Vulnerability Disclosure Program (VDP)
VDPs are meant for responsibly reporting vulnerabilities you encounter — not for actively hunting for fame or reputation. Even if you're just starting out, consider focusing on rewarded bug bounty programs instead.
/engagements/dhs-vdp
42
In Scope
1
Out of Scope
In-Scope Assets (42)
| Asset | Category | Bounty | Quick Links | |
|---|---|---|---|---|
| *.BIOMETRICS.GOV | URL | No | ||
| *.CBP.GOV | URL | No | ||
| *.CISA.GOV | URL | No | ||
| *.CPNIREPORTING.GOV | URL | No | ||
| *.CYBER.GOV | URL | No | ||
| *.CYBERSECURITY.GOV | URL | No | ||
| *.DISASTERASSISTANCE.GOV | URL | No | ||
| *.DOTGOV.GOV | URL | No | ||
| *.E-VERIFY.GOV | URL | No | ||
| *.EVERIFY.GOV | URL | No | ||
| *.EVUS.GOV | URL | No | ||
| *.FEMA.GOV | URL | No | ||
| *.FIRSTRESPONDERTRAINING.GOV | URL | No | ||
| *.FLETA.GOV | URL | No | ||
| *.FLETC.GOV | URL | No | ||
| *.FLOODSMART.GOV | URL | No | ||
| *.GET.GOV | URL | No | ||
| *.GLOBALENTRY.GOV | URL | No | ||
| *.HOMELANDSECURITY.GOV | URL | No | ||
| *.ICE.GOV | URL | No | ||
| *.JUNTOS.GOV | URL | No | ||
| *.LISTO.GOV | URL | No | ||
| *.NIC.GOV | URL | No | ||
| *.NIEM.GOV | URL | No | ||
| *.NMSC.GOV | URL | No | ||
| *.POWER2PREVENT.GOV | URL | No | ||
| *.PREVENTIONRESOURCEFINDER.GOV | URL | No | ||
| *.READY.GOV | URL | No | ||
| *.READYBUSINESS.GOV | URL | No | ||
| *.SAFETYACT.GOV | URL | No | ||
| *.SCHOOLSAFETY.GOV | URL | No | ||
| *.SECRETSERVICE.GOV | URL | No | ||
| *.STOPRANSOMWARE.GOV | URL | No | ||
| *.TOGETHER.GOV | URL | No | ||
| *.TRUMPCARD.GOV | URL | No | ||
| *.TSA.GOV | URL | No | ||
| *.US-CERT.GOV | URL | No | ||
| *.USCG.GOV | URL | No | ||
| *.USCIS.GOV | URL | No | ||
| *.USSS.GOV | URL | No | ||
| *.dhs.gov | URL | No | ||
| https://trumpcard.gov | URL | No |
Out-of-Scope Assets (1)
| Asset | Category | Bounty | |
|---|---|---|---|
| All third party sites and endpoints | OTHER | No |