Security testing use cases

Explore practical Hackcat workflows for authorized bug bounty research, Web and API testing, and smart contract security review.

Start with the question you need to answer and the assets you are allowed to test. These guides show where Ask mode helps you reason about a problem and where Agent mode can execute checks, collect evidence, and prepare a report.

Set the boundaries before you start

Share the authorized scope, exclusions, permitted request rates, and expected behavior. Provide only the files and test accounts needed for the task. A specific goal makes it easier to choose relevant tools and interpret their results.

Choose a workflow you can verify

Ask mode is useful for reviewing code, documentation, or observations. Agent mode adds terminal and browser execution in a supported cloud or connected local environment. The Agent should inspect a selected tool's actual availability and documentation before using it; a catalog entry alone does not prove the tool is installed or functional.

Review the evidence

Check preconditions, reproduction steps, outputs, and the claimed impact. Separate confirmed findings from hypotheses. Export a report where available and reproduce important results independently. A clean scan or an AI explanation cannot guarantee that a system is secure.

Open HackcatHelp CenterConnect a local Agent