Learn/Article or guide
Article or guideAccess control & business logicWeb application

Reading a scope like an attacker

Most researchers skim the scope and start testing. The half hour you spend reading it properly is the highest-value half hour of the engagement.

r0@r00tcauseSep 2026 · 3 min read

The scope is the map

A program's scope is not paperwork. It is the company telling you, in writing, which parts of their estate they are least sure about, and which parts they have already decided not to defend.

What to read first

  • The out-of-scope list. Everything on it was put there by somebody who got tired of closing the same report. That tells you what has already been found.
  • The max severity per asset. An asset capped at Medium is one they believe is isolated. Prove it is not.
  • The response targets. A program promising a one-day first response is staffed. One promising thirty is not.

The reward table is a confession

A company that pays ten times more for auth bugs is telling you where it is frightened.

Read the ratios, not the headline number. The gap between Critical and High is where the real threat model lives.

← More from Learn

More from @r00tcause