Work at Elastic? Claim it to respond to reviews as the verified owner.
Found a vulnerability?
If you would rather not deal with the vendor yourself, a BugRater analyst will submit it upstream on your behalf, with your explicit permission, and tell you what came back.
Ask BugRater to submit itPrivate. The report body is encrypted at rest; BugRater holds the key, so the analyst working it can read it. Every read is logged.
HackerOne’s own figures for this program, read from its public page, not reported by researchers and not part of the BugRater grade. Captured 24 Sep 2026.
What it pays, by severity
$1,106,791 paid to researchers in total, $177,799 of it in the last 90 days. Lifetime figure as HackerOne prints it: evidence this program has paid, not a promise about any one report.
Intake & responsiveness · last 90 days
Response targets it sets itself
A target the program declared, not a measurement of it being met.
Getting in the door
Open to submit. Nothing HackerOne publishes stands between a hunter and a first report here.
Over 33 days (18 snapshots): intake up 974 reports; response efficiency up 3 points; 90-day payout up $32,061.
See how this programme’s report load compares to others →
Reviews
0 publishedNo reviews yet.
Who this program credits
816 creditedResearchers HackerOne shows on this program’s public thanks list, best position first. “Recognised” is how many of a hunter’s submissions the program accepted; the ratio is their signal here, not our judgement of them.
| # | Researcher | Reputation | Recognised / submitted |
|---|---|---|---|
| 1 | d0xing | 2,927 | 140 / 152 92% |
| 2 | dee-see | 1,118 | 32 / 40 80% |
| 3 | yuske | 1,010 | 20 / 22 91% |
| 4 | tipsen | 914 | 20 / 24 83% |
| 5 | vultza | 888 | 26 / 40 65% |
| 6 | nnxxrr | 796 | 22 / 52 42% |
| 7 | skraft9 | 771 | 17 / 72 24% |
| 8 | holybugx | 696 | 40 / 63 63% |
| 9 | 3nvz | 543 | 20 / 42 48% |
| 9 | ton-ha | 543 | 0 / 2 0% |
| 11 | m0chan | 541 | 26 / 37 70% |
| 12 | parablack | 509 | 12 / 12 100% |
| 13 | superman85 | 469 | 11 / 17 65% |
| 14 | g0wthr | 460 | 15 / 35 43% |
| 15 | fidelio55 | 456 | 11 / 32 34% |
| 16 | goldenstone | 431 | 11 / 15 73% |
| 17 | lucasfutures | 426 | 13 / 51 25% |
| 18 | alexbrasetvik | 378 | 7 / 8 88% |
| 19 | 7urb0 | 353 | 8 / 10 80% |
| 20 | mateuszek | 343 | 11 / 53 21% |
| 21 | giant_anteater | 297 | 10 / 10 100% |
| 22 | codermak | 286 | 13 / 27 48% |
| 22 | mikey96 | 286 | 4 / 5 80% |
| 24 | 0xryz | 280 | 1 / 4 25% |
| 24 | lolamero | 280 | 6 / 8 75% |
Showing the top 25 of 816 credited on HackerOne.
Facts published by HackerOne on the program's own page, not reported by researchers, and not part of the BugRater grade. Last checked 23 Sep 2026.
Smarter search. Stronger security. Seamless observability. Uncover real-time insights with Search AI.
Scope
99 assets| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| *.ela.st | WILDCARD | ✓ bounty | Critical |
| *.elastic-cloud.com | WILDCARD | ✓ bounty | Critical |
| *.elastic.co | WILDCARD | ✓ bounty | Critical |
| *.elastic.dev | WILDCARD | ✓ bounty | Critical |
| *.elastic.wtf | WILDCARD | ✓ bounty | Critical |
Show all 99 assets
| Asset | Type | Eligibility | Max severity |
|---|---|---|---|
| *.elasticacademy.com | WILDCARD | ✓ bounty | Critical |
| *.elasticaccelerationzone.co | WILDCARD | ✓ bounty | Critical |
| *.elasticapm.co | WILDCARD | ✓ bounty | Critical |
| *.elasticbeats.wtf | WILDCARD | ✓ bounty | Critical |
| *.elasticcloud.wtf | WILDCARD | ✓ bounty | Critical |
| *.elasticgov.com | WILDCARD | ✓ bounty | Critical |
| *.elasticloud.wtf | WILDCARD | ✓ bounty | Critical |
| *.elasticnet.co | WILDCARD | ✓ bounty | Critical |
| *.elasticon.co | WILDCARD | ✓ bounty | Critical |
| *.elasticon.com | WILDCARD | ✓ bounty | Critical |
| *.elasticpartneracademy.com | WILDCARD | ✓ bounty | Critical |
| *.elasticps.co | WILDCARD | ✓ bounty | Critical |
| *.elasticsearch.com | WILDCARD | ✓ bounty | Critical |
| *.elasticsearch.fr | WILDCARD | ✓ bounty | Critical |
| *.elasticsearch.jp | WILDCARD | ✓ bounty | Critical |
| *.elasticsearch.org | WILDCARD | ✓ bounty | Critical |
| *.elasticsearch.wtf | WILDCARD | ✓ bounty | Critical |
| *.elstc.co | WILDCARD | ✓ bounty | Critical |
| *.eops.nl | WILDCARD | ✓ bounty | Critical |
| *.estccdn.com | WILDCARD | ✓ bounty | Critical |
| *.found.io | WILDCARD | ✓ bounty | Critical |
| *.insight.io | WILDCARD | ✓ bounty | Critical |
| *.kibana.wtf | WILDCARD | ✓ bounty | Critical |
| *.logstash.net | WILDCARD | ✓ bounty | Critical |
| *.logstash.wtf | WILDCARD | ✓ bounty | Critical |
| *.prelert.com | WILDCARD | ✓ bounty | Critical |
| *.theelasticast.com | WILDCARD | ✓ bounty | Critical |
| All Elastic Products | OTHER | ✓ bounty | Critical |
| Elastic Behavior Detections | SOURCE CODE | ✓ bounty | Medium |
| Elastic Credentials | OTHER | ✓ bounty | Low |
| elastic-cloud.com | URL | ✓ bounty | Critical |
| elasticsearch-ci.elastic.co | URL | ✓ bounty | Critical |
| https://cloud.elastic.co | URL | ✓ bounty | Critical |
| https://github.com/elastic/beats | SOURCE CODE | ✓ bounty | Critical |
| https://github.com/elastic/elasticsearch | SOURCE CODE | ✓ bounty | Critical |
| https://github.com/elastic/kibana | SOURCE CODE | ✓ bounty | Critical |
| https://github.com/elastic/logstash | SOURCE CODE | ✓ bounty | Critical |
| Software Supply Chain | OTHER | ✓ bounty | Critical |
| Subdomain takeover | OTHER | ✓ bounty | Low |
| www.elastic.co | URL | ✓ bounty | Critical |
| *.ctf.elstc.co | WILDCARD | out | None |
| *.elasticsearch.cn | WILDCARD | out | None |
| *.es.io | WILDCARD | out | None |
| *.ip.es.io | WILDCARD | out | None |
| *.jina.ai | WILDCARD | out | None |
| *.kbndev.co | WILDCARD | out | None |
| *.keephq.dev | WILDCARD | out | None |
| *.swiftype.com | WILDCARD | out | None |
| Beats | DOWNLOADABLE EXECUTABLES | out | None |
| Beats - Auditbeat | DOWNLOADABLE EXECUTABLES | out | None |
| Beats - Filebeat | DOWNLOADABLE EXECUTABLES | out | None |
| Beats - Heartbeat | DOWNLOADABLE EXECUTABLES | out | None |
| Beats - Metricbeat | DOWNLOADABLE EXECUTABLES | out | None |
| Beats - Osquerybeat | DOWNLOADABLE EXECUTABLES | out | None |
| Beats - Packetbeat | DOWNLOADABLE EXECUTABLES | out | None |
| Beats - Winlogbeat | DOWNLOADABLE EXECUTABLES | out | None |
| buy.elastic.co | URL | out | None |
| cloud.elastic.co | URL | out | None |
| community.elastic.co | URL | out | None |
| discuss.elastic.co | URL | out | None |
| Elastic Agent | DOWNLOADABLE EXECUTABLES | out | None |
| Elastic Clients | OTHER | out | None |
| Elastic Cloud Enterprise (ECE) | DOWNLOADABLE EXECUTABLES | out | None |
| Elastic Cloud on Kubernetes (ECK) | DOWNLOADABLE EXECUTABLES | out | None |
| Elastic Defend | DOWNLOADABLE EXECUTABLES | out | None |
| Elastic Distributions of OpenTelemetry (EDOT) | DOWNLOADABLE EXECUTABLES | out | None |
| Elastic Enterprise Search | DOWNLOADABLE EXECUTABLES | out | None |
| Elastic Maps Server | DOWNLOADABLE EXECUTABLES | out | None |
| Elastic Package Registry | OTHER | out | None |
| Elastic Synthetics Monitoring | OTHER | out | None |
| elastic.co | URL | out | None |
| elasticon.elastic.co | URL | out | None |
| Elasticsearch | DOWNLOADABLE EXECUTABLES | out | None |
| Fleet Server | DOWNLOADABLE EXECUTABLES | out | None |
| go.es.co | URL | out | None |
| https://github.com/elastic/*/wiki | WILDCARD | out | None |
| https://github.com/elastic/protections-artifacts/tree/main/behavior/rules/windows | SOURCE CODE | out | None |
| https://github.com/swiftype/*/wiki | WILDCARD | out | None |
| info.elastic.co | URL | out | None |
| ip.es.io | URL | out | None |
| jobs.elastic.co | URL | out | None |
| Kibana | DOWNLOADABLE EXECUTABLES | out | None |
| learn.elastic.co | URL | out | None |
| link.email.elastic.co | URL | out | None |
| Logstash | DOWNLOADABLE EXECUTABLES | out | None |
| Observability - APM Agents | DOWNLOADABLE EXECUTABLES | out | None |
| Observability - APM Server | DOWNLOADABLE EXECUTABLES | out | None |
| Other | OTHER | out | None |
| partners.elastic.co | URL | out | None |
| platform.keephq.dev | URL | out | None |
| sendgrid.elastic.co | URL | out | None |
| track.email.elastic.co | URL | out | None |
| training.elastic.co | URL | out | None |
| wiki.elastic.co | URL | out | None |
HackerOne lists 101 scope entries; its public listing groups many assets under one label, so identical entries are shown once.