What problem does it solve?
RCE vulnerabilities deliver the highest payouts in bug bounty programs, but they are difficult to find consistently across diverse tech stacks, admin interfaces, and cloud infrastructure. This skill eliminates guesswork by providing field-validated hunting techniques derived from 67 real public bug bounty reports, covering every major RCE vector and attack surface.
Core Features & Use Cases
- Comprehensive Attack Surface Mapping: Identifies all RCE-prone execution contexts including template engines, YAML/XML parsers, admin consoles, Kubernetes clusters, and dependency registries, with URL patterns, tech stack signals, and frontend code indicators to speed up reconnaissance.
- Proven Payload & Detection Library: Includes validated payloads for 10+ RCE vectors such as template injection, unsafe deserialization, dependency confusion, and path traversal to execution, plus bypass techniques for common filters and WAF rules.
- End-to-End Attack Chain Guidance: Breaks down 6 high-paying RCE attack chains into testable primitive steps, with real-world impact examples and cross-references to complementary hunting skills to help you combine low-severity findings into critical, triage-ready reports.
- Use Case: A penetration tester assessing a target running GitHub Enterprise Server can use this skill to locate the management console, test syslog-ng configuration fields for template injection, chain the primitive to a root shell, and produce a critical-severity report with full reproduction steps.
Quick Start
Use the hunt-rce skill to map all RCE-prone execution contexts on the target, test validated payloads for template injection, deserialization, and dependency confusion, and chain low-severity primitives into a demonstrated critical RCE finding with out-of-band confirmation.