Browse documentation
bbradar Pro guide

Find opportunities with Pro discovery

Search target identities, use program opportunity tiers, compare dupe risk, inspect report counts, and find upcoming programs.

6 min readReviewed Read as Markdown
On this page
Program tier
Elite
What it highlights
Very fresh, lightly reported programs with strong payout potential.
Program tier
Hot
What it highlights
Fresh programs with low visible competition and attractive rewards.
Program tier
Strong
What it highlights
Paid programs with a low public report count and solid potential, including older programs.
Program tier
Potential
What it highlights
Paid programs with a modest public report count that may be overlooked.

Use program tiers to build a research shortlist, then review the policy and program details before deciding what to investigate.

  1. Find the Opportunity row

    On the catalog, locate the Elite, Hot, Strong, and Potential chips above the program list.
  2. Select one or more tiers

    Selected tiers work as alternatives, so choosing Elite and Hot shows programs in either tier.
  3. Combine with catalog filters

    Narrow the results further with platform, tags, rewards, status, or search as needed.
  4. Clear the tier filter

    Select the active chip again or use the clear action to return to the full catalog.

Tiers are discovery aids, not guarantees of payout, valid vulnerability classes, or low duplicate counts. Always read the program policy and validate eligibility before testing.

Where source data supports it, Pro adds public report counts and a dupe-risk badge. Low means less visible crowding, Medium means some duplicate pressure is visible, and High means the program or target appears more crowded. Unknown means the available public data is insufficient.

Treat the badge as a comparative guide, not a prediction. Public counts can be incomplete and some platforms do not expose them.

bbradar combines observations from supported program sources. Publication follows successful retrieval and verification; source availability, rate limits, and incomplete checks can delay changes. A discovery date is the time bbradar first observed a program, unless a separate upstream launch date is provided.

Opportunity and target scores use available freshness, rewards, target type, and public report activity. Factor breakdowns expose the contributing evidence. Model versions and evidence coverage in the API help distinguish a scoring change from a new source observation. A public report count may cover a platform-specific period; inspect its source label before comparing programs.

Missing evidence remains missing. Unknown dupe risk does not mean low competition, and a score does not estimate exploitability, expected earnings, or permission to test. Self-Hosted programs do not receive fabricated opportunity scores or platform history.

Confirmed paused programs remain visible for reference with retained scope and rewards. They are excluded from active opportunity and global change feeds, and their current bounty eligibility is disabled. Always open the current official policy before selecting work.

  1. Choose a program

    Filter the catalog by the platform and asset categories relevant to your work. Open Example Program and inspect its status, reward description, and official policy link.
  2. Review an eligible target

    With Pro, open Program Targets. An example row for api.example.com might be in scope with a score of 74 and the label Strong Target. Check the factor breakdown and source observation, not just the score.
  3. Interpret an unknown signal

    If dupe risk is Unknown, public evidence is insufficient. Keep that uncertainty in your shortlist instead of treating it as low competition.
  4. Save a relevant alert

    Use the target’s alert shortcut, review the draft in Notification Rules, and select Save Rules. Keep only the streams and filters you want; a prefilled draft is not saved automatically.

The result is a short, evidence-based list to review against current program policies. An alert records a change; it does not authorize an interaction with an asset.

Future-dated contest programs remain publicly visible. Pro can also surface upcoming non-contest programs within the configured visibility window, giving you time to read policies and prepare research workflows before launch.