
サブスクリプションの有無を問わず動作する、AI搭載のバグバウンティハンティングツールキット。
AI搭載のバグバウンティハンティング — 偵察からレポートまで、すべてターミナル上で完結。
無料セットアップ
·
クイックスタート
·
コマンド
·
検出内容
·
インストール
·
FAQ
Powered by AwareXone.com — 詐欺・不正に対抗するあなたのAIエージェント
💜 スポンサー募集中
BugHunterはスポンサーを募集しています。 あなたの支援は新機能の開発資金となり、無料のスタンドアロンモードを誰もが使い続けられるようにします。スポンサーにはREADME内にロゴとリンクを掲載し、さらに全リリースでクレジットを記載します。
スポンサーになりたい方へ? AwareXone.com またはメール [email protected] までご連絡ください。
プロ向けのバグバウンティハンティングツールキットです。Claudeのサブスクリプションがあってもなくても動作します。ターゲットを指定すると、偵察(リコン)の実行、脆弱性のテスト、厳格なゲートによる検証結果の確認、HackerOne・Bugcrowd・Intigriti・Immunefi向けの提出可能なレポートの作成まで行います。
すべてを記憶します。 あるターゲットで見つけたパターンが次のターゲットに活かされます。セッションは中断したところから再開できます。
Claude Code プラグインとしても、また無料のAIプロバイダーを利用する完全スタンドアロンCLI(bughunter)としても動作します。
Claude Code、Claude Pro、その他の有料AIサブスクリプションはもう必要ありません。
一度インストールすれば、マシン上の任意のターミナルから bughunter コマンドを使えます:```bash
git clone https://github.com/shuvonsec/claude-bug-bounty.git
cd claude-bug-bounty
./install.sh --agent standalone
アップデートを取得した後、同じコマンドを再実行してください。インストーラーは、管理対象のアクティブな `bughunter` コマンドを検出して更新します。`/usr/local/bin` や `~/.local/bin` 配下の古いインストールも対象となり、`~/.bughunter/config.json` に保存されたプロバイダー設定は保持されます。
設定を保持したまま、スタンドアロンコマンドをアンインストールするには:```bash
./uninstall.sh --agent standalone
--purge-config を使用すると、~/.bughunter/config.json も削除されます。アンインストーラーは
claude、opencode、pi、codex、agents、all のターゲットもサポートしています。```
bughunter help # show every command
bughunter setup # choose your AI provider (Ollama is free + offline)
bughunter recon target.com # map the attack surface
bughunter hunt target.com # hunt for vulnerabilities
bughunter validate "finding" # 7-Question Gate on your finding
bughunter report # write a submission-ready report
bughunter chat # interactive AI hunting shell
bughunter providers # list all available AI providers
bughunter models # list models and show the selected one
bughunter status # check which provider is active
bughunter h target.com # short alias for hunt
bughunter r target.com # short alias for recon
bughunter v "finding" # short alias for validate
### 無料のAIプロバイダー(自動検出・無料優先)
| プロバイダー | コスト | プライバシー | 速度 | 始め方 |
|:---|:---|:---|:---|:---|
| **Ollama** | 100%無料・ローカルで実行 | 完全 — 自分のマシン上に留まる | 高速 | `ollama pull qwen2.5:14b` |
| **Groq** | 無料枠あり | クラウド | 非常に高速 | [console.groq.com](https://console.groq.com) → APIキーを取得 |
| **DeepSeek** | 非常に安価(v4-flash / v4-pro) | クラウド | 高速 | [platform.deepseek.com](https://platform.deepseek.com) |
| Claude API | 有料 | クラウド | 高速 | [console.anthropic.com](https://console.anthropic.com) |
| OpenAI | 有料 | クラウド | 高速 | [platform.openai.com](https://platform.openai.com) |
| **Grok (xAI)** | 有料 | クラウド | 高速 | [console.x.ai](https://console.x.ai) → `grok-4.5` |
| **OpenRouter** | サブスクリプション / 従量課金 | クラウド | 高速 | [openrouter.ai/keys](https://openrouter.ai/keys) → APIキーを取得 |
| **OrcaRouter** | サブスクリプション / 従量課金 | クラウド | 高速 | [orcarouter.ai](https://www.orcarouter.ai) → APIキーを取得 |
BugHunterはこの順序でプロバイダーを自動検出します: **Ollama → Groq → DeepSeek → … → OrcaRouter → OpenRouter → Claude → OpenAI**
プロバイダーの切り替えや、インストール済みのOllamaモデルの選択はいつでも可能です: `bughunter setup`。
セットアップは完全に非対話式にもできます:```bash
bughunter setup --provider ollama --model qwen2.5:14b
1回限りのオーバーライドを行うには、コマンドの前にオプションを置きます:```bash bughunter --provider ollama --model qwen3:14b hunt target.com
### 完全オフラインのゼロコストセットアップ```bash
# 1. Install Ollama (runs AI locally, no internet needed after download)
curl -fsSL https://ollama.ai/install.sh | sh
ollama pull qwen2.5:14b # ~9 GB, one-time download
# 2. Install BugHunter
git clone https://github.com/shuvonsec/claude-bug-bounty.git
cd claude-bug-bounty
./install.sh --agent standalone # creates system-wide 'bughunter' command
# 3. Hunt
bughunter setup # choose Ollama, then choose one of its installed models
bughunter recon target.com
export GROQ_API_KEY="your-key-here" # free at console.groq.com ./install.sh --agent standalone bughunter setup # choose Groq bughunter hunt target.com
---
## クイックスタート
**オプション A — スタンドアロン(サブスクリプション不要、すべてのユーザーで動作)**```bash
git clone https://github.com/shuvonsec/claude-bug-bounty.git
cd claude-bug-bounty
./install.sh --agent standalone # creates system-wide 'bughunter' command
bughunter setup # pick a free AI provider
bughunter recon target.com
bughunter hunt target.com
bughunter validate "my finding"
bughunter report
オプションB — Claude Code プラグイン (Claude Code が必要です)```bash git clone https://github.com/shuvonsec/claude-bug-bounty.git cd claude-bug-bounty chmod +x install_tools.sh && ./install_tools.sh # subfinder · httpx · nuclei · katana · ffuf chmod +x install.sh && ./install.sh # skills + commands → ~/.claude/
[No input text provided.]```bash
claude
/recon target.com # map the attack surface
/hunt target.com # test for vulnerabilities
/validate # run the 7-Question Gate
/report # write the submission
オプション C — Claude にインストールさせる (Claude Code のみ)
ターミナルを開き、claude を実行して、貼り付けます:```text
Install the Claude Bug Bounty toolkit from https://github.com/shuvonsec/claude-bug-bounty
into ~/tools/. Clone the repo, run ./install_tools.sh then ./install.sh.
Verify /recon /hunt /validate /report are available.
---
## コマンド
### コアワークフロー
| コマンド | 機能 |
|:---|:---|
| `/recon target.com` | サブドメイン列挙 · ライブホスト探索 · URLクロール · nucleiスイープ |
| `/hunt target.com` | IDOR · 認証バイパス · SSRF · XSS · SQLi · ロジックの欠陥などをテスト |
| `/validate` | 7つの質問によるゲート — 報告に時間を無駄にする前に弱い発見を排除 |
| `/report` | 60秒でH1 · Bugcrowd · Intigriti · Immunefiの提出物を生成 |
| `/autopilot target.com` | 完全ループ、自律実行 — スコープ → リコン → ハント → 検証 → 報告 |
### リコンと列挙
| コマンド | 機能 |
|:---|:---|
| `/surface target.com` | リコンデータ+メモリからランク付けされた攻撃対象領域 |
| `/scope-aggregate <program>` | H1 · Bugcrowd · Intigriti · YWH · Immunefi全体のスコープ内アセットをすべて取得 |
| `/cloud-recon --keyword <name>` | 公開S3 · Azure · GCPバケット + CloudFlareバイパスオリジンIP |
| `/param-discover <url>` | Arjun · x8による隠れたHTTPパラメータの発見 |
| `/secrets-hunt --js-bundle <dir>` | ソース、JSバンドル、またはGitHub組織内の漏えいした認証情報 |
| `/takeover --recon <dir>` | dnsReaper · subjackによるサブドメイン乗っ取りの候補 |
| `/scan-cves <host>` | 焦点を絞ったnuclei high/criticalスイープ + オプションのlog4j-scan |
| `/bypass-403 <url>` | 403/401に対するヘッダー · メソッド · エンコーディングのトリック |
| `/portscan <host>` | naabu/smapによるオープンポート + 非Webサービス(Redis · Docker API · DB · RDP) |
| `/screenshot -l urls.txt` | ライブホストをスクリーンショットしてHTMLギャラリーに — トリアージ + PoCの証拠 |
### スキャナ(Web + LLM)
| コマンド | 機能 |
|:---|:---|
| `/cors <url>` | CORS設定ミス — オリジンリフレクション · null · クレデンシャル付き |
| `/crlf <url>` | CRLF / レスポンススプリッティング + ホストヘッダーインジェクション |
| `/nosqli <url>` | NoSQLインジェクション(オペレーターバイパス · `$where`タイミング) |
| `/jwt-scan <token>` | オフラインJWTツールキット — alg:none · RS256→HS256 · シークレットクラック |
| `/oob <target>` | ブラインドSSRF/XXE/SQLi用のOut-of-bandリスナー(interactsh) |
| `/sast <path>` | 取得したJS/ソースに対するSemgrepセキュリティパック → ランク付けされたシンク |
| `/domxss <url>` | ヘッドレスChromiumでDOM XSSを確認 — ペイロードが実行された場合のみ報告 |
| `/llm-redteam <endpoint>` | LLMレッドチームコーパス — プロンプトインジェクション · ジェイルブレイク · 外部送信 |
### スマートコントラクト(Web3)
| コマンド | 機能 |
|:---|:---|
| `/web3-audit <contract.sol>` | Foundry PoCテンプレートを使用した10クラスのスマートコントラクト監査 |
| `/token-scan <contract>` | ラグプルスキャナ — ミント権限 · LPロック · ハニーポット · ボンディングカーブ |
### セッションとユーティリティ
| コマンド | 機能 |
|:---|:---|
| `/pickup target.com` | 前回のセッションから再開 — 未テストのエンドポイントを優先 |
| `/intel target.com` | このターゲットに関連するCVE + 公開されたレポート |
| `/chain` | バグAを発見 → それに連鎖するバグBとCを発見 |
| `/scope <asset>` | テストする前にドメインまたはURLがスコープ内かどうかを確認 |
| `/triage` | 2分で完了するクイックなgo/no-goチェック |
| `/remember` | 現在の発見またはテクニックをハントメモリに記録 |
| `/memory-gc` | ハントメモリJSONLファイルの検査またはローテーション(10MB上限、バックアップ3つ) |
| `/arsenal [tool]` | インストール済みの外部ツールを一覧表示、またはインストールのヒントを表示 |
---
## 検出内容
<details>
<summary><b>26種類のWeb2脆弱性クラス</b></summary>
<br>
| 脆弱性 | 一般的な報酬 |
|:---|:---|
| IDOR / BOLA | $500 – $5K |
| 認証バイパス | $1K – $10K |
| XSS(Stored / Reflected / DOM) | $500 – $5K |
| SSRF | $1K – $15K |
| ビジネスロジック | $500 – $10K |
| レースコンディション | $500 – $5K |
| SQLインジェクション | $1K – $15K |
| OAuth / OIDC | $500 – $5K |
| ファイルアップロード → RCE | $500 – $10K |
| GraphQL認証バイパス | $1K – $10K |
| LLM / プロンプトインジェクション | $500 – $10K |
| API設定ミス(mass assignment · JWT · CORS) | $500 – $5K |
| アカウント乗っ取り | $1K – $20K |
| SSTI | $2K – $10K |
| サブドメイン乗っ取り | $200 – $5K |
| クラウド / インフラ露出 | $500 – $20K |
| HTTPリクエストスマグリング | $5K – $30K |
| キャッシュポイズニング | $1K – $10K |
| MFA / 2FAバイパス | $1K – $10K |
| SAML / SSO攻撃 | $2K – $20K |
| エラー情報開示 / デバッグエンドポイント | $200 – $5K |
| CSSインジェクション | $500 – $5K |
| LFI → RCE | $1K – $15K |
| 安全でないデシリアライゼーション | $5K – $30K |
| 依存関係の混乱 / サプライチェーン | $1K – $20K |
| パディングオラクル / 暗号の誤用 | $2K – $20K |
</details>
<details>
<summary><b>10種類のWeb3 / スマートコントラクトのバグクラス</b></summary>
<br>
| 脆弱性 | 一般的な報酬 |
|:---|:---|
| 会計デシンク | $50K – $2M |
| アクセス制御 | $50K – $2M |
| 不完全なコードパス | $50K – $2M |
| オフバイワン | $10K – $100K |
| オラクル操作 | $100K – $2M |
| ERC4626シェアインフレーション | $50K – $500K |
| リエントランシー | $10K – $500K |
| フラッシュローン攻撃 | $100K – $2M |
| 署名リプレイ | $10K – $200K |
| プロキシ / アップグレード | $50K – $2M |
</details>
---
## AIエージェント
それぞれ1つの仕事に特化した9つのスペシャリスト:
| エージェント | 役割 |
|:---|:---|
| `recon-agent` | サブドメイン列挙 · ライブホスト発見 · URLクロール |
| `report-writer` | 支払いが発生するインパクト優先のレポート(N/Aにされない) |
| `validator` | 7つの質問によるゲートを実行 — 弱い発見を排除 |
| `web3-auditor` | 10のバグクラスにわたるスマートコントラクト監査 |
| `chain-builder` | バグA → それに連鎖するバグBとCを発見 |
| `autopilot` | 安全チェックポイント付きの完全なハントループ |
| `recon-ranker` | 攻撃対象領域を高価値のターゲットから順にランク付け |
| `token-auditor` | ミームコイン / トークンのラグプルとセキュリティスキャン |
| `credential-hunter` | ワードリスト生成 → OSINT → 侵害チェック → スプレー(スプレー前に完全停止) |
---
## 仕組み
<div align="center">```
You ─▶ /recon ─▶ /hunt ─▶ /validate ─▶ /report
│ │
▼ ▼
Hunt Memory 7-Question Gate
(persists across (kills weak findings
sessions) before you submit)
パイプライン内のすべてのツールは、インストールされているかどうかで実行が制御されます — 欠落しているツールはスキップされ、エラーにはなりません。一度設定した認証ヘッダーは、httpx · katana · ffuf · nuclei · dalfox に自動的に引き継がれます。
前提条件:```bash
brew install go python3 jq
sudo apt install golang python3 jq
**スキャンニングツール** (subfinder · httpx · nuclei · katana · ffuf · gau · dnsx · nmap · dalfox などをインストール):```bash
chmod +x install_tools.sh && ./install_tools.sh
スタンドアロンの bughunter コマンド (サブスクリプション不要、Claude Codeなしで動作):```bash
./install.sh --agent standalone
bughunter setup # choose Ollama (free) · Groq (free tier) · DeepSeek (cheap) · Claude · OpenAI
**AIスキル + コマンド**をClaude Codeへ:```bash
chmod +x install.sh && ./install.sh
その他のエージェントハーネス:```bash ./install.sh --agent opencode # OpenCode ./install.sh --agent pi # Pi Agent ./install.sh --agent codex # Codex ./install.sh --agent all # every supported target
**オプション: Chaos APIキー** (サブドメインカバレッジの向上)```bash
export CHAOS_API_KEY="your-key"
echo 'export CHAOS_API_KEY="your-key"' >> ~/.zshrc
毎セッションで7つのルールが適用され、例外はありません:
PR歓迎。最も価値があるもの:
skills/security-arsenal/SKILL.md へのペイロード追加---
## 利用者
<p align="center"><i>ワークフローにBugHunterを組み込んでいるチームと研究者。</i></p>
<table align="center">
<tr>
<td align="center" width="200">
<a href="https://awarexone.com">
<img src="https://assets.kitploit.com/production/public/readmes/51077/29e21784cbe8b37142a688801ddd02d4084136effa303a59c67cdd8621e4ac2a/b44baafd696ad5280f1c515671c279895b049b007d04ef2400f00b7eaef441fc-display-v1.webp" alt="AwareXone" width="72"/>
<br/><b>AwareXone</b>
</a>
<br/><sub>AIエージェント vs. 詐欺&不正</sub>
</td>
<td align="center" width="200">
<a href="ADOPTERS.md">
<img src="https://img.shields.io/badge/+-Add_your_team-7F55FF?style=for-the-badge" alt="Add your team"/>
</a>
<br/><sub>1行のPRを開く</sub>
</td>
</tr>
</table>
<p align="center">
チーム、プログラム、またはワークフローでBugHunterを使用していますか? <b><a href="ADOPTERS.md">あなたも追加</a></b> — <code>ADOPTERS.md</code>への簡単なPR、または<a href="https://github.com/shuvonsec/claude-bug-bounty/issues">issue</a>を開いてください。実在し、確認可能なエントリーのみ。
</p>
---
## スター履歴
<p align="center">
<a href="https://star-history.dera.page/#shuvonsec/claude-bug-bounty&type=date&legend=top-left">
<picture>
<source media="(prefers-color-scheme: dark)" srcset="https://star-history.dera.page/svg?repos=shuvonsec/claude-bug-bounty&type=date&theme=dark&legend=top-left" />
<source media="(prefers-color-scheme: light)" srcset="https://star-history.dera.page/svg?repos=shuvonsec/claude-bug-bounty&type=date&legend=top-left" />
<img alt="スター履歴チャート" src="https://star-history.dera.page/svg?repos=shuvonsec/claude-bug-bounty&type=date&legend=top-left" width="560" />
</picture>
</a>
</p>
---
## サポート
BugHunterがあなたのハントに役立っているなら、さらなるハントを支援できます:
<p align="center">
<a href="https://www.buymeacoffee.com/shuvonsec">
<img src="https://assets.kitploit.com/production/public/readmes/51077/322a7c99f1dd15a03b3c1b00b0d18ddd87443d80b823d3467a240721ae02357e/37540ef5b455c7e9fd2e680a883fa3eaa5ac7dfe7ea38853db90363dee628a84-display-v1.webp" alt="Buy Me A Coffee" height="50"/>
</a>
</p>
---
## 謝辞
BugHunterに貢献してくださったすべての皆様に感謝します。アバターをクリックすると、そのGitHubプロフィールが開きます。
<p align="center">
<a href="https://github.com/shuvonsec"><img src="https://assets.kitploit.com/production/public/readmes/51077/3c71ec4e8d747afbf17f2422c15a990e89b1e4c711129890ae2c2ddc0cf33b11/c28f708717c97d5e9032426d44661d39e54cbb0ea831351e3da7862fa89b0266-display-v1.webp" width="48" height="48" alt="shuvonsec" title="shuvonsec"/></a>
<a href="https://github.com/shuv0n"><img src="https://assets.kitploit.com/production/public/readmes/51077/d1087f300aa2f159be8a3f20f1da3b0d498d1a3b086006f00bba2e96bcafa1ca/3e4e701d8d7199dbc4aa5bfd0872da422c3630a3682e81bd4f00fb4b3eff796a-display-v1.webp" width="48" height="48" alt="shuv0n" title="shuv0n"/></a>
<a href="https://github.com/letztek"><img src="https://assets.kitploit.com/production/public/readmes/51077/8236747fa6130ad14ab79ca13ad7e1f727530cf03388d5ff69f6522d1202855b/850834b0bcf7305c85e3e2eef40eae2829896eb40992635126a5b518430569e3-display-v1.webp" width="48" height="48" alt="letztek" title="letztek"/></a>
<a href="https://github.com/bertolikimberly"><img src="https://assets.kitploit.com/production/public/readmes/51077/03de9cce0dd4aa48faa6d9c325d8b68533d34370322e235b459eb7cf8985aba7/610e73a3dd0ebcd37db0f1d16bb7ebf6cc7810df13cbebe65d77871ec3115621-display-v1.webp" width="48" height="48" alt="bertolikimberly" title="bertolikimberly"/></a>
<a href="https://github.com/venkatas"><img src="https://assets.kitploit.com/production/public/readmes/51077/b8248121001fa656e73d22b66e556f5416729e73c034c3df7e6fd6d178f69c64/2adc3afc7934f533642edb4278fcd3d4ad503b268bc0bd5a5d5cee7828190544-display-v1.webp" width="48" height="48" alt="venkatas" title="venkatas"/></a>
<a href="https://github.com/adityaax"><img src="https://assets.kitploit.com/production/public/readmes/51077/61029b5a332921d3cf18ee1f45ed1f427923e6e6afe082118104fa9f2ffde0c0/de5f88e6b6618bb8d52d8728c2dad1a3e20822f2d382e341792edf29758d2956-display-v1.webp" width="48" height="48" alt="adityaax" title="adityaax"/></a>
<a href="https://github.com/BeargleIndustries"><img src="https://assets.kitploit.com/production/public/readmes/51077/2b982731b11d958663f6cd0e2f70004401d97951366a574498718441f4314048/0cee9f5a6efcd85c280bd743ededb88faa88ed95b04ecb8966c302f7aa3065ec-display-v1.webp" width="48" height="48" alt="BeargleIndustries" title="BeargleIndustries"/></a>
<a href="https://github.com/ultra-supara"><img src="https://assets.kitploit.com/production/public/readmes/51077/c6d39ef6033dbeac0f1ed6bdbca50a78aa2f7b6cf92ef3270fda4163eb45e7c6/caae781831ae9859baa23bdbc1048e2ea737179d71af9e6f126644d53a111129-display-v1.webp" width="48" height="48" alt="ultra-supara" title="ultra-supara"/></a>
<a href="https://github.com/AurisDSP"><img src="https://assets.kitploit.com/production/public/readmes/51077/faa96c27e7d0493d309fee7b94e79aed51b991d83f17a44f605d22e2657691f0/50c186ab21c94f2b974570ebf01f896c770a361ab066e25338625993193d5604-display-v1.webp" width="48" height="48" alt="AurisDSP" title="AurisDSP"/></a>
<a href="https://github.com/Edneam"><img src="https://assets.kitploit.com/production/public/readmes/51077/e1a7a36a04544478fa1984f793aa3cea48f8a51bb090ce74a28e13334aafa6ab/bb9611fa7eeb5ebb5e58ae2a2cd4103c7bdf917f9191babf517d83f1eb5a6852-display-v1.webp" width="48" height="48" alt="Edneam" title="Edneam"/></a>
<a href="https://github.com/depapp"><img src="https://assets.kitploit.com/production/public/readmes/51077/3156944f4894fdd30b89baf215623103e46a7481c2858849d76016d17169c5ba/d8b617a44887e6737983e20cff14f61af07d18706bf0e3752ffeae54f5a7cc8b-display-v1.webp" width="48" height="48" alt="depapp" title="depapp"/></a>
<a href="https://github.com/Realgagenichols"><img src="https://assets.kitploit.com/production/public/readmes/51077/422e70caa8cce448ca55f0a63c0d7620f721b53821309c0291242ad0e4ff2043/9ce2cb2bd457ba0b88efca09db59c1264da78e7b854bb96352514aac13183d90-display-v1.webp" width="48" height="48" alt="Realgagenichols" title="Realgagenichols"/></a>
<a href="https://github.com/thuvh"><img src="https://assets.kitploit.com/production/public/readmes/51077/1dc37fcd3ddadd6b175572a34e2c86c44aedbc97fba2d79a1809a65aa4dce155/5a8b7a48be2c5e81eff7134f4d3f42b6e3ef9d4da35f88e87e99d129aa874859-display-v1.webp" width="48" height="48" alt="thuvh" title="thuvh"/></a>
<a href="https://github.com/onlybugs05"><img src="https://assets.kitploit.com/production/public/readmes/51077/f529bc0c7273b2e98e26352bb1a174c515dee670826bdf519240b63774f05b33/a89875927c1da3655d8c5880c93d1b13c30af04928b7a8335c4bb57e7a2f858d-display-v1.webp" width="48" height="48" alt="onlybugs05" title="onlybugs05"/></a>
<a href="https://github.com/savioruz"><img src="https://assets.kitploit.com/production/public/readmes/51077/362ee5f394d18365f33beae9d4e24b1f54a3bb299ceaa69aad6476c7912add35/fadecab17667be841099372f346c2892398fc55069a8d6c9e7c1031745fa92e9-display-v1.webp" width="48" height="48" alt="savioruz" title="savioruz"/></a>
<a href="https://github.com/Paebak"><img src="https://assets.kitploit.com/production/public/readmes/51077/0f26c58b1801e41175d39ad5df2ed02574c2bbff6e72a0999f278a962aaf9a2e/56ab94c06cf38bfc7c83550efc5b06597a135c4855b2f3122a79e9c493ef5310-display-v1.webp" width="48" height="48" alt="Paebak" title="Paebak"/></a>
<a href="https://github.com/nurazhardotcom"><img src="https://assets.kitploit.com/production/public/readmes/51077/3af62ef52780b5fac95a8b00db8fb562b8d03bf151a4a34c51dd4df37d47b4ab/e29f4b8a62da7772a4fbf0d385cc827efa746d74ec6cdc4f854c217e3d3b539d-display-v1.webp" width="48" height="48" alt="nurazhardotcom" title="nurazhardotcom"/></a>
<a href="https://github.com/SeekAndExploit"><img src="https://assets.kitploit.com/production/public/readmes/51077/943bffd56ab7cd823f6226ba45e1b2d8bfb24e2c705cf7285cd30c12d54b4d29/50579361c6456568868e787108a75c019b117b43e79ad16bfb43546876ffb1f1-display-v1.webp" width="48" height="48" alt="SeekAndExploit" title="SeekAndExploit"/></a>
<a href="https://github.com/Shawanga"><img src="https://assets.kitploit.com/production/public/readmes/51077/2f168dbf41d11829183809a1ada43bd407eb789ca322351b72544e9d8d689490/161721c856e5630413a4d7dabf33e2aadec45ff7a97f101952bbeeef8fff1b11-display-v1.webp" width="48" height="48" alt="Shawanga" title="Shawanga"/></a>
<a href="https://github.com/zeze-zeze"><img src="https://assets.kitploit.com/production/public/readmes/51077/6712b474717b9a0d31df50db07c0679323d745992e6905ef146ba93f059f1a0e/ea68d492a788a174c59ee241475e4ec6ba168ef8671359c2af6dc0db53d2aa7f-display-v1.webp" width="48" height="48" alt="zeze-zeze" title="zeze-zeze"/></a>
<a href="https://github.com/grave0x"><img src="https://assets.kitploit.com/production/public/readmes/51077/b177d7f1eb1e5f5f4ea6b0f01927068568d92feeb450c3588da3eb4ee444be3f/997770039b73abeb34cfa1bf34430cdd81e54b96626c1d856317711f6e55a15f-display-v1.webp" width="48" height="48" alt="grave0x" title="grave0x"/></a>
<a href="https://github.com/kevinaimonster"><img src="https://assets.kitploit.com/production/public/readmes/51077/eebb78e8387a8f45d69ee11489aa55bcefe42e934c61b6200470d4b3f8b8bc03/4dbb85af058868212ac2306d2ecd5f376ae81eb8faed80e96d9144193aea57c8-display-v1.webp" width="48" height="48" alt="kevinaimonster" title="kevinaimonster"/></a>
</p>
---
<p align="center">
<img src="https://assets.kitploit.com/production/public/readmes/51077/d32053d974d60dcec5ad625a665f0d22dbbddbc152b6d1184ad7b3774f0839e0/85e958d2288223e9020199c1ab154ead84e0e2170b64e9c21ce4ea15d6830014-display-v1.webp" alt="BugHunter" width="48"/><br>
<a href="https://github.com/shuvonsec">GitHub</a>
·
<a href="https://x.com/shuvonsec">Twitter</a>
·
<a href="mailto:[email protected]">[email protected]</a><br>
<b>バグハンターによって、バグハンターのために。</b><br>
<sub>MITライセンス · 認可されたセキュリティテスト専用。常に承認済みのバグバウンティプログラムのスコープ内でテストしてください。</sub>
</p>
<p align="center">
<a href="https://awarexone.com">
<img src="https://assets.kitploit.com/production/public/readmes/51077/29e21784cbe8b37142a688801ddd02d4084136effa303a59c67cdd8621e4ac2a/b44baafd696ad5280f1c515671c279895b049b007d04ef2400f00b7eaef441fc-display-v1.webp" alt="AwareXone" width="56"/>
</a>
<br/>
<sub><a href="https://awarexone.com"><b>AwareXone.com</b></a> 提供 · 詐欺&不正に対抗するあなたのAIエージェント</sub>
</p>
| # | ルール | 理由 |
|---|
| 1 | まず全体のスコープを読む | プログラムが許可したものだけをテストする |
| 2 | 実際のバグのみ | 「攻撃者は今すぐこれを実行できるか?」— そうでなければ停止 |
| 3 | 弱い報告を潰す | 30秒の確認で、無駄な報告にかかる何時間も節約できる |
| 4 | スコープ外に出ない | 1回の誤ったリクエストで禁止される可能性がある |
| 5 | 5分ルール | 5分経っても進展がない?次に進む |
| 6 | 報告前に検証 | 30分費やして書く前に /validate |
| 7 | 影響度優先 | 最も深刻な結果をもたらすバグからテストする |