TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

PortSwigger Blog

How this seasoned bug bounty hunter combines Burp Suite and HackerOne to uncover high-impact vulnerabilities

2025-09-12 · Read original ↗

ATT&CK techniques detected

3 predictions
T1190Exploit Public-Facing Application
79%
"’ most notable wins, a $ 38, 000 bug bounty, was uncovered using burp ’ s http request smuggler extension : i was testing an api on zoom ’ s bug bounty program and burp flagged possible smuggling. that lead turned into a $ 38k bounty. - burp suite gives hackers granular control, …"
T1588.002Tool
74%
"burp suite. visit the support center - burp suite professional is a leading web vulnerability scanner and proxy tool developed by portswigger, used by security professionals to intercept, manipulate, and analyze http requests in real time. its extensibility and powerful features …"
T1588.006Vulnerabilities
69%
"how this seasoned bug bounty hunter combines burp suite and hackerone to uncover high - impact vulnerabilities research academy my account customers about blog careers legal contact resellers attack surface visibility improve security posture, prioritize manual testing, free up t…"

Summary

Arman S. (Tess), a full-time independent security researcher and bug bounty hunter, talked us through how he uses Burp Suite Professional and HackerOne in tandem to find and report high-value security