If you're not finding a way to enumerate UUIDs for UUID-based IDORs then you're leaving money on the table.
Here are some ways I've done this in the past:
I've made over 100k on SSRF vulnerabilities.
They aren't always as simple as pointing it at localhost or AWS Metadata service.
Here are some tricks I've picked up over the past 5 years of web app testing:
@Medo_Kll@wld_basha Over the past year, I've been fully focused on penetration testing and learning new things as an offensive security consultant. I'm still doing bug bounties, but now I'm part of the Synack Red team. I'll also be returning to hunting on HackerOne soon. Thanks for asking about me!