Skip to content

Workflow

Bug bounty rewards finding and reporting vulnerabilities in programs with a defined scope. Unlike a pentest with fixed time and objectives, here you compete with many hunters and get paid by impact. A repeatable workflow is what separates the one who finds bugs from the one who gets lost exploring aimlessly.

1. CHOOSE a program broad, active scope vs mature/competed (see bb-plataformas)
2. READ the scope what's in/out and the rules (CRITICAL, see bb-scope)
3. RECON map the whole surface (subdomains, apps, APIs; see bb-recon)
4. ANALYSIS understand the app, its logic, and its technology
5. HUNT test by vuln class, prioritizing by impact
6. VALIDATE confirm and scope the impact; reproducible PoC
7. REPORT a clear, actionable report (see bb-reporte)
8. FOLLOW-UP respond to triage, defend the severity
- business logic (bb/web-logic): hard to automate, high value, less competition
- access control: IDOR/BOLA (web-api) -> among the most rewarded and common
- "forgotten" assets: old subdomains, acquisitions, undocumented APIs (bb-recon)
- new/recent functionality: fewer eyes on it
- what mass automation does NOT find (that's where the money and less noise are)
Breadth lots of recon + mass scanning -> "low-hanging" bugs (heavily competed)
Depth pick a few targets and understand them deeply -> logic, chains, high impact
# the best hunters combine: broad recon to find forgotten surface
# + depth on the promising targets
Recon subfinder, amass, httpx, nuclei (see bb-recon, tool-nuclei)
Proxy Burp Suite (the work hub, see tool-burp)
Fuzzing ffuf (see tool-ffuf) for hidden content/parameters
Notes document EVERYTHING (tested, pending) -> don't repeat or get lost
  • Always work within scope and rules (Reading the scope & rules); going out can be a crime and a ban.
  • Chain tools into a repeatable workflow; document to avoid repeating work.
  • Prioritize by impact and by what mass automation doesn’t see (logic, access).
  • Persistence: bug bounty is intermittent; consistency and method win.
  • Prioritize hard-to-automate classes (IDOR/BOLA, business logic): that’s where bots can’t reach and payouts are higher.
  • Don’t stay on the surface: document recon assets and revisit them; many bugs hide in the forgotten ones.
  • Common mistake: blindly running scanners and reporting their output; duplicates and noise burn your reputation.
  • Choose a program fitting your style (broad vs mature)
  • Read scope and rules thoroughly (Reading the scope & rules)
  • Full recon of the surface (Recon automation)
  • Understand the app before attacking (technology, logic)
  • Hunt prioritizing by impact (logic, access)
  • Validate with a reproducible PoC and scope the impact
  • Clear, actionable report (Writing a good report)
  • Document everything to avoid repeating or getting lost