There are several ways to identify hacker testing traffic at various layers for testing/feature enablement or testing control & monitoring.
Application Layer: User Allowlisting
HackerOne provides each hacker with a forwarding email address
This email can be helpful in identifying hacker testing accounts for allowlisting within the application itself
Session Layer: HTTP Headers
Researchers may add headers to requests such as: βX-HackerOne-Research: [H1 username]β
Network Layer: IP Allowlisting
HackerOne Gateway
Hacker traffic will come from dedicated egress IP address(es)
Hacker VPN traffic can be analyzed for insight into asset testing coverage
Personal IP Check-in
Limited to the H1 Pentest product. Used in lieu of Gateway
"Human Layer": Hacker Vetting & Communication
HackerOne Clear researchers - This feature is not available to all product and platform editions. For more details, please see the HackerOne Product and Platform Entitlement Overview.
Custom alert process for each program
email, phone, Slack, Teams, PagerDuty, and others
HackerOne API
