What problem does it solve?
Red team operators frequently misapply bug bounty or web application penetration testing (WAPT) scope rules to authorized red team engagements, leading to missed access-yielding findings, premature retraction of valid vulnerabilities, and incomplete host coverage due to unnecessary self-throttling.
Core Features & Use Cases
- Scope Discipline Rules: Clear guidelines to distinguish red team (gain access, prove impact) from bug bounty/WAPT (find bugs, write reports) to avoid incorrect prioritization of low-impact vulnerability classes.
- Mindset Corrections: 9 targeted fixes for common operator anti-patterns including premature finding retraction, incomplete sister-app sweeps, and stopping at first blocker.
- Engagement Cadence Standards: Pre/during/post engagement checklists and a complete per-host sweep checklist to ensure no live surface is left untested.
- Blocker Decision Trees: Step-by-step alternative vectors for common roadblocks including captchas, WAFs, rate limits, and failed reproducibility checks to avoid unnecessary engagement stops.
- Use Case: For an authorized external red team engagement targeting a corporate network, load this skill at the start to avoid missing critical authentication bypass or SSRF vulnerabilities by incorrectly skipping them as "WAPT-class" bugs.
Quick Start
Load the redteam-mindset skill at the start of any authorized red team engagement and refer to it whenever you encounter a blocker, are tempted to retract a finding, or are unsure if a tested host surface is fully covered.