Hunt Checklists
10 checklists. Tick through them on a live target instead of rereading a blog.
Hunt Checklists index
- First hour on a new program - Do this before you fire nuclei. Most wasted hunts skip the paper.
- JavaScript review - Treat the frontend as source. Most P1s on modern apps start here.
- Authorization / IDOR - If you only have one account you are guessing. Two accounts is the test.
- Authentication / ATO - Account takeover is a chain. Inventory every step of how an identity becomes a session.
- SSRF - Canary first. Metadata second. File handlers last.
- XSS - Marker first. Context second. Execute third. Cookie/CSP last.
- API / GraphQL - The UI is a subset of the schema. Hunt the schema.
- Cache - Two clients. One poisons. The other must receive it.
- Before you submit - Skeptic pass. If you cannot kill your own finding, the triager will.
- Cloud / SaaS extras - Public buckets and metadata still pay. Most of the work is proving it is theirs.