— no diffs detected in snapshot history yet —
No reports yet — be the first to share your triage timing for Dynatrace.
// peer-sourced response times. platforms won’t publish this — hunters can. anonymized in aggregate.
{
"allows_bounty_splitting": true,
"average_time_to_bounty_awarded": 455,
"average_time_to_first_program_response": 2,
"average_time_to_report_resolved": 816,
"handle": "dynatrace",
"id": 0,
"managed_program": true,
"name": "Dynatrace",
"offers_bounties": true,
"offers_swag": false,
"response_efficiency_percentage": 81,
"submission_state": "open",
"url": "https://hackerone.com/dynatrace",
"website": "https://dynatrace.com",
"targets": {
"in_scope": [
{
"asset_identifier": "*.sprint.apps.dynatracelabs.com",
"asset_type": "WILDCARD",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Wildcard domain for your Dynatrace Platform environment, sometimes also called 3rd gen. \nThis is your default testing environment. Once you request your testing environment you will be redirected to this environment. \n\nAPI endpoints:\n- <environment-id>.sprint.apps.dynatracelabs.com/platform/swagger-ui/index.html\n\nHow to Switch Between APIs:\n1. Navigate to the top right corner of the page.\n2. Locate the drop-down box next to \"Select a Definition.\"\n3. Click on the drop-down box.\n4. Choose the desired API from the available options.",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "*.sprint.dynatracelabs.com",
"asset_type": "WILDCARD",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Wildcard domain for your 2nd gen testing environments - an older but fully supported and regularly updated version of our product.\n\nTo get there, follow the steps described in our Policy page under \"how to access your 2nd gen environment\"\n\nAPI endpoints:\n* <environment-id>.sprint.dynatracelabs.com/rest-api-doc/index.jsp\n\nHow to Switch Between APIs:\n1. Navigate to the top right corner of the page.\n2. Locate the drop-down box next to \"Select a Definition.\"\n3. Click on the drop-down box.\n4. Choose the desired API from the available options.",
"integrity_requirement": "not_defined",
"max_severity": "critical"
},
{
"asset_identifier": "Core Assets",
"asset_type": "OTHER",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Used for asset classification only, please have a look at the policy page or the rewards section. ",
"integrity_requirement": "not_defined",
"max_severity": "critical"
},
{
"asset_identifier": "Dynatrace ActiveGate",
"asset_type": "DOWNLOADABLE_EXECUTABLES",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "ActiveGate is a secure proxy that connects Dynatrace OneAgents to Dynatrace Clusters or other ActiveGates. For more details please have a look at the Useful tips section of the policy or our [support page](https://www.dynatrace.com/support/help/setup-and-configuration/dynatrace-activegate).",
"integrity_requirement": "not_defined",
"max_severity": "critical"
},
{
"asset_identifier": "Dynatrace MobileAgent",
"asset_type": "DOWNLOADABLE_EXECUTABLES",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "The MobileAgent can be used to monitor Android or IOs apps. \nFor more details please have a look at the \"Useful tips\" section of the policy or our [support page](https://www.dynatrace.com/support/help/platform-modules/digital-experience/mobile-applications).",
"integrity_requirement": "not_defined",
"max_severity": "critical"
},
{
"asset_identifier": "Dynatrace OneAgent",
"asset_type": "DOWNLOADABLE_EXECUTABLES",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "OneAgent is responsible for collecting all monitoring data within your environment. \nFor more details please have a look at the \"Useful tips\" section of the policy or our [support page](https://www.dynatrace.com/support/help/setup-and-configuration/dynatrace-oneagent/installation-and-operation). ",
"integrity_requirement": "not_defined",
"max_severity": "critical"
},
{
"asset_identifier": "account-sprint.dynatracelabs.com",
"asset_type": "URL",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "This is the old domain for our account management, the new domain is myaccount-hardening.dynatracelabs.com. Since the domain is still used in some parts of our software, it is still in scope. ",
"integrity_requirement": "not_defined",
"max_severity": "critical"
},
{
"asset_identifier": "https://github.com/Dynatrace",
"asset_type": "SOURCE_CODE",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": false,
"eligible_for_submission": true,
"instruction": "⚠️ **Minimum Reputation Requirement:** Only reporters with at least **150 reputation** are eligible to submit reports for assets in this scope. For more information see our [policy page](https://hackerone.com/dynatrace).\n\nPlease note that only the following repositories are in scope: \n- [OneAgent-Ansible](https://github.com/Dynatrace/Dynatrace-OneAgent-Ansible)\n- [configuration-as-code](https://github.com/Dynatrace/dynatrace-configuration-as-code)\n- [configuration-as-code-core](https://github.com/Dynatrace/dynatrace-configuration-as-code-core)\n- [dynatrace-operator](https://github.com/Dynatrace/dynatrace-operator)\n- [dynatrace-otel-collector](https://github.com/Dynatrace/dynatrace-otel-collector)\n- [heroku-buildpack-dynatrace](https://github.com/Dynatrace/heroku-buildpack-dynatrace)\n- [backstage-plugin](https://github.com/Dynatrace/backstage-plugin)\n- [swift-mobile-sdk](https://github.com/Dynatrace/swift-mobile-sdk)\n- [dynatrace-bootstrapper](https://github.com/Dynatrace/dynatrace-bootstrapper)\n- [OneAgent-SDK-for-Java](https://github.com/Dynatrace/OneAgent-SDK-for-Java)\n- [openkit-js](https://github.com/Dynatrace/openkit-js)\n- [agent-nodejs](https://github.com/Dynatrace/agent-nodejs)\n\nDo not perform any tests against [https://github.com.](https://github.com/).",
"integrity_requirement": "not_defined",
"max_severity": "critical"
},
{
"asset_identifier": "myaccount-hardening.dynatracelabs.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "Myaccount is the place where you can manage your license, subscriptions, users, groups, policies and more. \nFor more details please have a look at the \"Useful tips\" section of the policy or our [support page](https://www.dynatrace.com/support/help/manage/account-management). \n\nAPI endpoints:\n- https://api-hardening.internal.dynatracelabs.com/spec/",
"integrity_requirement": null,
"max_severity": "critical"
},
{
"asset_identifier": "sso-sprint.dynatracelabs.com",
"asset_type": "URL",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": true,
"eligible_for_submission": true,
"instruction": "This domain is used in our single sign on solution, you will see the domain for example during the login process. ",
"integrity_requirement": "not_defined",
"max_severity": "critical"
}
],
"out_of_scope": [
{
"asset_identifier": "*.dev.dynatracelabs.com",
"asset_type": "WILDCARD",
"availability_requirement": "none",
"confidentiality_requirement": "none",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": "none",
"max_severity": "none"
},
{
"asset_identifier": "*.dynatrace.com",
"asset_type": "WILDCARD",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "This is our corporate website and it is out of scope of this program. ",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "EasyTrade demo application",
"asset_type": "DOWNLOADABLE_EXECUTABLES",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "This is a demo application which helps you fill your testing environment with data. \nFor more details please have a look at the \"Useful tips\" section of the policy or the [github repo](https://github.com/Dynatrace/easytrade)",
"integrity_requirement": "not_defined",
"max_severity": "none"
},
{
"asset_identifier": "easyTravel demo application",
"asset_type": "DOWNLOADABLE_EXECUTABLES",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "This is a demo application which helps you fill your testing environment with data. For more details please have a look at the \"Useful tips\" section of the policy or our [community page](https://community.dynatrace.com/t5/Start-with-Dynatrace/easyTravel-Documentation-and-Download/m-p/181271).",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "playground.apps.dynatrace.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Dynatrace Playground is a public sandbox environment. Contains only demo data, so it is out of scope. No real customer, production, or sensitive information is present, meaning vulnerabilities here pose no security risk.",
"integrity_requirement": null,
"max_severity": "none"
},
{
"asset_identifier": "university-staging.dynatracelabs.com",
"asset_type": "URL",
"availability_requirement": "not_defined",
"confidentiality_requirement": "not_defined",
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": null,
"integrity_requirement": "not_defined",
"max_severity": "none"
},
{
"asset_identifier": "wyq34449.sprint.apps.dynatracelabs.com",
"asset_type": "URL",
"availability_requirement": null,
"confidentiality_requirement": null,
"eligible_for_bounty": false,
"eligible_for_submission": false,
"instruction": "Dynatrace Playground is a public sandbox environment. Contains only demo data, so it is out of scope. No real customer, production, or sensitive information is present, meaning vulnerabilities here pose no security risk.",
"integrity_requirement": null,
"max_severity": "none"
}
]
}
}Core Assets· criticalDynatrace ActiveGate· criticalDynatrace MobileAgent· criticalDynatrace OneAgent· criticalEasyTrade demo applicationeasyTravel demo application