ScopeHunter
A professional network for security practitioners -- built where the work happens, honestly labeled as it grows.
Why "ScopeHunter"?
In security work, scope is the line that separates authorized from not -- the boundaries of a pentest engagement, a bug bounty program, a rules-of-engagement document. A hunter is the practitioner who works inside that line: a threat hunter, a bounty hunter, someone actively searching for what others miss, within the bounds they're actually permitted to operate in.
Scope also means attack surface -- the systems, dependencies, and exposures you're responsible for watching. A live CISA/NVD vulnerability feed lives here alongside your profile, not bolted on as an afterthought: staying current on what's actively being exploited is part of the job, not a separate tool you have to context-switch to.
But scope isn't just technical -- it's professional too. This platform exists for the conversations that happen around the work: comparing notes with other practitioners, debating a finding, mentorship in both directions. ScopeHunter only claims what's actually in scope, though: real features are labeled real, prototypes are labeled prototypes.
What's real today
A compliance workspace for SOC 2, CMMC 2.0 (NIST SP 800-171), and ISO 27001: track controls, automate OS-hardening evidence collection, connect cloud infrastructure for automated disk-encryption and configuration evidence, scan for default credentials, and generate System Security Plans -- alongside a professional trust network for security practitioners.
Compliance workspace overview · CMMC 2.0 automation · Credential scanner · FAQ · Feature status