Workflow
Bug bounty rewards finding and reporting vulnerabilities in programs with a defined scope. Unlike a pentest with fixed time and objectives, here you compete with many hunters and get paid by impact. A repeatable workflow is what separates the one who finds bugs from the one who gets lost exploring aimlessly.
The hunter’s cycle
Section titled “The hunter’s cycle”1. CHOOSE a program broad, active scope vs mature/competed (see bb-plataformas)2. READ the scope what's in/out and the rules (CRITICAL, see bb-scope)3. RECON map the whole surface (subdomains, apps, APIs; see bb-recon)4. ANALYSIS understand the app, its logic, and its technology5. HUNT test by vuln class, prioritizing by impact6. VALIDATE confirm and scope the impact; reproducible PoC7. REPORT a clear, actionable report (see bb-reporte)8. FOLLOW-UP respond to triage, defend the severityWhere to look (prioritize by impact)
Section titled “Where to look (prioritize by impact)”- business logic (bb/web-logic): hard to automate, high value, less competition- access control: IDOR/BOLA (web-api) -> among the most rewarded and common- "forgotten" assets: old subdomains, acquisitions, undocumented APIs (bb-recon)- new/recent functionality: fewer eyes on it- what mass automation does NOT find (that's where the money and less noise are)Depth vs breadth
Section titled “Depth vs breadth”Breadth lots of recon + mass scanning -> "low-hanging" bugs (heavily competed)Depth pick a few targets and understand them deeply -> logic, chains, high impact# the best hunters combine: broad recon to find forgotten surface# + depth on the promising targetsTools (chained)
Section titled “Tools (chained)”Recon subfinder, amass, httpx, nuclei (see bb-recon, tool-nuclei)Proxy Burp Suite (the work hub, see tool-burp)Fuzzing ffuf (see tool-ffuf) for hidden content/parametersNotes document EVERYTHING (tested, pending) -> don't repeat or get lostBlue Team / ethical note
Section titled “Blue Team / ethical note”- Always work within scope and rules (Reading the scope & rules); going out can be a crime and a ban.
- Chain tools into a repeatable workflow; document to avoid repeating work.
- Prioritize by impact and by what mass automation doesn’t see (logic, access).
- Persistence: bug bounty is intermittent; consistency and method win.
Best practices and common mistakes
Section titled “Best practices and common mistakes”- Prioritize hard-to-automate classes (IDOR/BOLA, business logic): that’s where bots can’t reach and payouts are higher.
- Don’t stay on the surface: document recon assets and revisit them; many bugs hide in the forgotten ones.
- Common mistake: blindly running scanners and reporting their output; duplicates and noise burn your reputation.
Testing checklist
Section titled “Testing checklist”- Choose a program fitting your style (broad vs mature)
- Read scope and rules thoroughly (Reading the scope & rules)
- Full recon of the surface (Recon automation)
- Understand the app before attacking (technology, logic)
- Hunt prioritizing by impact (logic, access)
- Validate with a reproducible PoC and scope the impact
- Clear, actionable report (Writing a good report)
- Document everything to avoid repeating or getting lost