Professional Certificate in Vulnerability Research & Responsible Disclosure
The research profession done properly: authorization, isolated labs, minimal evidence, severity you can justify, and coordinated disclosure that gets flaws fixed.
Tuition
$499
Advanced
Level
6
Modules
30
Lessons
6
Graded quizzes
1
Assignments
15 hours
Estimated time
What you will be able to do
- Establish authorization and scope before any testing begins
- Build an isolated lab that cannot reach anything real
- Analyze a weakness and capture the minimum evidence that proves it
- Assess and justify severity honestly
- Run coordinated disclosure and the CVE process to a fixed flaw
What is inside
6 modules, 30 lessons. Each module ends in a graded quiz and most carry an assignment.
- 01
The Vulnerability Research Profession
What vulnerability researchers actually do, where they work, and why the profession exists at all. This module separates research from penetration testing and red teaming, fixes the vocabulary of weakness, vulnerability, exploit, and proof of concept so you can use each word precisely, explains who benefits when a flaw is found and reported well, and sets out the ethical spine and the legal and reputational stakes that govern the work. Taught through Aperture Systems, a fictional mid size software vendor, and Kestrel Logistics, the fictional freight and warehousing company that runs Aperture Relay and employs the analyst you will follow.
5 lessons · 15 quiz questions
- 02
Authorization, Law and Ethics
Authorization is the single line that separates vulnerability research from a criminal offense, and it has to exist in writing before the first request is sent. This module teaches how authorization is granted and by whom, how to read a scope document, bug bounty terms and safe harbor language with a professional eye, what computer misuse law looks like at a concepts level in the United States and the United Kingdom, what to do when a finding lands outside scope or a response contains real personal data, how to think about disclosure timing, and the specific moments when a researcher should stop and involve a lawyer. Taught through Amara Boateng, a junior researcher at Kestrel Logistics, and Aperture Systems, the fictional mid size software vendor whose product Kestrel runs.
5 lessons · 15 quiz questions
- 03
Building a Safe Research Lab
The working environment that makes vulnerability research defensible. Covers isolation as a first principle and why research never touches production or anything reachable from it, designing an isolated environment around a known good state and disciplined snapshots, obtaining your own licensed copy of software through legitimate routes and reading the terms that govern it, documenting the exact environment so a vendor can reproduce what you saw, synthetic data discipline and the traps that let real data leak into a lab, and the operational hygiene that keeps personal research cleanly separate from employer systems. Taught through Amara Boateng, a career changer researching Aperture Relay, a document routing and partner file exchange platform made by the fictional software vendor Aperture Systems and run in production by her employer, Kestrel Logistics.
5 lessons · 15 quiz questions
- 04
Research Methodology and Analysis
The working method of a vulnerability researcher: forming a testable hypothesis about where a system is likely to be weak, reading documentation and configuration surfaces to map trust boundaries, understanding the major classes of weakness at a conceptual level so you can recognize them, using automated discovery such as fuzzing as a concept rather than a magic button, keeping notes that make a finding reproducible, and deciding honestly whether what you are looking at is a real security finding at all. Taught through Aperture Systems, a fictional mid size software vendor whose product Aperture Relay is run by the student's employer, Kestrel Logistics, and through a lab instance the student is explicitly authorized to test. This module deliberately teaches weakness classes as what goes wrong and why it matters, never as operational attack instruction.
5 lessons · 15 quiz questions
- 05
Triage, Severity and Writing It Up
The stretch of work between noticing something odd and sending a report is where researchers earn or lose their reputation. This module teaches confirmation, so you never send a finding that turns out to be an artifact of your own lab; preconditions and realistic impact, so you can say who could do this and what they would get; honest severity scoring with a recognized system, including how to justify each metric and how to disagree with a vendor without theatrics; the minimum evidence principle, which proves an issue without collecting data you have no business holding; and the technical report itself, structured so an engineer at Aperture Systems can act on it, in a tone that produces a patch rather than a call to their legal team. Taught through Aperture Systems, a fictional mid size software vendor whose document routing and partner file exchange platform, Aperture Relay, your employer runs in production.
5 lessons · 15 quiz questions
- 06
Coordinated Disclosure, CVE and Your Research Career
The final module takes a validated finding and walks it all the way to a fixed product and a public advisory. You will run the coordinated disclosure process end to end, find a security contact when a vendor appears to have none, understand what a security.txt file is for and what it does not grant you, set and hold a defensible timeline, handle a silent, defensive or hostile vendor without losing your footing, escalate through a national coordination body when the direct route fails, request an identifier from a CVE Numbering Authority, write a public advisory that an administrator can act on in ten minutes, and build a research reputation through bug bounty work and a portfolio that hiring managers can verify. Taught through Aperture Systems, a fictional mid size software vendor whose product Aperture Relay your employer, Kestrel Logistics, runs in production. This module carries the course capstone.
5 lessons · 15 quiz questions · assignment