AI-assisted bug bounty research

Use Hackcat to organize authorized bug bounty research, inspect Web and API behavior, and prepare findings with evidence you can verify.

Who this is for

For individual bug bounty hunters investigating an in-scope website or API. Hackcat helps turn a broad question into concrete checks and organize the observations. The researcher remains responsible for the program rules, impact assessment, and final submission.

What to provide

Provide the program scope, allowed hosts, prohibited techniques, and any rate limits. Include the specific behavior you want to investigate, relevant request and response samples, and test accounts you are permitted to use. Remove unrelated personal data and credentials from uploaded material.

Review with Ask mode

Use Ask mode to review a request, explain an authentication flow, compare responses, or develop a focused test hypothesis. Ask is useful when you want to reason about evidence before running checks; it does not establish that a vulnerability exists.

Execute with Agent mode

Use Agent mode for execution within the authorized scope. The Agent can discover relevant security tools, inspect their availability and documentation, run terminal or browser checks, and record findings. Tool selection and successful execution depend on the environment and the available permissions.

Choose an execution environment

A cloud sandbox suits reachable application endpoints. Connect a local or desktop environment when the target requires a VPN, an internal network, or your own files. State permitted request rates and stop conditions before active testing; cloud network restrictions can limit some scans.

Evidence and deliverables

Ask for affected endpoints, reproduction steps, request and response evidence, observed impact, and remediation. Review recorded findings and export the report where available. Reproduce important results independently and remove duplicates before submitting to the bounty program.

Limits and responsible testing

Hackcat cannot guarantee a valid finding, a bounty, or complete coverage. Automated output can contain false positives and miss application-specific logic. Do not test excluded assets, disrupt production, or access another person's data beyond the program's explicit authorization.

Open HackcatHelp CenterConnect a local Agent