now in private beta·H1-Live SF ’26

A second brain for
bug bounty hunters.
Not another autonomous agent.

Vigihunt remembers every request you’ve seen, every asset you’ve found, and every test worth running — and surfaces them at the exact moment you need them. Copilot, not replacement. The human stays on the keyboard.

vigihunt · acme-corp · sessioncopilot
which endpoints on staging take a URL as input?
found 3 in this session:
GET /api/fetch?url= 12 reqs · 14:41
POST /api/webhook?callback= 2 reqs · 14:22
POST /api/import?source= 1 req · 14:03

cited from:
15 requests2 scansOWASP A10

draft an SSRF test plan for /api/fetch
drafting 9 test cases · ready for your approval.
→ never executes payloads. never sends traffic you didn’t authorize.
trusted by hunters who’ve shipped atHackerOneBugcrowdIntigritiYesWeHackGoogle VRPApple Security

Why it’s different

Generic AI gives generic answers.

Ask any chatbot about an SSRF and you’ll get a textbook reply. Ask Vigihunt about /api/fetch and you’ll get cited evidence — pulled from your traffic, your recon, and the methodology that actually works on bugs like this.

Three things, one answer.

When you ask a question, Vigihunt searches what you’ve seen, what your scans found, and the methodology that matters — at the same time. Every claim traces back to a source you can click.

01
Methodology
OWASP, ATT&CK, and the playbooks that actually work in the field.
shared
02
Your recon
Every subdomain, service, and tech your scans surface for this target.
per-project
03
Your session
Every request you’ve seen — captured live or imported from Burp.
real-time

The contract

The copilot stays in the passenger seat.

These aren’t features. They’re the rules we won’t break — what makes Vigihunt usable in programs that are paying attention.

Never executes payloads

The copilot drafts test cases. You run them. There is no auto-exploit button — not now, not ever.

Defined scope only

Every action is checked against the scope you declared. If it’s not in-scope, it doesn’t get touched.

Cited or it doesn’t count

Every answer comes with the exact requests, scans, and docs behind it. One click to verify, every time.

Full audit trail

Every query, every action, every decision is logged and replayable. You always know what the AI did on your behalf.

The product

Four surfaces. One hunt.

Scope, traffic, plan, deliver. Each surface is great on its own — together, they keep the context with you, hand-off-free.

01 · Scope Studio

A living map of the attack surface.

Drop in a bounty URL or root domain. Get back every asset, grouped by trust tier, diffed weekly, and annotated by the copilot. Hot assets pulse. Out-of-scope is struck through.

scope · acme-corp.com · 142 assets
02 · Traffic Copilot

Chat that remembers every request.

Burp imports in one click. The browser extension streams what you browse. Ask anything — the copilot points to the exact requests behind every answer.

session · 1,842 reqs · live
▸ what auth is /login using?
JWT in cookie, missing httpOnly. [3 requests cited]
03 · Test Plan Builder

Methodology drafted. Never executed.

Pick a target. Get a checklist grounded in proven attack patterns, with citations. You run the tests. It tracks coverage and surfaces gaps.

plan · /api/fetch · SSRF
file:// → local read
127.0.0.1 → internal services
gopher:// payload
cloud metadata endpoint
DNS rebinding
URL parser confusion
04 · Finding Tracker + Report

Writeup-ready in one click.

Every confirmed finding lives with its evidence — requests, payloads, screenshots. Generate a client-ready report without burning a weekend on the rewrite.

finding · VH-2026-041
● high · CVSS 7.5
SSRF via /api/fetch · file:// schema
staging.acme-corp.com · reproduced 3×
request.harresponse.txtscreenshot.png

The copilot remembers.
The hunter decides.

Start a project against any public bounty program in under two minutes. No credit card. No trial expiry. Just you, your hunt, and a second brain that’s read the docs.