v3.0 — Now with AI-powered verification

Bug Hunting,
Automated.

24/7 AI-powered vulnerability scanner that finds security flaws in web applications — so you don't have to.

Scroll
Features

Everything you need to hunt bugs

A complete toolkit for automated vulnerability discovery, from reconnaissance to report submission.

65+ Automated Scanners

XSS, SQLi, SSRF, IDOR, CRLF, DOM XSS, and 60+ more vulnerability detection modules.

AI Decision Engine

Intelligent scan planning, context-aware testing, and automated finding verification with AI.

24/7 Autonomous

Runs continuously on VPS infrastructure without manual intervention. Set it and forget it.

Manual Test Guides

Step-by-step instructions for beginners. Learn while you earn with guided exploitation paths.

Real-time Dashboard

Live progress tracking, finding management, and scan status with WebSocket updates.

Auto-Report Submit

Generate professional PoC reports and submit directly to HackerOne or Bugcrowd.

Process

How Ellipse works

Three steps from target to verified vulnerability.

1

Add Target

Enter a HackerOne or Bugcrowd program URL. Ellipse discovers all in-scope assets automatically.

2

Auto Scan

65+ scanners run in parallel. AI plans the attack path, discovers subdomains, and tests for vulnerabilities.

3

Get Results

View findings with PoC exploits, manual test guides, and ready-to-submit reports in your dashboard.

0
Scanners
0
Vuln Types
0
Uptime
0
Platforms
Open Source
HackerOne + Bugcrowd
About Ellipse

Built for ethical security researchers

Ellipse is a next-generation bug bounty automation platform built for ethical security researchers. It combines 65+ automated vulnerability scanners with an AI decision engine to find security flaws in web applications — around the clock.

The platform automates the entire bug bounty workflow: from reconnaissance and subdomain discovery to vulnerability scanning, verification, and report submission. Whether you're a seasoned researcher or just starting out, Ellipse gives you the tools to find real bugs, faster.

Our Mission

Make vulnerability discovery accessible, efficient, and autonomous for every security researcher.

Our Vision

A world where every researcher has AI-powered tools to protect the internet.

ellipse v3.0 — status: active
scanners 65 loaded
ai_engine online
targets monitoring
uptime 99.9%
$ ellipse --version
Ellipse Scanner v3.0.0 — Automated Bug Bounty Platform
FAQ

Frequently asked questions

Ellipse is an automated bug bounty hunting platform that uses 65+ vulnerability scanners and an AI decision engine to find security flaws in web applications. It runs 24/7 on VPS infrastructure and supports platforms like HackerOne and Bugcrowd.

The AI engine analyzes target applications, plans optimal scan strategies, verifies found vulnerabilities to reduce false positives, and learns from previous scan results to improve over time. It combines traditional scanning with intelligent decision-making.

Yes, Ellipse is open-source and free to use. You only need a VPS to run it on. The AI features use external APIs which may have associated costs, but the core scanning engine is completely free.

Ellipse supports HackerOne and Bugcrowd programs. Always ensure you have authorization before scanning. Ellipse is designed for ethical bug bounty hunting only — only scan in-scope assets of programs you're authorized to test.

Deploy Ellipse on a VPS, configure your credentials, add a target program URL, and let it run. The dashboard provides real-time progress, and the manual test guides help you learn as you go. Check the API documentation for detailed setup instructions.

Ellipse is built with Python (Flask/FastAPI), uses Playwright for browser automation, integrates with AI models for decision making, and employs a plugin-based scanner architecture. It runs on Linux VPS with Docker support.

Contact

Get in touch

Have questions about Ellipse? Want to contribute? Drop us a message.

Email
ellipselaab@gmail.com
GitHub
github.com/janhdonline
Location
Running on VPS — Worldwide