
Bb Methodology (Grade A)Security-tested testing-security skill for Claude AI. Grade A. Use at the START of any bug bounty hunting session, when switching targets, or when feeling lost about what to do next. Master orchestrat
Overview
Key features
- 5-phase non-linear hunting workflow
- Critical thinking framework
- Developer psychology integration
- Anomaly detection guidance
- What-If experiments for scenario planning
- Engagement type confirmation process
Pricing
- Model
- Free
- Category
- Skills
- Rating
- No reviews yet
Use cases
Starting a Bug Bounty Hunting Session
Use the Bb Methodology at the start of a bug bounty hunting session to ensure a structured approach and to confirm the engagement type.
Switching Targets
Apply the Bb Methodology when switching targets to quickly adapt and focus on the new target's specific vulnerabilities and attack scenarios.
Overcoming a Hunting Stalemate
Use the Bb Methodology when feeling lost about what to do next to regain focus and direction in the hunting process.
Pros & Cons
Pros
- Combines a structured 5-phase workflow with critical thinking for effective bug hunting
- Helps hunters think like attackers with specific goals, improving the quality of findings
- Emphasizes the importance of confirming engagement type to ensure accurate reporting
- Provides a clear framework for defining targets, selecting vulnerability classes, and executing tests
Cons
- Requires a significant shift in mindset for hunters used to pattern-based scanning
- May be complex for beginners to fully grasp and apply effectively
Reviews
Sign in to leave a review.
No reviews yet. Be the first!
Q&A
Why this exists?
Most bug-hunting Claude setups are either too generic (one big "security" prompt) or too fragmented (you bookmark 30 disclosed reports and re-read them every engagement). Neither scales past the second target. This bundle was built and validated through authorized engagements that exposed different capability gaps: Bug-bounty engagement — surfaced four gaps a starter 3-skill stack could not close: 1. No hypothesis discipline — drafts written before validation → wasted hours, hurt validity ratio 2. No per-program reporting tactics — VRT defaults auto-downgraded P3-worthy findings to P4 3. No engagement coordination — findings, evidence, and submission IDs scattered across folders 4. No evidence hygiene — screenshots leaked cookies and victim PII External red-team engagement — exposed five additional gaps that bug-bounty defaults made worse: 1. Conservative defaults retracted real findings — WAPT mindset stopped tests early on defended targets where red-team continuation would have surfaced bypass chains → redteam-mindset 2. No mid-engagement situational awareness — client SOC patched confirmed SQLi within 30 min; external attacker locked 14 accounts during a live test session — both invisible without explicit detection methodology → mid-engagement-ir-detection 3. No enterprise-platform attack chains — M365 + Entra ID, on-prem SharePoint, Cisco SSL VPN, vCenter, and 7 Android APKs all needed current 2024-2026 CVE knowledge and platform-specific tradecraft → m365-entra-attack, o
Asked by Fiorella Bianchi · Nov 2, 2025
How it works?
A 6-phase, non-linear workflow — recon → map & rank → hunt → validate → report — with scope enforced in code and a 7-Question Gate before anything is submitted. Two ways to drive it: Plain English — describe what you're testing and the relevant skill loads automatically. /hunt scaffold + cbh CLI — engagement-folder structure, state, and orchestration. → Usage guide & worked example · 6-phase architecture & skill-to-phase map · cbh CLI
Asked by Emiliano Vargas · Oct 15, 2025
What's inside?
82 skills, auto-loaded by topic — no invocation by name. Coverage across the external attack surface: | Category | # | Examples | |---|---|---| | Web application hunting | 13 | XSS, SQLi, SSRF, IDOR, LFI, SSTI, XXE, CSRF, CORS, open-redirect | | Authentication & identity | 7 | auth-bypass, session, OAuth, SAML, MFA-bypass, ATO | | API & infrastructure | 15 | GraphQL, gRPC, WebSocket, API-misconfig, host-header, RCE | | Advanced & concurrency | 6 | race-condition, HTTP smuggling, deserialization, cache-poison | | Framework-specific | 4 | Next.js, Node.js, Laravel, Spring Boot | | Enterprise identity & cloud ★ | 3 | M365/Entra, Okta, cloud-IAM-deep | | Infrastructure & appliance ★ | 4 | VMware vCenter, enterprise VPN, SharePoint, ASP.NET/NTLM | | Red-team tradecraft ★ | 4 | redteam-mindset, APK pipeline, supply-chain recon, mid-engagement IR | | Recon & OSINT | 4 | web2-recon, offensive-osint, subdomain | | Workflow, reporting & specialized | 11 | methodology, triage-validation, evidence-hygiene, VRT-aware reporting | Full searchable catalog → docs/skills.md. Also ships 15 slash commands (/hunt, /recon, /report, …) and a deterministic engagement engine (engine/) that maps a target's attack surface and routes each finding to the skill that handles it.
Asked by Quentin Lefevre · Aug 22, 2025
What is this?
claude-bughunter is a drop-in skill bundle for the Claude Code skills system. Install once and Claude Code stops being a chatbot and starts behaving like a senior bug-hunting researcher or red-team operator: it knows the techniques, the chain templates, the VRT mappings, the platform CVE chains, and the hygiene — and it stays in scope. Four layers stack: Think — bb-methodology + redteam-mindset: the 5-phase non-linear workflow, critical-thinking framework, and red-team operator discipline. Hunt webapps — 48 hunt- skills curated from 681 disclosed HackerOne reports: per-class detection patterns, payloads, bypass tables, and chain templates. Hit the perimeter — enterprise platform chains (M365/Entra, Okta, vCenter, SSL-VPN appliances, SharePoint, cloud IAM): current 2024–2026 CVE chains + post-credential escalation. Ship it — triage-validation + reporting + evidence-hygiene: the 7-Question Gate, VRT-aware severity, OOS rebuttals, PII redaction, and red-team deliverables. All triggered automatically by topic — describe what you're testing in plain English and the relevant skill loads. No invocation by name.
Asked by Zain Malik · Aug 11, 2025
Ask a question
Skills alternatives

Security-tested development skill for Claude AI. Grade A. Inspects and configures the security headers a Power Pages site sends to browsers — Content Security Policy, frame and clickjacking protection

Security-tested data-ai skill for Claude AI. Grade A. Use when starting feature work that needs isolation from current workspace or before executing implementation plans - creates isolated git worktre

Security-tested data-ai skill for Claude AI. Grade A. GA4 BigQuery Export Schema Reference — complete field reference, nested structures, query patterns, and performance tips

Security-tested data-ai skill for Claude AI. Grade A. Meta Conversions API (CAPI) Setup Reference — architecture, event types, customer information hashing, deduplication, implementation examples, AEM

Security-tested development skill for Claude AI. Grade A. Lista o que uma funcao/metodo chama (call graph direto)

Security-tested data-ai skill for Claude AI. Grade A. Name Haskell test modules after the module under test with a Spec suffix in the same namespace. Use when writing or reviewing Haskell test module

Security-tested data-ai skill for Claude AI. Grade A. Simulate a 5-member expert board deliberation for major decisions. Use when evaluating plans, architecture choices, feature designs, or any decisi

Security-tested development skill for Claude AI. Grade A. MVC avançado via PE (Pontos de Entrada) — adicionar grids customizadas em telas MVC padrão (CNTA300/MATA070/MATA440/MATA460/FINA040 via *STRU)
Trending now

Document intelligence API that parses, splits, OCRs, and extracts structured data from complex PDFs, slides, and spreadsheets.

Sponsored answers, paid per click.

Accurate Homework Help with Full Explanations

Open multimodal 12B model handling interleaved images and text with a 128K context window.
