Blueprint to Making $100K with Caido (Free Bug Bounty Course)

Blueprint to Making $100K with Caido (Free Bug Bounty Course)

Source: YouTube · NahamSec · published Aug 17, 2026 · 1:17:05

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Kaido is a powerful proxy tool for bug bounty hunting, but most users only utilize 10% of its capabilities 0:00-0:05. By leveraging advanced plugins, workflows, and AI integration, hackers can significantly increase their efficiency and finding rates 0:40-0:50.

Key Takeaways:
• Bane's Plugin allows users to create custom view modes that trigger shell commands or AI analysis (like Claude) on specific requests, enabling immediate code explanation or manipulation without leaving the proxy 0:50-1:15.
• Passive workflows can be configured to automatically monitor HTTP history for specific conditions, such as user IDs appearing in requests, and color-code them to generate leads for manual testing 23:30-25:00.
• Active workflows streamline manual tasks by allowing users to send selected requests directly to external tools like SQLmap via shell commands with a single click, reducing friction and maintaining focus 35:10-37:00.
• The GS Analyzer plugin automatically scans JavaScript files for secrets, subdomains, and API endpoints, saving hours of manual code review 42:50-44:00.
• Kaido’s new WebSocket replay feature allows for easy interaction and filtering of WebSocket traffic, revealing vulnerabilities that are often missed in standard HTTP testing 46:10-47:30.
• Shift Agents can be assigned to specific replay collections to automatically test for vulnerabilities like SQLi or IDOR, acting as a "second brain" to catch bugs the hunter might overlook 55:20-58:00.

Mastering these features transforms Kaido from a simple repeater into a comprehensive hunting platform. Building a custom system within the tool is more critical than the tool itself for long-term success 0:54-1:00.

Sources:

  • 0:00 Introduction to Kaido's underutilized potential.
  • 0:50 Overview of Bane's plugin and custom view modes.
  • 23:30 Explanation of passive workflows for lead generation.
  • 35:10 Using active workflows to integrate external tools.
  • 42:50 JavaScript analysis with GS Analyzer.
  • 46:10 WebSocket replay and streamQL filtering.
  • 55:20 Implementing Shift Agents for automated testing.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Most people never get past 10% of what Kaido can actually do. This guy got a $100,000 doing it. Today, he's going to show us the difference. This is Aram, and today he's opening his actual setup, the exact plugins, the workflows, and all of the features he uses to find bugs and also get paid. Here's why this matters, though. Most of us treat proxies like a glorified repeater. I'm guilty of it myself. I send a request. I match and replace some stuff. I run a couple of queries and I pretty much just close it because I live and breathe within the replay tab. That's maybe 5% of what these tools can actually do. And Kaido specifically is moving fast. New features are dropping constantly. Whether you're doing bug bounty, pentest or absec, it's turning into one of the most powerful tools that any…