| 01 | SQLi Hunter SQL and NoSQL injection across ORM raw fragments, GraphQL resolvers, OIDC-p... | /hunt-sqli | web-hunting | both | 12 | VIEW → |
| 02 | XSS Hunter Cross-site scripting across DOM, reflected, stored, and mutation-based patt... | /hunt-xss | web-hunting | both | 174 | VIEW → |
| 03 | SSRF Hunter Server-side request forgery including cloud metadata endpoint exfiltration,... | /hunt-ssrf | web-hunting | both | — | VIEW → |
| 04 | RCE Hunter Remote code execution via deserialization, template injection, command inje... | /hunt-rce | web-hunting | both | — | VIEW → |
| 05 | IDOR Hunter Insecure direct object references including BOLA in REST/GraphQL, ID enumer... | /hunt-idor | web-hunting | both | 26 | VIEW → |
| 06 | CSRF Hunter Cross-site request forgery including SameSite bypass, token fixation, and J... | /hunt-csrf | web-hunting | both | — | VIEW → |
| 07 | SSTI Hunter Server-side template injection across Jinja2, Twig, Freemarker, Velocity, a... | /hunt-ssti | web-hunting | both | — | VIEW → |
| 08 | XXE Hunter XML external entity injection including blind OOB exfiltration, file read v... | /hunt-xxe | web-hunting | both | — | VIEW → |
| 09 | File Upload Hunter Unrestricted file upload bypasses — MIME type spoofing, extension trickery,... | /hunt-file-upload | web-hunting | both | — | VIEW → |
| 10 | Cache Poison Hunter Web cache poisoning via unkeyed headers, parameter cloaking, fat GET exploi... | /hunt-cache-poison | web-hunting | both | — | VIEW → |
| 11 | HTTP Smuggling Hunter HTTP request smuggling — CL.TE, TE.CL, TE.TE variants with bypass and respo... | /hunt-http-smuggling | web-hunting | code | — | VIEW → |
| 12 | Race Condition Hunter Race condition exploitation on payment flows, coupon redemption, rate-limit... | /hunt-race-condition | web-hunting | code | — | VIEW → |
| 13 | Business Logic Hunter Business logic flaws — price manipulation, workflow bypass, state machine a... | /hunt-business-logic | web-hunting | both | — | VIEW → |
| 14 | GraphQL Hunter GraphQL introspection abuse, batching attacks, IDOR through aliases, nested... | /hunt-graphql | web-hunting | both | — | VIEW → |
| 15 | LLM/AI Hunter LLM-integrated application vulnerabilities — prompt injection, insecure too... | /hunt-llm-ai | web-hunting | both | — | VIEW → |
| 16 | Dispatch Hunter Smart target triage and hunting path dispatch — routes to the right skill b... | /hunt-dispatch | web-hunting | code | — | VIEW → |
| 17 | Misc Vuln Hunter Catch-all for open redirect, CRLF injection, clickjacking, host header inje... | /hunt-misc | web-hunting | both | — | VIEW → |
| 18 | ASP.NET Hunter ASP.NET-specific attack surface — ViewState deserialization, __EVENTTARGET ... | /hunt-aspnet | web-hunting | both | — | VIEW → |
| 19 | Bug Bounty Planner Structured methodology for scoping, prioritizing, and executing a bug bount... | /bug-bounty | web-hunting | both | — | VIEW → |
| 20 | BB Methodology End-to-end bug bounty methodology — recon, attack surface mapping, vulnerab... | /bb-methodology | web-hunting | both | — | VIEW → |
| 21 | Local Toolkit Local toolchain setup for bug bounty — ffuf, nuclei, sqlmap, burp configura... | /bb-local-toolkit | web-hunting | code | — | VIEW → |
| 22 | Security Arsenal Curated command arsenal for web security testing — one-liner reference for ... | /security-arsenal | web-hunting | both | — | VIEW → |
| 23 | OAuth Hunter OAuth 2.0 and OIDC vulnerabilities — CSRF on redirect_uri, state fixation, ... | /hunt-oauth | auth | both | 19 | VIEW → |
| 24 | ATO Hunter Account takeover chains — password reset poisoning, username enumeration, t... | /hunt-ato | auth | both | — | VIEW → |
| 25 | Auth Bypass Hunter Authentication bypass — JWT alg=none, weak HMAC secrets, path traversal in ... | /hunt-auth-bypass | auth | both | — | VIEW → |
| 26 | MFA Bypass Hunter Multi-factor authentication bypass — code reuse, race conditions on OTP val... | /hunt-mfa-bypass | auth | both | — | VIEW → |
| 27 | SAML Hunter SAML SSO vulnerabilities — signature wrapping, XML comment injection, NameI... | /hunt-saml | auth | both | — | VIEW → |
| 28 | API Misconfig Hunter API security misconfiguration — mass assignment, JWT attacks, prototype pol... | /hunt-api-misconfig | api-infra | both | — | VIEW → |
| 29 | Cloud Misconfig Hunter Cloud storage and service misconfiguration — S3 bucket ACL, GCS bucket enum... | /hunt-cloud-misconfig | api-infra | both | — | VIEW → |
| 30 | GraphQL Deep Dive GraphQL security deep dive — introspection bypass, batching amplification, ... | /hunt-graphql | api-infra | both | — | VIEW → |
| 31 | NTLM Info Hunter NTLM information disclosure — internal hostname/domain leak via 401 challen... | /hunt-ntlm-info | api-infra | code | — | VIEW → |
| 32 | Cloud IAM Deep Cloud IAM attack chains across AWS, Azure, GCP — STS/AssumeRole chaining, M... | /cloud-iam-deep | enterprise | both | 6 | VIEW → |
| 33 | M365/Entra Attack Microsoft 365 and Entra ID attack surface — OAuth app consent phishing, tok... | /m365-entra-attack | enterprise | both | — | VIEW → |
| 34 | Okta Attack Okta attack patterns — password spray against admin portal, impersonation A... | /okta-attack | enterprise | both | — | VIEW → |
| 35 | SharePoint Hunter SharePoint and OneDrive attack surface — anonymous file access, OOTB webpar... | /hunt-sharepoint | enterprise | both | — | VIEW → |
| 36 | Enterprise VPN Attack Enterprise VPN attack surface — Pulse Secure, Fortinet, Cisco AnyConnect pr... | /enterprise-vpn-attack | enterprise | both | — | VIEW → |
| 37 | VMware vCenter Attack VMware vCenter attack chain — CVE-2021-21985, CVE-2021-22005 pre-auth RCE, ... | /vmware-vcenter-attack | enterprise | both | — | VIEW → |
| 38 | APK Red-Team Pipeline End-to-end Android APK red-team — automated acquisition, jadx decompilation... | /apk-redteam-pipeline | red-team | code | 1 | VIEW → |
| 39 | Supply Chain Recon Supply chain attack reconnaissance — dependency confusion targets, npm/PyPI... | /supply-chain-attack-recon | red-team | both | — | VIEW → |
| 40 | IR Detection Awareness Mid-engagement IR detection signals — EDR telemetry patterns, SIEM correlat... | /mid-engagement-ir-detection | red-team | both | — | VIEW → |
| 41 | Red Team Mindset Red team cognitive framework — objective-first thinking, OPSEC discipline, ... | /redteam-mindset | red-team | both | — | VIEW → |
| 42 | OSINT Methodology 5-stage recon pipeline with 29 asset types, identity-fabric mapping (Entra/... | /osint-methodology | recon | both | — | VIEW → |
| 43 | Offensive OSINT Offensive OSINT techniques for authorized red-team engagements — breach cor... | /offensive-osint | recon | both | — | VIEW → |
| 44 | Subdomain Hunter Subdomain enumeration and takeover identification — passive/active discover... | /hunt-subdomain | recon | code | — | VIEW → |
| 45 | Triage Validation 7-Question Gate pre-submission workflow — 4 pre-submission gates, always-re... | /triage-validation | reporting | both | — | VIEW → |
| 46 | Report Writing Bug bounty report writing for H1/Bugcrowd/Intigriti/Immunefi — impact-first... | /report-writing | reporting | both | — | VIEW → |
| 47 | Evidence Hygiene Evidence collection and hygiene — screenshot standards, video PoC requireme... | /evidence-hygiene | reporting | both | — | VIEW → |
| 48 | Bugcrowd Reporting Bugcrowd-specific report templates, VRT alignment, P1–P5 severity mapping, ... | /bugcrowd-reporting | reporting | both | — | VIEW → |
| 49 | Red Team Report Executive and technical red team report template — attack narrative, kill c... | /redteam-report-template | reporting | both | — | VIEW → |
| 50 | Web3 Smart Contract Audit Smart contract security audit — 10 DeFi bug classes, Foundry PoC template, ... | /web3-audit | specialized | both | — | VIEW → |
| 51 | Meme Coin Audit Meme coin and low-TVL token audit — rug-pull pattern detection, honeypot id... | /meme-coin-audit | specialized | both | — | VIEW → |