Bug bounty
Complete bug bounty workflow
Skills for your AI
Complete bug bounty workflow
Bugcrowd-specific reporting tactics complementing report-writing
Develop business continuity plans and impact analysis. Implement BCP testing and communication procedures. Use when building organizational resilience.
Implement change management processes. Configure CAB reviews, change windows, and rollback procedures. Use when managing production changes.
Audit and remediate CIS benchmark violations.
Cloud IAM red-team attack chain across AWS, Azure, GCP
Secure Docker images and container runtime configurations.
Scan container images for vulnerabilities using Trivy, Grype, and cloud-native tools.
Perform dynamic application security testing with OWASP ZAP, Burp Suite, and Nikto.
Scan package dependencies for known vulnerabilities using Snyk, Dependabot, and OWASP Dependency-Check.
Implement disaster recovery strategies and runbooks. Configure RPO/RTO targets and failover procedures. Use when planning for business continuity.
External SSL VPN / remote-access appliance attack matrix
Evidence-capture and PoC-redaction discipline for bug-bounty submissions
Implement FedRAMP requirements for federal cloud services. Configure NIST 800-53 controls and continuous monitoring. Use when providing cloud services to US federal agencies.
Configure iptables, nftables, and cloud firewalls. Implement network segmentation and traffic filtering. Use when securing network perimeters or implementing security zones.
Configure GCP Cloud Audit Logs for compliance. Set up log routing and BigQuery analysis. Use when auditing GCP activity.
Secure secrets in Google Cloud Secret Manager. Configure IAM policies, integrate with GKE, and manage secret versions. Use when managing secrets in GCP environments.
Implement GDPR data protection requirements. Configure consent management, data subject rights, and privacy by design. Use when processing EU personal data.
Technical SEO audit with GEO-specific checks — crawlability, indexability, security, performance, SSR, and AI crawler access
Manage secrets and PKI with HashiCorp Vault.
Implement HIPAA security and privacy rules. Configure PHI protections and BAA requirements. Use when handling healthcare data.
Hunt API security misconfiguration
Hunt ASP.NET-specific surface
Hunt account takeover taxonomy