Turn signals into findings.
Move from an unusual behavior to a falsifiable hypothesis, the lowest-impact test, and evidence that holds up in a report.
Choose the path that matches the work.
No need to know which internal content type you need first.
I observed something unusual
Turn application behavior into hypotheses, safe tests, and evidence requirements.
I want to test a vulnerability class
Open a repeatable playbook with preconditions, variants, false positives, and tools.
I want to study real disclosures
Explore normalized security reports by technique, technology, impact, and chain.
Go deep on a technique.
View all 21 playbooks →IDOR & broken access control
Object ownership, cross-account evidence, identifier discovery, and reporting.
Intermediate → 02 / Server-sideSSRF hunting
URL consumers, parser behavior, OOB confirmation, and cloud metadata boundaries.
Advanced → 03 / API securityGraphQL abuse
Schema discovery, authorization gaps, batching, aliases, and complexity controls.
Intermediate → 04 / IdentityOAuth & SSO
State handling, redirect validation, token binding, and account-linking flaws.
Advanced →Build the next safe test.
Target-aware commands with placeholders, context, and source links.