live session is recorded and made available to enrolled students. This means you can revisit complex topics at your own pace, catch up if you miss a session (though attendance is strongly encouraged), and reference the material throughout your learning journey.

Can I join from any country?

Yes. Training is conducted online and students join from across South Asia, the Middle East, Europe, and beyond. Sessions are bilingual — English and Urdu/Hindi — to accommodate the broadest audience. All you need is a laptop and a stable internet connection.

How long does the batch mentorship programme last?

The full batch mentorship programme covers 16 modules over approximately 3–4 months, with live sessions 3 times per week — giving you 120+ hours of structured training. The 1:1 mentorship timeline is fully flexible, built around your personal goals and pace.

Do I receive a certificate on completion?

Yes. Students who complete all modules and assessments receive a verifiable certificate of completion from HackproofHacks. Combined with the practical skills and portfolio you build, this certificate is designed to support your job applications, freelance proposals, and bug bounty profiles.

What equipment do I need to join the training?

A laptop or desktop capable of running a virtual machine (Windows, macOS, or Linux) and a reliable internet connection. We guide you through setting up your hacking lab — Kali Linux, VirtualBox, and Burp Suite — in the very first module. No software or prior setup is required before day one.

Ready to apply?

Most decisions go out within hours. Next cohort starts August 2026, capped at 20 students.