Bundled with Unleash skills pack. Source: C:\Users\Admin.agents\skills\zdi-researcher-guidelines\SKILL.md
ZDI Researcher Guidelines
Operational rules for Trend Micro Zero Day Initiative (ZDI) acquisition and disclosure.
This skill decides how to pick, package, and submit to ZDI. For the generic fail-closed
eligibility gate used across 0-day campaigns, also run zero-day-target-eligibility.
Re-check live sources before every major campaign or submission:
Do not store portal cookies, session IDs, tax forms, government IDs, or payment details in skills, memory, git, or reports.
1. Program model (what ZDI is)
ZDI is a vendor-agnostic vulnerability acquisition program, not a vendor bug bounty:
- Researcher finds a non-public vulnerability.
- Submits via the secure researcher portal (one vulnerability per case).
- ZDI validates and, at its sole discretion, makes a USD offer.
- On accept, researcher assigns all IP/rights in the vulnerability information to Trend Micro / ZDI.
- ZDI coordinates private vendor disclosure, may ship encrypted/generic customer protections first, then publishes a ZDI advisory after patch or policy deadline.
- Researcher may take public credit (or stay anonymous) and may republish only the public advisory text after ZDI/vendor disclosure — no extra technical detail unless ZDI agrees in writing.
Key differences vs vendor bounties:
- ZDI buys exclusivity until coordinated disclosure.
- After offer acceptance you may not sell, discuss, leak, blog, tweet technical detail, or dual-submit.
- Ownership remains yours until an offer is accepted (or if declined / no offer).
- Offers are non-binding chatter until posted in portal/email and accepted there.
- ZDI will not bury a bought bug because a vendor refuses to fix it.
2. Hard acceptance gates
A candidate is only ZDI-viable when all hard gates pass. Fail closed.
2.1 Latest available version
- Must reproduce on the latest available stable/GA product build as of verification day.
- Beta / pre-release / Insider / Canary / nightly / unreleased hardware fail.
- End-of-life / end-of-support products fail (ZDI will not offer).
- Independently updated components (engines, firmware, definitions, browser runtimes, management servers) must also be current.
- Windows application impact is evaluated on supported Windows 11 branches, not retired Windows 10.
2.2 Widespread deployment
- Target must have credible widespread deployment (enterprise, consumer-at-scale, infrastructure, OEM, cloud, OS-bundled, or critical role).
- Niche tools, lab toys, and low-install specialty software usually fail even if the bug is pretty.
- Prefer products that matter in real enterprise / infrastructure estates.
2.3 Novelty / non-public
- Must be previously unpatched and not already publicly posted or otherwise known.
- First researcher to give ZDI verifiable detail wins; later duplicates get nothing.
- Public root-cause / CVE / advisory / blog / exploit-db / patch diff describing the same issue kills eligibility.
- Variants are OK only when the affected instance + root cause + impact are materially distinct.
2.4 Security-relevant, reproducible impact
- Must cross a real confidentiality / integrity / availability / privilege / sandbox / guest-host / tenant / pre-auth boundary.
- Must be reproducible by ZDI analysts. Unreproducible submissions are not acquired.
- Crash-only reports without proven security impact are weak or rejected.
2.5 Geographic / identity eligibility
- Most countries allowed; FAQ states ZDI cannot accept researchers residing in Cuba, Iran, North Korea, Sudan, or Syria (US law).
- Identity is required for payment and ethics screening — no anonymous payout participation.
- Public advisory credit can still be anonymous/pseudonymous by preference.
- Trend Micro employees/consultants are ineligible.
- Follow employer IP / moonlighting policies before accepting payment.
3. Preference stack (what gets paid well)
Official preference order / emphasis:
- Remote code execution
- Enterprise-affecting software
- Server-side flaws
- OS (desktop or mobile)
- Browsers
- SCADA / IIoT
- Sandbox escapes
- VM escapes
- Security products
Also accepted in principle (with lower or case-by-case interest): broad software including consumer apps, ICS/OT, cloud, and Pwn2Own track targets — subject to current bulletins and valuation.
Valuation dimensions ZDI explicitly uses
Score a candidate on all of these before spending exploit-dev time:
| Factor |
High value |
Low value |
| Product deployment |
pervasive / default / enterprise standard |
niche / rare |
| Privilege gained |
SYSTEM/root/host/pre-auth RCE |
low-integrity info leak |
| Default exposure |
default install / default config |
optional obscure feature |
| Product importance |
DB, mail, DNS, VPN, firewall, hypervisor, IdP, backup, security console |
secondary utility |
| User interaction |
none / drive-by / zero-click |
complex social engineering |
| Exploit reliability |
deterministic, default settings |
racey, heisenbug, needs exotic heap state only |
| Attack surface |
unauth remote / WAN |
local only after admin foothold |
4. Common non-offers (exclusion filter)
ZDI states it does not commonly offer on:
- XSS (reflected/stored/DOM) without exceptional native/tenant boundary impact
- DLL planting / search-order hijack that already assumes attacker-controlled load path equivalent to the impact
- Live websites / SaaS-only config issues (shippable product defects only; do not poke production tenants just to satisfy freshness)
- ActiveX-only issues
- Most consumer-only products, including gaming (exceptions: widely used security products and some IoT)
- Beta / pre-release software
- Anything already public or known
- Products marked EOL / EOS by the vendor
- AI-slop / low-merit bulk submissions (currently clogging the queue; deprioritized)
If unsure about interest in a specific product: email zdi@trendmicro.com before starting deep research.
5. Current product-interest suspensions (check bulletins)
These were active on the portal bulletins as of last verification. Always re-read bulletins — interest shifts without individual notice.
Suspended / do not target for ZDI acquisition
| Product / class |
Bulletin |
Notes |
| Oracle VirtualBox |
2026-07-02 |
Acquisition pause |
| GIMP |
2026-03-31 |
Suspended |
| QEMU |
2026-03-31 |
Suspended |
| Krita |
2026-03-31 |
Suspended |
| Ashlar-Vellum products |
2026-03-31 |
Suspended |
| Embedded systems (general) |
2026-03-31 |
Suspended until further notice |
| Digilent DASYLab |
2025-11-21 |
Indefinite suspend |
| FontForge |
2025-11-21 |
Indefinite suspend |
| Consumer networking equipment |
2025-11-21 |
Any consumer networking gear |
| IrfanView products |
2025-07-08 PDF bulletin |
No longer accepting |
| Foxit PDF Editor |
2025-07-08 |
Not accepting (Reader may still be in scope with limits) |
| PDF-XChange Viewer |
2025-07-08 |
Not accepting (Editor may still be in scope with limits) |
| Windows 10 retiring branches |
2025-09-15 |
App vulns tested on Win11; retiring Win10 OS cases not accepted |
| Windows 7 / other EOL OS |
historical |
EOL never accepted |
PDF reader interest snapshot (subject to change)
| Product |
Accepting |
Notes |
| Adobe Acrobat Reader DC |
Yes — highest PDF payout |
High-level bugs, JS engine ± sandbox escape, standalone escape, parsers; full chain not required |
| pdfforge PDF Architect Free |
Partial |
High-level + parser RCE with clear RCE evidence; no parser info-disclosure |
| pdfforge PDF Creator Free |
Partial |
High-level + non-Architect features only; no rendering/parser (send those to Architect) |
| Foxit PDF Reader |
Partial |
High-level, JS engine, parser RCE with evidence; no Chromium N-days; no parser info-disclosure |
| Foxit PDF Editor |
No |
Suspended |
| PDF-XChange Editor |
Partial |
High-level, JS, parser RCE; no parser info-disclosure |
| PDF-XChange Viewer |
No |
Suspended |
| PDFsam suite |
Partial |
High-level only; no rendering/parser |
| Soda PDF Desktop |
Partial |
High-level only; no rendering/parser |
| Other PDF apps |
Unlikely |
Case-by-case only |
6. Submission packaging rules
6.1 Case hygiene
- One vulnerability per case. Never bundle multiple root causes in one submission.
- Submit through the portal, not cleartext email. Email report bodies without PGP may be rejected; portal uploads need not be encrypted.
- If emailing ZDI about a case, encrypt to the current PGP key.
- Provide enough for an analyst who has never seen the target to reproduce on a clean latest-stable install.
6.2 Minimum technical package
Every case should include:
- Vendor / product / exact version / build / patch level / channel
- Component (service, module, parser, protocol, driver, etc.)
- Vulnerability class and root cause (not just crash site)
- Attack vector (remote/local, auth/unauth, interaction model)
- Impact (RCE, LPE, SBX, VM escape, auth bypass, etc.) and resulting privilege
- Default-config reachability statement
- Step-by-step reproduction on clean latest stable
- PoC / exploit / crash sample / debugger notes as appropriate
- Expected vs actual behavior
- Suggested severity (CVSS-like reasoning; ZDI still decides)
- Novelty statement: closest public bugs and why this differs
- Test environment details (OS build, deps, VM/hardware)
- Hashes of PoC files and, when practical, affected binaries
- Discovery date and confirmation it was not disclosed elsewhere
Format is flexible (write-up, annotated PoC, exploit). Quality and reproducibility beat prose volume.
6.3 Quality bar that maximizes offers
- Prefer root-cause + reliable trigger over “here is a crash”.
- For memory corruption: show controlled crash, corruption primitive, or control-flow influence sufficient to argue RCE potential when full exploit is not required.
- For “high-level” bugs (command injection, path traversal, LPE, auth bypass): full practical impact demo.
- State whether bug works on default install and default settings.
- Avoid AI-generated filler, unverified claims, or shotgun duplicate cases — queue is explicitly overloaded with low-merit AI submissions and those are deprioritized.
- Do not require ZDI to buy licenses they cannot get; prefer widely available enterprise/eval builds when possible, and document license needs early.
6.4 What not to put in a case
- Other researchers’ work presented as yours
- Employer confidential / stolen internal bug data
- Production customer data, live-site testing against third parties without authorization
- Extra unrelated bugs (split cases)
- Public exploit rebrands / N-day with no novel root cause
- Credentials, cookies, or personal payment data inside the vulnerability write-up
7. Process, SLAs, and researcher obligations
7.1 Lifecycle
Discover → (optional interest email) → Portal submit (1 bug/case)
→ ZDI exclusive evaluation license while under review
→ Validate / reproduce / value
→ Offer | No-offer | Need-info
→ Accept offer (≤ 7 calendar days or offer rescinds)
→ IP assignment + payment (wire/check; often 2–3 weeks)
→ Vendor notify + coordination (standard 120 days)
→ Patch or policy deadline → ZDI public advisory (+ optional credit)
→ Researcher may republish the public advisory text only
7.2 Timing expectations
| Event |
Expectation |
| Initial ZDI response (normal) |
~2 weeks average historically |
| Queue status HIGH (current bulletin) |
> 6 weeks for most cases; critical cases prioritized |
| Offer validity |
7 calendar days, then rescinded (may re-ask) |
| Payment after accept |
~2–3 weeks depending on method / tax forms |
| Vendor first ack window |
5 business days, then second try +5 |
| Vendor unreachable |
possible limited public advisory ~15 business days after first contact |
| Standard patch window after vendor ack |
120 days |
| Faulty/incomplete prior patch (critical + active/imminent exploit) |
30 days |
| Faulty patch critical/high with partial protection, exploit not imminent |
60 days |
| Other faulty-patch class |
90 days |
| Extensions past 120 days |
rare; ZDI sole discretion |
7.3 Exclusivity and confidentiality (post-accept)
After accepting an offer you must not:
- distribute, sell, assign elsewhere, discuss, or disclose vulnerability details
- publish write-ups, tweets, conference talks, or PoCs before ZDI/vendor public disclosure
- tip third parties or other programs
Violating exclusivity can mean program ban and loss of trust/payment remedies under the agreement.
During evaluation (pre-accept), ZDI has an exclusive license to evaluate; you still own the bug and may withdraw, but do not publicly burn it if you want an offer.
7.4 Credit and republish rights
- Choose credit name / anonymous / pseudonym in portal preferences.
- After public ZDI and/or vendor disclosure, you may republish the public disclosure text only, unmodified, unless ZDI agrees otherwise.
- Republishing early or modifying the advisory can forfeit credit.
7.5 Payment and account
- Methods: wire transfer or mailed check (set in portal).
- US persons: W-9 before payment; 1099 as required.
- Non-US: W-8BEN / W-8BEN-E and government ID as requested; email forms to zdi@trendmicro.com (PGP preferred).
- Account must be verified before payout.
- Enable TOTP when available.
- Keep profile/payment data accurate; agreement requires prompt updates.
- Offers and acceptances are binding only via portal/email offer + formal accept (or manually signed writing) — phone chat is non-binding.
7.6 Reward tiers (points = USD paid, then multipliers)
| Tier |
Points |
One-time bonus |
Future submission bonus |
Point multiplier |
| Bronze |
15,000 |
$2,000 |
10% |
10% |
| Silver |
25,000 |
$5,000 |
15% |
15% |
| Gold |
45,000 |
$10,000 |
20% |
25% |
| Platinum |
65,000 |
$25,000 |
25% |
50% |
Example: Platinum base valuation $4,000 → paid $5,000 (25% bonus) and 6,000 points (50% multiplier).
Referral: referred researcher’s first acquisition grants referrer 2,500 points (registration alone does not count).
Pwn2Own wins are purchased into the same disclosure machine under contest rules; TIP/targeted incentives may pay much higher for full working exploits on listed targets when active.
8. Pre-research decision checklist
Run before deep work. Any FAIL stops the campaign for ZDI purposes.
[ ] Bulletins checked today — product not suspended
[ ] Latest stable/GA version identified from vendor authority
[ ] Not beta / pre-release / EOL / EOS
[ ] Widespread deployment evidence recorded
[ ] Impact in preference stack or clearly high enterprise value
[ ] Not XSS / DLL plant / live-site / ActiveX / consumer-game junk case
[ ] Novelty search clean (CVE, ZDI upcoming/published, vendor notes, git, blogs, exploit indexes)
[ ] Default-config remote or high-value local boundary plausible
[ ] Clean lab path exists (license, hardware, firmware)
[ ] Interest email sent if product is borderline
[ ] zero-day-target-eligibility campaign card opened
9. Pre-submit decision checklist
[ ] Reproduced on latest stable within revalidation window
[ ] One root cause only in this case
[ ] PoC/repro steps work on clean install
[ ] Version/build/component table complete
[ ] Impact and privilege clearly demonstrated or evidenced
[ ] Novelty ledger attached
[ ] No prior public post / dual submission / conference abstract
[ ] Researcher agreement terms understood (assignment + exclusivity on accept)
[ ] Tax/payment profile ready if offer expected
[ ] Queue delay acceptable (HIGH may exceed six weeks)
[ ] Offer response plan ready (7-day clock)
10. Campaign card (ZDI-specific)
ZDI target:
Product / channel / latest build proof:
Component / attack surface:
Boundary crossed:
Preference-stack fit (RCE/enterprise/server/OS/browser/SCADA/sbx/VM/security):
Deployment evidence:
Default-config reachable?
User interaction:
Reliability:
Bulletin status (clear / suspended / PDF-limited):
Closest public work + distinction:
Lab recipe:
Report package paths:
Interest-email result (if any):
Submit-by date:
Case ID:
Status: RESEARCH | PACKAGING | SUBMITTED | NEEDINFO | OFFER | ACCEPTED | DECLINED | NO_OFFER | PUBLIC
Revalidation deadline:
11. Agent operating rules
When helping with ZDI work:
- Gate first with this skill +
zero-day-target-eligibility before exploit engineering.
- Re-fetch bulletins/criteria if last verification is stale or user is about to submit.
- Prefer targets in the preference stack with clear widespread deployment.
- Reject or warn hard on suspended products and classic non-offer classes.
- Package reports for analyst reproducibility, not blog aesthetics.
- Never dual-track a bug to another buyer/program once ZDI offer is accepted.
- Never place cookies, sessionids, W-8/W-9 content, government IDs, or bank details in repo files, skills, or memory.
- After accept, treat all technical detail as embargoed until official public advisory.
- For Windows targets, validate on supported Windows 11, not retired Win10 impact stories.
- If queue is HIGH, prioritize critical, high-clarity cases over speculative low-impact spam.
12. Quick fail patterns
- “Works on last year’s build only”
- “Needs beta flag / debug SKU”
- “Consumer game trainer bug”
- “XSS in marketing site”
- “DLL plant from attacker-controlled directory already writable at same privilege”
- “Public CVE with different trigger string”
- “QEMU/VirtualBox/GIMP/embedded/consumer router after suspension dates”
- “Parser info-leak only on a PDF product that bars info-disclosure”
- “AI summary of possible bug without working PoC”
- “Three root causes in one portal case”
13. Verification before calling a target “ZDI-ready”
1---2name: zdi-researcher-guidelines3description: Use when planning, triaging, packaging, or submitting vulnerability research to Trend Micro Zero Day Initiative (ZDI). Encodes official submission criteria, valuation factors, disclosure timelines, exclusivity rules, current product-interest suspensions, report quality bar, and portal workflow. Pair with zero-day-target-eligibility before investing in a target.4license: MIT5---67> Bundled with Unleash skills pack. Source: C:\Users\Admin\.agents\skills\zdi-researcher-guidelines\SKILL.md89# ZDI Researcher Guidelines1011Operational rules for Trend Micro **Zero Day Initiative (ZDI)** acquisition and disclosure.12This skill decides **how to pick, package, and submit** to ZDI. For the generic fail-closed13eligibility gate used across 0-day campaigns, also run `zero-day-target-eligibility`.1415Re-check live sources before every major campaign or submission:1617| Source | URL |18|---|---|19| Submission criteria | https://www.zerodayinitiative.com/portal/criteria/ |20| Program bulletins / interest changes | https://www.zerodayinitiative.com/portal/bulletins/ |21| Disclosure policy | https://www.zerodayinitiative.com/advisories/disclosure_policy/ |22| Benefits / valuation / tiers | https://www.zerodayinitiative.com/about/benefits/ |23| FAQ | https://www.zerodayinitiative.com/about/faq/ |24| Researcher agreement | https://zerodayinitiative.com/documents/zdi_researcher_agreement.pdf |25| PGP key (email only) | https://www.zerodayinitiative.com/documents/zdi-pgp-key.asc |26| Published advisories | https://www.zerodayinitiative.com/advisories/published/ |27| Upcoming advisories | https://www.zerodayinitiative.com/advisories/upcoming/ |28| Contact | zdi@trendmicro.com |2930Do **not** store portal cookies, session IDs, tax forms, government IDs, or payment details in skills, memory, git, or reports.3132## 1. Program model (what ZDI is)3334ZDI is a **vendor-agnostic vulnerability acquisition** program, not a vendor bug bounty:35361. Researcher finds a **non-public** vulnerability.372. Submits via the **secure researcher portal** (one vulnerability per case).383. ZDI validates and, at its sole discretion, makes a **USD offer**.394. On accept, researcher **assigns all IP/rights** in the vulnerability information to Trend Micro / ZDI.405. ZDI coordinates private vendor disclosure, may ship **encrypted/generic** customer protections first, then publishes a ZDI advisory after patch or policy deadline.416. Researcher may take **public credit** (or stay anonymous) and may **republish only the public advisory text** after ZDI/vendor disclosure — no extra technical detail unless ZDI agrees in writing.4243Key differences vs vendor bounties:4445- ZDI buys **exclusivity** until coordinated disclosure.46- After offer acceptance you may **not** sell, discuss, leak, blog, tweet technical detail, or dual-submit.47- Ownership remains yours **until** an offer is accepted (or if declined / no offer).48- Offers are non-binding chatter until posted in portal/email and accepted there.49- ZDI will **not** bury a bought bug because a vendor refuses to fix it.5051## 2. Hard acceptance gates5253A candidate is only ZDI-viable when **all** hard gates pass. Fail closed.5455### 2.1 Latest available version5657- Must reproduce on the **latest available stable/GA** product build **as of verification day**.58- Beta / pre-release / Insider / Canary / nightly / unreleased hardware **fail**.59- End-of-life / end-of-support products **fail** (ZDI will not offer).60- Independently updated components (engines, firmware, definitions, browser runtimes, management servers) must also be current.61- Windows application impact is evaluated on **supported Windows 11** branches, not retired Windows 10.6263### 2.2 Widespread deployment6465- Target must have **credible widespread deployment** (enterprise, consumer-at-scale, infrastructure, OEM, cloud, OS-bundled, or critical role).66- Niche tools, lab toys, and low-install specialty software usually fail even if the bug is pretty.67- Prefer products that matter in real enterprise / infrastructure estates.6869### 2.3 Novelty / non-public7071- Must be **previously unpatched** and **not already publicly posted or otherwise known**.72- First researcher to give ZDI **verifiable** detail wins; later duplicates get nothing.73- Public root-cause / CVE / advisory / blog / exploit-db / patch diff describing the same issue kills eligibility.74- Variants are OK only when the **affected instance + root cause + impact** are materially distinct.7576### 2.4 Security-relevant, reproducible impact7778- Must cross a real confidentiality / integrity / availability / privilege / sandbox / guest-host / tenant / pre-auth boundary.79- Must be **reproducible** by ZDI analysts. Unreproducible submissions are not acquired.80- Crash-only reports without proven security impact are weak or rejected.8182### 2.5 Geographic / identity eligibility8384- Most countries allowed; FAQ states ZDI **cannot accept** researchers residing in **Cuba, Iran, North Korea, Sudan, or Syria** (US law).85- Identity is required for payment and ethics screening — no anonymous payout participation.86- Public advisory credit can still be anonymous/pseudonymous by preference.87- Trend Micro employees/consultants are ineligible.88- Follow employer IP / moonlighting policies before accepting payment.8990## 3. Preference stack (what gets paid well)9192Official preference order / emphasis:93941. **Remote code execution**952. **Enterprise-affecting software**963. **Server-side** flaws974. **OS** (desktop or mobile)985. **Browsers**996. **SCADA / IIoT**1007. **Sandbox escapes**1018. **VM escapes**1029. **Security products**103104Also accepted in principle (with lower or case-by-case interest): broad software including consumer apps, ICS/OT, cloud, and **Pwn2Own track** targets — subject to current bulletins and valuation.105106### Valuation dimensions ZDI explicitly uses107108Score a candidate on all of these before spending exploit-dev time:109110| Factor | High value | Low value |111|---|---|---|112| Product deployment | pervasive / default / enterprise standard | niche / rare |113| Privilege gained | SYSTEM/root/host/pre-auth RCE | low-integrity info leak |114| Default exposure | default install / default config | optional obscure feature |115| Product importance | DB, mail, DNS, VPN, firewall, hypervisor, IdP, backup, security console | secondary utility |116| User interaction | none / drive-by / zero-click | complex social engineering |117| Exploit reliability | deterministic, default settings | racey, heisenbug, needs exotic heap state only |118| Attack surface | unauth remote / WAN | local only after admin foothold |119120## 4. Common non-offers (exclusion filter)121122ZDI states it does **not commonly offer** on:123124- **XSS** (reflected/stored/DOM) without exceptional native/tenant boundary impact125- **DLL planting / search-order hijack** that already assumes attacker-controlled load path equivalent to the impact126- **Live websites** / SaaS-only config issues (shippable product defects only; do not poke production tenants just to satisfy freshness)127- **ActiveX-only** issues128- **Most consumer-only products**, including **gaming** (exceptions: widely used security products and some IoT)129- **Beta / pre-release** software130- Anything **already public or known**131- Products marked **EOL / EOS** by the vendor132- AI-slop / low-merit bulk submissions (currently clogging the queue; deprioritized)133134If unsure about interest in a specific product: **email zdi@trendmicro.com before starting deep research**.135136## 5. Current product-interest suspensions (check bulletins)137138These were active on the portal bulletins as of last verification. **Always re-read bulletins** — interest shifts without individual notice.139140### Suspended / do not target for ZDI acquisition141142| Product / class | Bulletin | Notes |143|---|---|---|144| Oracle VirtualBox | 2026-07-02 | Acquisition pause |145| GIMP | 2026-03-31 | Suspended |146| QEMU | 2026-03-31 | Suspended |147| Krita | 2026-03-31 | Suspended |148| Ashlar-Vellum products | 2026-03-31 | Suspended |149| Embedded systems (general) | 2026-03-31 | Suspended until further notice |150| Digilent DASYLab | 2025-11-21 | Indefinite suspend |151| FontForge | 2025-11-21 | Indefinite suspend |152| Consumer networking equipment | 2025-11-21 | Any consumer networking gear |153| IrfanView products | 2025-07-08 PDF bulletin | No longer accepting |154| Foxit PDF Editor | 2025-07-08 | Not accepting (Reader may still be in scope with limits) |155| PDF-XChange Viewer | 2025-07-08 | Not accepting (Editor may still be in scope with limits) |156| Windows 10 retiring branches | 2025-09-15 | App vulns tested on Win11; retiring Win10 OS cases not accepted |157| Windows 7 / other EOL OS | historical | EOL never accepted |158159### PDF reader interest snapshot (subject to change)160161| Product | Accepting | Notes |162|---|---|---|163| Adobe Acrobat Reader DC | Yes — highest PDF payout | High-level bugs, JS engine ± sandbox escape, standalone escape, parsers; full chain not required |164| pdfforge PDF Architect Free | Partial | High-level + parser RCE with clear RCE evidence; no parser info-disclosure |165| pdfforge PDF Creator Free | Partial | High-level + non-Architect features only; **no** rendering/parser (send those to Architect) |166| Foxit PDF Reader | Partial | High-level, JS engine, parser RCE with evidence; no Chromium N-days; no parser info-disclosure |167| Foxit PDF Editor | No | Suspended |168| PDF-XChange Editor | Partial | High-level, JS, parser RCE; no parser info-disclosure |169| PDF-XChange Viewer | No | Suspended |170| PDFsam suite | Partial | High-level only; no rendering/parser |171| Soda PDF Desktop | Partial | High-level only; no rendering/parser |172| Other PDF apps | Unlikely | Case-by-case only |173174## 6. Submission packaging rules175176### 6.1 Case hygiene177178- **One vulnerability per case.** Never bundle multiple root causes in one submission.179- Submit through the **portal**, not cleartext email. Email report bodies without PGP may be rejected; portal uploads need not be encrypted.180- If emailing ZDI about a case, encrypt to the current PGP key.181- Provide enough for an analyst who has never seen the target to reproduce on a clean latest-stable install.182183### 6.2 Minimum technical package184185Every case should include:1861871. **Vendor / product / exact version / build / patch level / channel**1882. **Component** (service, module, parser, protocol, driver, etc.)1893. **Vulnerability class** and **root cause** (not just crash site)1904. **Attack vector** (remote/local, auth/unauth, interaction model)1915. **Impact** (RCE, LPE, SBX, VM escape, auth bypass, etc.) and resulting privilege1926. **Default-config reachability** statement1937. **Step-by-step reproduction** on clean latest stable1948. **PoC / exploit / crash sample / debugger notes** as appropriate1959. **Expected vs actual behavior**19610. **Suggested severity** (CVSS-like reasoning; ZDI still decides)19711. **Novelty statement**: closest public bugs and why this differs19812. **Test environment** details (OS build, deps, VM/hardware)19913. **Hashes** of PoC files and, when practical, affected binaries20014. **Discovery date** and confirmation it was not disclosed elsewhere201202Format is flexible (write-up, annotated PoC, exploit). Quality and reproducibility beat prose volume.203204### 6.3 Quality bar that maximizes offers205206- Prefer **root-cause + reliable trigger** over “here is a crash”.207- For memory corruption: show **controlled crash, corruption primitive, or control-flow influence** sufficient to argue RCE potential when full exploit is not required.208- For “high-level” bugs (command injection, path traversal, LPE, auth bypass): full practical impact demo.209- State whether bug works on **default install** and **default settings**.210- Avoid AI-generated filler, unverified claims, or shotgun duplicate cases — queue is explicitly overloaded with low-merit AI submissions and those are deprioritized.211- Do not require ZDI to buy licenses they cannot get; prefer widely available enterprise/eval builds when possible, and document license needs early.212213### 6.4 What not to put in a case214215- Other researchers’ work presented as yours216- Employer confidential / stolen internal bug data217- Production customer data, live-site testing against third parties without authorization218- Extra unrelated bugs (split cases)219- Public exploit rebrands / N-day with no novel root cause220- Credentials, cookies, or personal payment data inside the vulnerability write-up221222## 7. Process, SLAs, and researcher obligations223224### 7.1 Lifecycle225226```text227Discover → (optional interest email) → Portal submit (1 bug/case)228 → ZDI exclusive evaluation license while under review229 → Validate / reproduce / value230 → Offer | No-offer | Need-info231 → Accept offer (≤ 7 calendar days or offer rescinds)232 → IP assignment + payment (wire/check; often 2–3 weeks)233 → Vendor notify + coordination (standard 120 days)234 → Patch or policy deadline → ZDI public advisory (+ optional credit)235 → Researcher may republish the public advisory text only236```237238### 7.2 Timing expectations239240| Event | Expectation |241|---|---|242| Initial ZDI response (normal) | ~2 weeks average historically |243| Queue status HIGH (current bulletin) | **> 6 weeks** for most cases; critical cases prioritized |244| Offer validity | **7 calendar days**, then rescinded (may re-ask) |245| Payment after accept | ~2–3 weeks depending on method / tax forms |246| Vendor first ack window | 5 business days, then second try +5 |247| Vendor unreachable | possible limited public advisory ~15 business days after first contact |248| Standard patch window after vendor ack | **120 days** |249| Faulty/incomplete prior patch (critical + active/imminent exploit) | **30 days** |250| Faulty patch critical/high with partial protection, exploit not imminent | **60 days** |251| Other faulty-patch class | **90 days** |252| Extensions past 120 days | rare; ZDI sole discretion |253254### 7.3 Exclusivity and confidentiality (post-accept)255256After accepting an offer you **must not**:257258- distribute, sell, assign elsewhere, discuss, or disclose vulnerability details259- publish write-ups, tweets, conference talks, or PoCs before ZDI/vendor public disclosure260- tip third parties or other programs261262Violating exclusivity can mean **program ban** and loss of trust/payment remedies under the agreement.263264During evaluation (pre-accept), ZDI has an exclusive license to evaluate; you still own the bug and may withdraw, but do not publicly burn it if you want an offer.265266### 7.4 Credit and republish rights267268- Choose credit name / anonymous / pseudonym in portal preferences.269- After **public** ZDI and/or vendor disclosure, you may republish **the public disclosure text only**, unmodified, unless ZDI agrees otherwise.270- Republishing early or modifying the advisory can forfeit credit.271272### 7.5 Payment and account273274- Methods: **wire transfer** or **mailed check** (set in portal).275- US persons: **W-9** before payment; 1099 as required.276- Non-US: **W-8BEN** / **W-8BEN-E** and government ID as requested; email forms to zdi@trendmicro.com (PGP preferred).277- Account must be **verified** before payout.278- Enable TOTP when available.279- Keep profile/payment data accurate; agreement requires prompt updates.280- Offers and acceptances are binding only via **portal/email offer + formal accept** (or manually signed writing) — phone chat is non-binding.281282### 7.6 Reward tiers (points = USD paid, then multipliers)283284| Tier | Points | One-time bonus | Future submission bonus | Point multiplier |285|---|---:|---:|---:|---:|286| Bronze | 15,000 | $2,000 | 10% | 10% |287| Silver | 25,000 | $5,000 | 15% | 15% |288| Gold | 45,000 | $10,000 | 20% | 25% |289| Platinum | 65,000 | $25,000 | 25% | 50% |290291Example: Platinum base valuation $4,000 → paid $5,000 (25% bonus) and 6,000 points (50% multiplier).292293Referral: referred researcher’s **first acquisition** grants referrer **2,500 points** (registration alone does not count).294295Pwn2Own wins are purchased into the same disclosure machine under contest rules; TIP/targeted incentives may pay much higher for full working exploits on listed targets when active.296297## 8. Pre-research decision checklist298299Run before deep work. Any **FAIL** stops the campaign for ZDI purposes.300301```text302[ ] Bulletins checked today — product not suspended303[ ] Latest stable/GA version identified from vendor authority304[ ] Not beta / pre-release / EOL / EOS305[ ] Widespread deployment evidence recorded306[ ] Impact in preference stack or clearly high enterprise value307[ ] Not XSS / DLL plant / live-site / ActiveX / consumer-game junk case308[ ] Novelty search clean (CVE, ZDI upcoming/published, vendor notes, git, blogs, exploit indexes)309[ ] Default-config remote or high-value local boundary plausible310[ ] Clean lab path exists (license, hardware, firmware)311[ ] Interest email sent if product is borderline312[ ] zero-day-target-eligibility campaign card opened313```314315## 9. Pre-submit decision checklist316317```text318[ ] Reproduced on latest stable within revalidation window319[ ] One root cause only in this case320[ ] PoC/repro steps work on clean install321[ ] Version/build/component table complete322[ ] Impact and privilege clearly demonstrated or evidenced323[ ] Novelty ledger attached324[ ] No prior public post / dual submission / conference abstract325[ ] Researcher agreement terms understood (assignment + exclusivity on accept)326[ ] Tax/payment profile ready if offer expected327[ ] Queue delay acceptable (HIGH may exceed six weeks)328[ ] Offer response plan ready (7-day clock)329```330331## 10. Campaign card (ZDI-specific)332333```text334ZDI target:335Product / channel / latest build proof:336Component / attack surface:337Boundary crossed:338Preference-stack fit (RCE/enterprise/server/OS/browser/SCADA/sbx/VM/security):339Deployment evidence:340Default-config reachable? 341User interaction:342Reliability:343Bulletin status (clear / suspended / PDF-limited):344Closest public work + distinction:345Lab recipe:346Report package paths:347Interest-email result (if any):348Submit-by date:349Case ID:350Status: RESEARCH | PACKAGING | SUBMITTED | NEEDINFO | OFFER | ACCEPTED | DECLINED | NO_OFFER | PUBLIC351Revalidation deadline:352```353354## 11. Agent operating rules355356When helping with ZDI work:3573581. **Gate first** with this skill + `zero-day-target-eligibility` before exploit engineering.3592. **Re-fetch bulletins/criteria** if last verification is stale or user is about to submit.3603. Prefer targets in the **preference stack** with clear widespread deployment.3614. Reject or warn hard on suspended products and classic non-offer classes.3625. Package reports for **analyst reproducibility**, not blog aesthetics.3636. Never dual-track a bug to another buyer/program once ZDI offer is accepted.3647. Never place cookies, sessionids, W-8/W-9 content, government IDs, or bank details in repo files, skills, or memory.3658. After accept, treat all technical detail as **embargoed** until official public advisory.3669. For Windows targets, validate on **supported Windows 11**, not retired Win10 impact stories.36710. If queue is HIGH, prioritize **critical, high-clarity** cases over speculative low-impact spam.368369## 12. Quick fail patterns370371- “Works on last year’s build only”372- “Needs beta flag / debug SKU”373- “Consumer game trainer bug”374- “XSS in marketing site”375- “DLL plant from attacker-controlled directory already writable at same privilege”376- “Public CVE with different trigger string”377- “QEMU/VirtualBox/GIMP/embedded/consumer router after suspension dates”378- “Parser info-leak only on a PDF product that bars info-disclosure”379- “AI summary of possible bug without working PoC”380- “Three root causes in one portal case”381382## 13. Verification before calling a target “ZDI-ready”383384- [ ] Live criteria page still matches hard gates above385- [ ] Live bulletins do not suspend the product/class386- [ ] Latest-stable reproduction evidence exists387- [ ] Deployment + preference-stack story is credible388- [ ] Novelty ledger complete389- [ ] Report package meets section 6390- [ ] Exclusivity/payment consequences understood391- [ ] Campaign card updated392