A second brain for
bug bounty hunters.
Not another autonomous agent.
Vigihunt remembers every request you’ve seen, every asset you’ve found, and every test worth running — and surfaces them at the exact moment you need them. Copilot, not replacement. The human stays on the keyboard.
Why it’s different
Generic AI gives generic answers.
Ask any chatbot about an SSRF and you’ll get a textbook reply. Ask Vigihunt about /api/fetch and you’ll get cited evidence — pulled from your traffic, your recon, and the methodology that actually works on bugs like this.
Three things, one answer.
When you ask a question, Vigihunt searches what you’ve seen, what your scans found, and the methodology that matters — at the same time. Every claim traces back to a source you can click.
The contract
The copilot stays in the passenger seat.
These aren’t features. They’re the rules we won’t break — what makes Vigihunt usable in programs that are paying attention.
Never executes payloads
The copilot drafts test cases. You run them. There is no auto-exploit button — not now, not ever.
Defined scope only
Every action is checked against the scope you declared. If it’s not in-scope, it doesn’t get touched.
Cited or it doesn’t count
Every answer comes with the exact requests, scans, and docs behind it. One click to verify, every time.
Full audit trail
Every query, every action, every decision is logged and replayable. You always know what the AI did on your behalf.
The product
Four surfaces. One hunt.
Scope, traffic, plan, deliver. Each surface is great on its own — together, they keep the context with you, hand-off-free.
A living map of the attack surface.
Drop in a bounty URL or root domain. Get back every asset, grouped by trust tier, diffed weekly, and annotated by the copilot. Hot assets pulse. Out-of-scope is struck through.
Chat that remembers every request.
Burp imports in one click. The browser extension streams what you browse. Ask anything — the copilot points to the exact requests behind every answer.
Methodology drafted. Never executed.
Pick a target. Get a checklist grounded in proven attack patterns, with citations. You run the tests. It tracks coverage and surfaces gaps.
Writeup-ready in one click.
Every confirmed finding lives with its evidence — requests, payloads, screenshots. Generate a client-ready report without burning a weekend on the rewrite.
The copilot remembers.
The hunter decides.
Start a project against any public bounty program in under two minutes. No credit card. No trial expiry. Just you, your hunt, and a second brain that’s read the docs.