Skip to Content
status: accepting new hunters

Stop reading writeups.
Start finding real bugs.

1-on-1 coaching and live hacking sessions with 9+ years in the field — recon methodology, real target walkthroughs, and the workflow that actually finds valid, payable reports.

redline0xf@coaching:~
$ whoami --verbose
experience: 9+ years, offensive security
focus: web app recon, live hunting, mentoring
format: 1-on-1, screen-shared, real targets
$ ls ./sessions
live-hacking-session/   recon-deepdive/   career-review/
$
9+ yrs
in offensive security
1:1
live, not pre-recorded
Real targets
no toy labs only
Screen-share
watch the actual workflow

// offerings

Pick your session

Every session is live and 1-on-1 — no cohort, no pre-recorded course dump. You bring the questions or the target, we work through it together.

live_hacking.sh

Live Hacking Session

Watch a full recon-to-report pass on a real scoped target, or bring your own target and hunt together in real time. Includes a split arrangement on any bounty found during the session.

Bounty split · 2% of any confirmed payout
recon --deep

Recon & Methodology Review

Walk through your current recon pipeline, tooling, and note-taking — I'll point out where you're losing coverage or wasting time, and rebuild the workflow with you.

1 session · billed per call
career --plan

1-on-1 Career & Program Strategy

Program selection, report quality, triage/response strategy, and how to actually build a sustainable income from bug bounty rather than chasing every program at once.

1 session · billed per call

// how it works

From booking to first bug

101

Book a slot

Pick a session type and time — everything's scheduled and paid through Topmate, no back-and-forth DMs needed.

302

Tell me where you're stuck

Before the call, send your target, your current methodology, or the specific wall you've hit — the session is built around that, not a generic script.

200

Work the target live

Screen-shared, real-time recon and testing — you see the actual decision-making, not a polished highlight reel.

// about

Why 1-on-1, not a course

Most bug bounty content teaches you what a vulnerability class is. It rarely shows you the actual decision tree of hunting: what to check first, when to abandon a lead, how to read an app's attack surface fast. That's the part that only transfers live, with someone watching your screen and correcting the workflow in real time — so that's the only format I teach in.

Read more about the approach →

Ready to work a real target together?

Sessions are limited to keep them actually 1-on-1. Book through Topmate — payment and scheduling handled there.

Book on Topmate →