What problem does it solve?
Hunt-rce helps you identify, triage, and validate remote code execution opportunities across common web and infrastructure attack surfaces, reducing guesswork by requiring concrete impact evidence before reporting.
Core Features & Use Cases
- Attack surface targeting for high-impact RCE classes: Focuses on management consoles, admin/config UIs, execution endpoints, and parsing-heavy surfaces such as YAML/XML, templates, and path-based dispatchers.
- Evidence-driven validation workflow: Uses a clear validation gate to confirm attacker capability (command execution, file read, or out-of-band callbacks), articulate victim loss, and ensure fast reproducibility from scratch.
- Triage-oriented hunting guidance and escalation logic: Provides signals, payload patterns, bypass ideas, and a discipline for escalating findings when the same primitive yields higher impact on a CGI-enabled or execution-capable surface.
Use it when you are conducting a bug bounty or red-team engagement and want a repeatable method to move from reconnaissance signals to confirmed RCE with minimal ambiguity.
Quick Start
Use the hunt-rce skill to locate RCE-by-construction surfaces on the target, then confirm exploitability with an output or out-of-band callback before writing the report.