Passive Recon Engine

See what's exposed before attackers do.

Enter a target to run a passive recon scan — DNS, subdomains, open ports, TLS, OSINT, and web-layer misconfigurations. No login, no attack payloads.

Use a work email on the same domain as the target — it's how we confirm you're authorised to scan it. Local targets (localhost / IPs) don't need one.
Passive scan only — crawls the site, checks headers/config/TLS, enumerates subdomains, queries OSINT sources, and scans common ports. Nothing here sends attack payloads.
0
Attack payloads sent
8
Recon modules
CT
Subdomain intel source
Target—
—
0%