Generate an attack briefing for an authorized bug bounty program
Quand l'utiliser : You're starting work on a new bug bounty target and want a strategic overview.
Prérequis
- HackerOne API token — Generate at hackerone.com/settings/api_token
- h1-brain installed and databases populated — Clone, install, run fetch_rewarded_reports to populate personal DB
Déroulement
-
Generate the briefinghack('target-company') — Generate a full attack briefing for this program.✓ Copié→ Comprehensive briefing with scope, known weakness patterns, untouched assets, and suggested attack vectors
-
Cross-reference with disclosuresSearch disclosed reports for this company. What vulnerability types have been found before?✓ Copié→ List of disclosed vulnerabilities with types and bounty amounts
Résultat : A strategic attack plan based on historical data and current scope.
Pièges
- Stale scope data — The tool fetches fresh scope from HackerOne API, but verify on the program page