Workflows & Stacks
Copy-paste multi-tool pipelines and starter stacks that string the toolkit together.
Workflows & Stacks index
- Recon → live hosts → nuclei - The canonical bug-bounty one-liner: enumerate subdomains, resolve, probe live HTTP, and scan for known issues.
- URL corpus → XSS candidates - Collect historical URLs, filter for reflected-XSS-shaped params, inject a marker, and scan with dalfox.
- Content discovery on live hosts - Fuzz directories/files across every live host with a frequency-ordered wordlist.
- JS recon for endpoints & secrets - Crawl a target, pull JS files, and parse them for hidden endpoints and API routes.
- Ports → web services → scan - Scan for open ports, probe which speak HTTP, then run nuclei against those services.
- Historical URLs → gf → live probe - Pull historical URLs, canonicalise, pattern-grep, then only hit what is still alive.
- Subdomains → CNAME → takeover - Enumerate, extract CNAMEs, fingerprint dangling services. Verify by hand before you touch a claim.
- Exposed .git → dump → secrets - Confirm /.git/HEAD, dump the repo, scan history with verification.
- Live hosts → params → hidden keys - Harvest parameters from JS and history, then brute extra keys on the interesting endpoints.
- Find GraphQL → introspect → Cop - Locate the endpoint, dump the schema if allowed, then run the cheap automated checks.
- JS files → maps → sinks - Collect JS, restore source maps, run semgrep/jsluice. This is the SPA recon loop.
- Keyword → cloud_enum → httpx - Guess public buckets and cloud apps from the brand name, then probe what is actually HTTP.
- Candidate params → OAST canary - Take URL-shaped parameters, swap in an interactsh payload, watch for hits. Do not jump to metadata.
- API authorization matrix - Build a role-by-action matrix across two accounts you control. Test read and write operations separately, record expected policy, and use harmless records only.
- WebSocket channel authorization - Verify handshake origin, token binding, subscription authorization, and unsubscribe behavior using two test accounts. Subscribe only to channels and messages created for the assessment.
- Cloud DNS ownership - Inventory CNAMEs and cloud-service mappings, then distinguish an active tenant from a genuinely unclaimed resource. Never create or claim a third-party resource without written program permission.
- GraphQL operation boundaries - Map which queries and mutations each test role may execute, including object-level authorization and persisted-operation handling. Keep introspection and volume within the program's rules.
- Identity state machine - Model registration, verification, recovery, MFA, session refresh, logout, and account deletion as explicit states. Look for state transitions that grant more access than the prior state permits.
- JavaScript to API authorization - Trace client-side routes, feature flags, and request builders to the APIs they call, then validate server enforcement with controlled roles. A hidden UI is not an authorization boundary.
- Mobile API and deep-link boundaries - Map deep links to their app routes and API calls, then test validation of host, path, parameters, and login state in an emulator with accounts you control. Avoid testing links delivered to real users.
- Owned-row SQLi discriminator - Boolean/error probe on a record you created, then a unique canary. No tenant dumps, no --batch spray.
- Two-account object replay - Capture object IDs as A, replay as B across GET/PUT/DELETE, batch, and GraphQL node(id). The pipeline is a notebook, not a scanner.
- URL corpus to CRLF header probe - Take a focused live URL list, probe encoded CRLF, keep only responses that echo a unique header you set.
- Two-org tenant replay - Decide which tenant identifier the server trusts by replaying objects you own across two organisations.
- Passkey and recovery map - Decide whether recovery can mint a session that the passkey ceremony would not have issued on its own.
- Session cookie inventory - Decide which cookies are the session and whether logout, rotation, and scope match that decision.
- Cache deception on a static-looking path - Decide whether a private response is stored and later served to a second client that never authenticated.
- OAuth PKCE and DPoP notes - Decide whether the advertised PKCE and DPoP requirements match what the token endpoint enforces on a login you complete.
- OpenAPI versus live routes - Decide which documented operations exist, which live operations are undocumented, and whether those live calls enforce the same ownership checks as the UI.
- App link statement read - Decide whether the published app association matches the hosts and paths the installed app actually opens.
- Export job ownership - Decide whether an export job, its file, and its status are bound to the account that created them.