Playbooks
70 step-by-step methodologies with the exact tools and commands for each stage.
Playbooks index
- Full Recon Methodology - End-to-end attack-surface mapping: from a root domain to a prioritized list of live, interesting hosts.
- Subdomain Takeover - Find dangling DNS records pointing to de-provisioned cloud services you can re-claim.
- IDOR & Broken Access Control - Systematically test whether one user can reach another user's objects or actions.
- Account Takeover - Chain weaknesses in auth, reset, and session flows to seize another user's account.
- API Hunting Methodology - Discover, understand, and abuse API surface - usually where the real vulns hide.
- AI / LLM surface classification - Classify the AI surface first. A finding is an authority gap: a tool token wider than the tool, or another tenant's retrieved text. A prompt that only confuses the model is not the report. Use mcp-tool-trust and rag-document-trust for the test. OWASP LLM Top 10 (2025) is the category list.
- SSRF Hunting - Confirm the server requests a host you control. Cloud metadata is a later step, and only when the program allows it. In the 2025 OWASP list, SSRF sits under broken access control.
- HTTP Request Smuggling - Exploit disagreements between a front-end proxy and back-end server on where one request ends, to poison the connection of the next user.
- Web Cache Poisoning - An unkeyed input changes the response other users receive. That is poisoning. A private response stored at a URL the cache treats as static is deception, and it belongs on the cache-deception playbook. Report them separately.
- Prototype Pollution (client & server) - Inject properties into Object.prototype to change app behavior - client-side DOM XSS or server-side RCE via gadget chains.
- OAuth & SSO Misconfiguration - Abuse loose redirect and state handling in OAuth flows to steal tokens and take over accounts.
- JWT Attacks - Forge or tamper JSON Web Tokens by abusing weak verification.
- CORS Misconfiguration - Abuse permissive cross-origin policies to read authenticated responses from a victim's browser.
- XXE Injection - Abuse XML external entity parsing to read files, perform SSRF, or exfiltrate data out-of-band.
- File Upload to RCE - Turn a file upload into code execution by defeating type/extension checks.
- GraphQL Abuse - Enumerate and attack GraphQL: schema recovery, authorization gaps, and resource abuse.
- Race Conditions (single-packet attack) - Exploit small timing windows where the app checks-then-acts, to double-spend, bypass limits, or over-redeem.
- Business Logic Flaws - Break the intended rules of a workflow - the bugs scanners never find.
- Dependency Confusion & Supply Chain - Discover internal package names and (with authorization) demonstrate how a public look-alike could be pulled into builds.
- Git & CI/CD Secret Recon - Find leaked credentials and internal detail across code, git history, and exposed CI artifacts.
- Scaling: Automation & Monitoring - Move from one-off scans to continuous coverage that pings you when a target's attack surface changes.
- XSS Hunting (reflected, stored, DOM) - Find every reflection, name the context, then execute. XSS is a gadget until it reads a session, a token, or an admin UI.
- CSP Bypass - CSP is not the bug. It is the reason a reflection does not fire. Parse it, then look for a gadget on an allowed origin.
- postMessage & DOM gadgets - Map every message listener and every wildcard sender. SPA auth and payment widgets live and die here.
- WebSocket Hunting - Treat the socket as an API with a worse auth story. Handshake, first message, then every subscribe.
- Host Header & Password Reset Poisoning - If the app builds absolute URLs from the request Host, reset mails and caches become ATO.
- MFA / 2FA Bypass - MFA that is checked in the UI and not on the API is not MFA. Test skip, brute, race, and backup codes.
- Open Redirect Chains - Do not report the bounce. Report where the victim's code, token, or script execution goes.
- SSTI Hunting - A reflected ${7*7} is a gadget. Engine identification plus a sandbox escape is the report.
- LFI to RCE - File read is P3-P4. Wrappers, log poison, session files, and upload + include are how it becomes RCE.
- CSRF Hunting - State-changing requests that run as the victim from a foreign origin. JSON and SameSite made this rarer, not dead.
- SAML / SSO Attacks - SAML is XML plus cryptography plus a pile of libraries that disagree. Signature wrap and XXE still show up.
- SPA / Next.js / React Hunting - The HTML is a shell. Routes, server actions, and /_next/data are the app.
- Cache Key Analysis - Work out the key, then find something the origin uses that the key ignores.
- Clickjacking & XS-Leaks - Framable pages are inventory. A one-click sensitive action, or a leak of cross-origin state, is the report.
- Mass Assignment & Hidden Fields - Send the fields the UI never sends. The schema is the attack surface.
- Insecure Deserialization - A serialized blob in a cookie or parameter is a gadget. RCE depends on the classes in the classpath.
- Webhooks, Unfurl, PDF, Image SSRF - Every 'fetch this URL for me' feature is SSRF. Canary, then internal, then metadata.
- Writing a Report That Survives Triage - A finding that cannot be reproduced from the text is not a finding. Write for a tired triager on their third coffee.
- Firebase / Supabase Apps - The API key is supposed to be public. The bug is the rules, the open signup, and the data.
- Scope, Wildcards, and Intake - A beautiful bug on an out-of-scope host is a waste of a week. Parse the policy like it is code.
- Advanced JavaScript Analysis - Turn shipped JavaScript into a bounded, evidence-led map of client attack paths: collect only in-scope artifacts, recover source where exposed, trace controllable data to real sinks or authorization decisions, then validate the smallest safe chain.
- Back-office Renderer Sinks - Find attacker-controlled records that are rendered later in support, moderation, reporting, export, or admin workflows, then prove the smallest safe execution or sensitive-action path.
- Blind Command / Server-side OAST - Use controlled, callback-only discriminators to distinguish server-side processing from reflection and to establish a safe evidence trail for blind command or fetch hypotheses.
- Archive-to-Live Surface Delta - Compare historical public surface against the current authorized application to find live legacy routes, stale client artifacts, and security-relevant drift without treating archived content as live proof.
- SQL injection hunting - Treat SQLi as a query-shape bug, not a dump script. Boolean and error on an owned row, then OAST if it is blind. Stop before information_schema of other tenants.
- Cloud storage and public object hunting - Public buckets still pay, but only after you prove ownership. DNS, TLS SAN, response body, or a billing alias. Guessing a brand name is recon, not a report.
- CRLF / header injection - A parameter that lands in a response header or a backend request header is a split gadget. Prove a new header you control, then ask what it becomes.
- Exception paths and fail-open - OWASP Top 10:2025 A10 is mishandling of exceptional conditions: timeouts, empty bodies, parser failures, and error handlers that do a different job than the happy path. The bug is a state change that happens because something went wrong.
- Passkeys and WebAuthn - A passkey is an origin-bound credential. The finding is usually the path around it: recovery, a second factor that still mints a full session, or a registration that attaches a credential to the wrong account.
- OAuth PKCE, DPoP, and mix-up - Modern OAuth fails when the token endpoint does not require what the metadata advertises. PKCE (RFC 7636) and DPoP (RFC 9449) only help if a token is refused without the proof. Mix-up is a client that sends a code to the wrong token endpoint.
- Tenant isolation - A tenant is the boundary between organizations, not a label in the UI. The test is two organizations you are allowed to join, and which identifier the server actually trusts.
- Web cache deception - Cache deception stores a private response at a URL the cache thinks is static. It is not cache poisoning. Poisoning changes what other users receive. Deception discloses your own authenticated page to a second client that never logged in.
- Cookie and session binding - Decide which cookies are the session, then check scope, flags, and whether logout actually kills them. SameSite, the __Host- prefix, and Partitioned (CHIPS) are properties of that decision, not a checklist of headers.
- GitHub Actions trust - pull_request_target runs in the base repository, which can include secrets and a privileged token. It becomes dangerous when that workflow checks out pull request code and runs it. Describe the condition. Do not run untrusted code on a repository you are not allowed to test.
- MCP and agent tool trust - An MCP bug is a gap between the tool the user invoked and the authority the token actually has. A prompt trick without that gap is not the report.
- RAG document trust - Cross-tenant RAG is an authorization bug on retrieved chunks. If the index returns another tenant's text into a context you are allowed to see, the filter failed before the model spoke.
- Storage partitioning and XS-Leaks - Storage partitioning is real. A universal Chrome shutdown of third-party cookies is not: as of 2026 Chrome still sends them when the user allows them. Safari, Firefox, Incognito, and enterprise policy often block or partition them. An XS-Leak that needs a shared cookie jar has to be shown in a named browser.
- Reset and magic-link binding - A reset or magic link is a bearer token delivered through mail. The questions are who receives it, whether it is bound to a browser or session, and whether it can be used twice.
- App Links and Universal Links - HTTPS app links are a verified host claim. Android uses assetlinks.json. Apple uses apple-app-site-association. A custom scheme is usually unverified. The bug is an auth callback that accepts the weaker claim.
- GraphQL persisted queries - Automatic persisted queries and allow lists only help if an unknown operation is rejected. Authorization still has to run per field and per object after the hash is accepted.
- Exports and webhook authenticity - An export job and a webhook are both delayed authority. The job must stay bound to the account that created it. The webhook must fail when the signature is missing, and a signature check that throws must not fail open.
- Archive and document parsers - Archive and document parsers turn entry names and links into filesystem paths. An entry that resolves outside the extract root is the primitive. Impact starts when the service later reads or writes that path, on a file you created.
- Feature flags and hidden routes - A hidden button is not an authorization boundary. If the API still serves the route, the flag only hid the link.
- Inbound email and renderers - Inbound mail becomes a ticket, a comment, or HTML. The questions are who renders it, whether links are unfurled server-side, and whether the address the app stores is the address that received the mail.
- API schema drift - The published OpenAPI file and the live API drift apart. Old versions stay mounted. Docs reveal routes the UI never calls. Authorization still has to hold on the route you actually hit.
- Clickjacking and framing policy - A framed page is a finding only when a click still completes a state change. Read the framing headers, name the action, and stop. Do not publish a frame.
- Cloud metadata boundary - Metadata is not the first request. It is a later hop, and only after a callback you control has already shown that the server fetches a URL, and only when the program allows that hop.
- SCIM, directory sync, and invites - Provisioning bugs are authorization bugs on user creation. Compare two orgs you belong to. Do not create users in a tenant that is not yours.
- Billing, credits, and refunds - The price that counts is the one the server stores. Change one money field on an object you own, compare it with the ledger, and stop.