Browse Skills
11972 skills across 8 categories
🐞
2026/08/16
Bug Bounty Methodology
Bug Bounty Methodology orchestrates bug bounty hunting sessions by combining a five-phase non-linear workflow with critical thinking tactics like developer psychology, anomaly detection, and what-if experiments to decide next steps.
Quality
3.6K559
🐞
2026/08/16
Bugcrowd Reporting
Bugcrowd Reporting provides Bugcrowd-specific submission tactics for VRT category selection, manual severity overrides, OOS-clause rebuttals, and chained-finding cross-references. Use it when filing Bugcrowd reports or responding to triage decisions.
Writing
3.6K559
🐞
2026/08/16
Business Logic Hunter
Business Logic Hunter identifies business logic vulnerabilities in web applications, covering price tampering, coupon stacking, verification bypass, and rate limit abuse. Use it when hunting for financial-impact bugs in e-commerce, SaaS, and payment platforms.
Quality
3.6K559
☠️
2026/08/16
Cache Poison Hunter
Cache Poison Hunter finds cache poisoning and web cache deception vulnerabilities in CDN-fronted apps, using techniques like unkeyed header reflection and path confusion to poison cached responses or steal dynamic content.
Quality
3.6K559
🔍
2026/08/16
CAPTCHA Bypass Hunter
CAPTCHA Bypass Hunter identifies CAPTCHA validation weaknesses such as omitted fields, replayable tokens, and missing server-side checks. Use it during security testing to find bypasses that enable brute force, account farming, or automated abuse.
Quality
3.6K559
🔐
2026/08/16
Cloud IAM Attack Chains
Cloud IAM Attack Chains analyzes cloud IAM credentials and privilege paths across AWS, Azure, and GCP to determine what access a credential grants and how to escalate. Use it after discovering an AWS key, Azure secret, GCP service account JSON, or K8s SA token from a code repo, JS bundle, APK, or SSRF chain.
DevOps
3.6K559
🔍
2026/08/16
Cloud Misconfig Hunter
Cloud Misconfig Hunter searches for misconfigurations in AWS, GCP, and Azure cloud services, including public S3 buckets, exposed CloudFront origins, public Lambda function URLs, and leaked IAM credentials in JavaScript bundles. It validates findings by attempting actual data read/write or remote code execution, and is used during bug bounty and penetration testing engagements.
DevOps
3.6K559
🐞
2026/08/16
DOM Vulnerability Hunter
DOM Vulnerability Hunter finds and exploits client-side DOM vulnerabilities such as DOM clobbering, PostMessage misconfigurations, service worker abuse, and CSS exfiltration. Use it when auditing web applications for DOM XSS, client-side auth bypass, or token theft without server-side interaction.
Quality
3.6K559
🔓
2026/08/16
Enterprise VPN Attack
Enterprise VPN Attack catalogs fingerprinting methods and CVEs for SSL VPN/remote-access appliances such as Cisco ASA/AnyConnect, Fortinet, Citrix, Palo Alto, Pulse Secure, SonicWall, and F5. Use it when a perimeter exposes an SSL VPN gateway to test pre-auth RCE, SSRF, path traversal, and default credentials.
Quality
3.6K559
🛡️
2026/08/16
Evidence Hygiene
Evidence Hygiene guides redaction of cookies, PII, and HAR files in bug-bounty evidence capture, ensuring sessions and user data are protected before screenshots or attachments are shared. Use it before any PoC capture to avoid leaking secrets.
AI Engineering
3.6K559
🐛
2026/08/16
Exceptional Conditions Hunter
Exceptional Conditions Hunter probes web endpoints with malformed or unexpected input to surface verbose error pages, stack traces, and internal file paths or library versions. Use it when testing APIs, forms, or query parameters for error-disclosure vulnerabilities.
Quality
3.6K559
🕵️
2026/08/16
Hunt ASP.NET
Hunt ASP.NET detects ASP.NET Webforms, WCF, and SharePoint attack surfaces such as ViewState deserialization, machineKey recovery, and trace.axd/elmah.axd disclosure to find high-value vulnerabilities in bug bounty programs.
Quality
3.6K559