Automate bug bounty recon from your terminal
RedCell runs the full bug bounty recon pipeline autonomously — from passive OSINT and subdomain enumeration to CVE scanning, dark-web OSINT, and a ready-to-submit findings report. All inside your authorized scope.
Install in one command
curl -fsSL https://redcell.sh/install.sh | shThen redcell login and redcell — no configuration required.
The RedCell bug bounty workflow
RedCell executes these steps autonomously in a single session.
Passive OSINT & subdomain discovery
RedCell maps your authorized target automatically — enumerating subdomains, resolving DNS, and fingerprinting services. No manual toolchain setup required.
Port scanning & service fingerprinting
The agent scans in-scope hosts for open ports and identifies services, technologies, and framework versions to surface the most likely attack vectors.
CVE scanning with web-nuclei templates
RedCell runs web-nuclei CVE templates against discovered services, collecting potential vulnerabilities ranked by severity.
Dark-web OSINT via Tor
The agent searches onion services for exposed credentials, paste dumps, and leaked data related to your authorized target scope.
Proof-of-concept verification
Each vulnerability is verified with a real PoC check before being logged — so your report contains confirmed findings, not false positives.
Exportable findings report
All verified findings, evidence screenshots, and severity scores are exported to Markdown and JSON — ready for your bug bounty report submission.
Why security researchers use RedCell
No manual toolchain
RedCell replaces a scattered collection of recon scripts, scanner configs, and manual steps with a single autonomous agent session.
Scope enforcement built in
Every action passes through a scope-guard. RedCell will not contact out-of-scope hosts — protecting you from accidental violations.
Dark-web coverage others skip
The darkweb-osint plugin searches Tor onion services for exposed credentials and data related to your target scope.
Submit-ready reports
Exportable Markdown and JSON reports with verified findings, severity scores, and evidence — formatted for bug bounty platform submissions.
Runs on your machine
RedCell is a single compiled binary. No SaaS portal, no cloud upload, no data leaving your host.
Free to start
The Free plan includes 200K tokens/month and the full CLI — enough to run meaningful engagements with no credit card required.
Start your first bug bounty engagement
Free plan. No credit card. One install command.