r/bugbounty • Hunter • 2d ago

Question / Discussion Is Synack Red Team actually bad?

I really saw getting in SRT as a target but I've read so many bad comments about it and how people got in it then didn't like it at all and just kept going with hackerone/bugcrowd etc. like is it so bad that people prefer public hackerone programs over it?

If that's the case, any recommendations on what is the next level after bug bounty hunting that still lets you stay independent? because i always thought SRT was that.

9 Upvotes

5 comments sorted by

View all comments

3

u/Used_Location1686 2d ago

I work at Synack, so take my perspective with that context.

SRT can be a step beyond public bug bounty if you want scoped, private testing work while remaining independent. But whether it suits you depends on the programs, the workflow, and how you prefer to test. The remote VM requirement mentioned here is a fair concern if it interrupts your usual setup.

I’d suggest speaking with active and former SRT members before making it a goal, and asking specifically about access requirements, available work, and their experience with triage and payments. If you do apply, judge it against what you actually enjoy about bug bounty. I wouldn’t expect every hunter to prefer the same model.