Use Case·Bug Bounty

Automate bug bounty recon from your terminal

RedCell runs the full bug bounty recon pipeline autonomously — from passive OSINT and subdomain enumeration to CVE scanning, dark-web OSINT, and a ready-to-submit findings report. All inside your authorized scope.

Install in one command

curl -fsSL https://redcell.sh/install.sh | sh

Then redcell login and redcell — no configuration required.

The RedCell bug bounty workflow

RedCell executes these steps autonomously in a single session.

01

Passive OSINT & subdomain discovery

RedCell maps your authorized target automatically — enumerating subdomains, resolving DNS, and fingerprinting services. No manual toolchain setup required.

02

Port scanning & service fingerprinting

The agent scans in-scope hosts for open ports and identifies services, technologies, and framework versions to surface the most likely attack vectors.

03

CVE scanning with web-nuclei templates

RedCell runs web-nuclei CVE templates against discovered services, collecting potential vulnerabilities ranked by severity.

04

Dark-web OSINT via Tor

The agent searches onion services for exposed credentials, paste dumps, and leaked data related to your authorized target scope.

05

Proof-of-concept verification

Each vulnerability is verified with a real PoC check before being logged — so your report contains confirmed findings, not false positives.

06

Exportable findings report

All verified findings, evidence screenshots, and severity scores are exported to Markdown and JSON — ready for your bug bounty report submission.

Why security researchers use RedCell

No manual toolchain

RedCell replaces a scattered collection of recon scripts, scanner configs, and manual steps with a single autonomous agent session.

Scope enforcement built in

Every action passes through a scope-guard. RedCell will not contact out-of-scope hosts — protecting you from accidental violations.

Dark-web coverage others skip

The darkweb-osint plugin searches Tor onion services for exposed credentials and data related to your target scope.

Submit-ready reports

Exportable Markdown and JSON reports with verified findings, severity scores, and evidence — formatted for bug bounty platform submissions.

Runs on your machine

RedCell is a single compiled binary. No SaaS portal, no cloud upload, no data leaving your host.

Free to start

The Free plan includes 200K tokens/month and the full CLI — enough to run meaningful engagements with no credit card required.

Start your first bug bounty engagement

Free plan. No credit card. One install command.