Dangling & Takeover
scan
NS zone takeover, CNAME interception, GitHub Pages, unclaimed subdomains.
Active
Exposure & Secrets
exposure
.env files, API keys, AWS credentials, private keys, configs.
Active
JavaScript Mining
jsmine
API endpoints, backend URLs, auth tokens in JS bundles.
Active
API & Access Control
authprobe, graphql
IDOR, broken auth, GraphQL introspection, privilege escalation.
Active
Vulnerabilities
vulnscan
CVEs, XXE, SQLi, XSS, SSRF, authentication bypasses.
Active
Port & Service
apiscan
Open ports, banner grabbing, default credentials, unpatched services.
Active
LLM Verification
judge
Headless L2 verification. Kills false positives before filing.
Active
Exposure Index
leak
LeakIX-fed discovery. Indexes known exposures in your scope.
Active
Program Radar
watch
New paying programs detected. Auto-recons fresh scope 15 min later.
Active
Auto-Report
promote
Drafts reports from verified findings. CVSS tables & PoC steps.
Active
Git Exposure
git
Hardcoded secrets, exposed .git folders, source code leaks.
Active
Filing Automation
submission
Auto-files verified findings to H1, BC, YWH with 30-min pacing.
Active
WhatsApp Alerts
notify
Real-time findings alerts. +50671323131 on high-confidence hits.
Blocked
VPS Sentinel
sentinel
VPS health, CPU/RAM/disk, IDS status, intrusion alerts, remediation.
Active
idle — detector ready.