Professional profile required
This card is only issued once the hacker switches to Professional and adds a public name. Hobby profiles stay anonymous on purpose.
Annex — how this was earned
16 entries. Nothing scores without one.
2 entries
4 entries
3 entries
7 entriescapped at 600
16 ledger entries back these totals. The full derivation is visible to the holder and to Rooted review.
Where your proof lands
Derived from what each verified ledger entry actually covers. You have nothing in active directory, tooling & code.
- Web & appsec1,290EvidenceCache poisoning through an unkeyed headerChaining an IDOR into a full account takeoverConfirmed medium in the OAuth callbackGetting SSRF out of a PDF rendererConfirmed low in the invoice exportConfirmed medium in the file upload handlerConfirmed low in the tenant switcher
- Offensive ops350EvidenceDaily questions
- Foundations350EvidenceDaily questions
- Vuln research90EvidenceCache poisoning through an unkeyed header
- Active Directoryno proof yet
- Tooling & codeno proof yet
The road to Exploit Hunter
570 pts shortEverything below is priced. Pick the cheapest one and the gap closes.
- Connect Hack The Box
Rank, owns and global standing pulled from your profile.
+300points53% of the gap - Claim a CVE
Any published advisory with your name on the credit line.
+260points46% of the gap - Connect TryHackMe
Points and completed rooms.
+180points32% of the gap - Connect GitHub
Public tooling, exploits and the code you shipped.
+160points28% of the gap - Review another hacker's work
Accepted peer review adds small points and proves you can judge other hackers' reasoning.
+15points3% of the gap - Land another confirmed report
4 confirmed reports already. Reports have no ceiling; confirmed impact keeps moving the rank.
+360points63% of the gap
Not one figure above was typed in by hexwren.
Read how points are earnedRank requirements beyond points
- Rank 4+ - One verified credential or one confirmed report
- Rank 7+ - One confirmed report or one credited CVE
- Rank 9+ - A credited CVE at CVSS 9.0+, or three critical confirmed reports