Bug bounty field index.
Search tools, playbooks, public program scope, disclosed reports, payload classes, workflows, and learning resources for authorized research.
Type two or more characters. Results stay on this page until you choose one.
Name the thing in front of you.
The index routes from the observation, not the content type.
A response I cannot explain
Work backward through state, parser, identity, and trust boundaries.
A class I want to pressure-test
Open the preconditions, controls, variants, and stop conditions.
A public bug I need to understand
Classify the failure and product lane, then read severity, EPSS, KEV, and ransomware evidence as separate facts.
Four common ways trust falls apart.
View all 21 playbooks →IDOR & broken access control
Object ownership, cross-account evidence, identifier discovery, and reporting.
Intermediate → 02 / Server-sideSSRF hunting
URL consumers, parser behavior, OOB confirmation, and cloud metadata boundaries.
Advanced → 03 / API securityGraphQL abuse
Schema discovery, authorization gaps, batching, aliases, and complexity controls.
Intermediate → 04 / IdentityOAuth & SSO
State handling, redirect validation, token binding, and account-linking flaws.
Advanced →Choose the tool after the question.
Command templates, placeholders, operating context, and source links.