Documentation
README
Hunting Methodology
The 5-Phase Non-Linear Workflow
Phase 1: Understand the Target (before touching anything)
- Read program scope, policy, safe harbor
- Read 5+ disclosed reports in hacktivity
- Map crown jewels: what would hurt the company most?
- Understand the business domain — what features handle money, PII, auth?
Phase 2: Map the Surface
- Subdomain enumeration → live hosts → tech stack detection
- JS bundle analysis → API endpoints, secrets, internal URLs
- Run
/surfacefor P1/P2/Kill ranking
This is the opening of the README. Read the full README on GitHub.