AI-assisted bug bounty research
Use Hackcat to organize authorized bug bounty research, inspect Web and API behavior, and prepare findings with evidence you can verify.
Who this is for
For individual bug bounty hunters investigating an in-scope website or API. Hackcat helps turn a broad question into concrete checks and organize the observations. The researcher remains responsible for the program rules, impact assessment, and final submission.
What to provide
Provide the program scope, allowed hosts, prohibited techniques, and any rate limits. Include the specific behavior you want to investigate, relevant request and response samples, and test accounts you are permitted to use. Remove unrelated personal data and credentials from uploaded material.
Review with Ask mode
Use Ask mode to review a request, explain an authentication flow, compare responses, or develop a focused test hypothesis. Ask is useful when you want to reason about evidence before running checks; it does not establish that a vulnerability exists.
Execute with Agent mode
Use Agent mode for execution within the authorized scope. The Agent can discover relevant security tools, inspect their availability and documentation, run terminal or browser checks, and record findings. Tool selection and successful execution depend on the environment and the available permissions.
Choose an execution environment
A cloud sandbox suits reachable application endpoints. Connect a local or desktop environment when the target requires a VPN, an internal network, or your own files. State permitted request rates and stop conditions before active testing; cloud network restrictions can limit some scans.
Evidence and deliverables
Ask for affected endpoints, reproduction steps, request and response evidence, observed impact, and remediation. Review recorded findings and export the report where available. Reproduce important results independently and remove duplicates before submitting to the bounty program.
Limits and responsible testing
Hackcat cannot guarantee a valid finding, a bounty, or complete coverage. Automated output can contain false positives and miss application-specific logic. Do not test excluded assets, disrupt production, or access another person's data beyond the program's explicit authorization.