Browse documentation
Find opportunities with Pro discovery
Search target identities, use program opportunity tiers, compare dupe risk, inspect report counts, and find upcoming programs.
On this page
The catalog covers 25 platforms, including HackZar. Enable Include VDPs for recognition-only programs. HackZar includes public scope and total report counts. Its catalog dates use the Created date published on each program page, with a conservative estimate when that date is unavailable. Select HackZar in Notification Rules to filter private alerts to that platform.
Open the program catalog
Go to the bbradar catalog while signed in with Pro.Enter a target fragment
Type at least three characters from a hostname, package, repository, contract, IP range, or another known target identity.Review the match context
Target-aware results show the program attached to the matching active target. Use a distinctive fragment when a broad word returns too many programs.Open the program
Select the result, scroll to Program Targets, and verify the exact active scope and upstream policy before testing.
Discover programs
Search programs and active target identities
Acme Cloud
ELITEapi.example.test
Low dupe risk
Nova Wallet
HOTapi.example.test
Medium dupe risk
- Program tier
- Elite
- What it highlights
- Very fresh, lightly reported programs with strong payout potential.
- Program tier
- Hot
- What it highlights
- Fresh programs with low visible competition and attractive rewards.
- Program tier
- Strong
- What it highlights
- Paid programs with a low public report count and solid potential, including older programs.
- Program tier
- Potential
- What it highlights
- Paid programs with a modest public report count that may be overlooked.
| Program tier | What it highlights |
|---|---|
| Elite | Very fresh, lightly reported programs with strong payout potential. |
| Hot | Fresh programs with low visible competition and attractive rewards. |
| Strong | Paid programs with a low public report count and solid potential, including older programs. |
| Potential | Paid programs with a modest public report count that may be overlooked. |
Use program tiers to build a research shortlist, then review the policy and program details before deciding what to investigate.
Find the Opportunity row
On the catalog, locate the Elite, Hot, Strong, and Potential chips above the program list.Select one or more tiers
Selected tiers work as alternatives, so choosing Elite and Hot shows programs in either tier.Combine with catalog filters
Narrow the results further with platform, tags, rewards, status, or search as needed.Clear the tier filter
Select the active chip again or use the clear action to return to the full catalog.
Tiers are discovery aids, not guarantees of payout, valid vulnerability classes, or low duplicate counts. Always read the program policy and validate eligibility before testing.
Where source data supports it, Pro adds public report counts and a dupe-risk badge. Low means less visible crowding, Medium means some duplicate pressure is visible, and High means the program or target appears more crowded. Unknown means the available public data is insufficient.
Treat the badge as a comparative guide, not a prediction. Public counts can be incomplete and some platforms do not expose them.
bbradar combines observations from supported program sources. Publication follows successful retrieval and verification; source availability, rate limits, and incomplete checks can delay changes. A discovery date is the time bbradar first observed a program, unless a separate upstream launch date is provided.
Opportunity and target scores use available freshness, rewards, target type, and public report activity. Factor breakdowns expose the contributing evidence. Model versions and evidence coverage in the API help distinguish a scoring change from a new source observation. A public report count may cover a platform-specific period; inspect its source label before comparing programs.
Missing evidence remains missing. Unknown dupe risk does not mean low competition, and a score does not estimate exploitability, expected earnings, or permission to test. Self-Hosted programs do not receive fabricated opportunity scores or platform history.
Confirmed paused programs remain visible for reference with retained scope and rewards. They are excluded from active opportunity and global change feeds, and their current bounty eligibility is disabled. Always open the current official policy before selecting work.
Choose a program
Filter the catalog by the platform and asset categories relevant to your work. Open Example Program and inspect its status, reward description, and official policy link.Review an eligible target
With Pro, open Program Targets. An example row forapi.example.commight be in scope with a score of 74 and the label Strong Target. Check the factor breakdown and source observation, not just the score.Interpret an unknown signal
If dupe risk is Unknown, public evidence is insufficient. Keep that uncertainty in your shortlist instead of treating it as low competition.Save a relevant alert
Use the target’s alert shortcut, review the draft in Notification Rules, and select Save Rules. Keep only the streams and filters you want; a prefilled draft is not saved automatically.
The result is a short, evidence-based list to review against current program policies. An alert records a change; it does not authorize an interaction with an asset.
Future-dated contest programs remain publicly visible. Pro can also surface upcoming non-contest programs within the configured visibility window, giving you time to read policies and prepare research workflows before launch.
