DNS brute force ACTIVE
A wordlist of about 50 likely names tested one by one. Finds the dev., the staging., the vpn. that never had a certificate.
The free mode is light on resources: it reads the public certificate record and already finds plenty. The advanced mode spends more time and more lookups to squeeze out the maximum results possible. Check out what it offers below.
A wordlist of about 50 likely names tested one by one. Finds the dev., the staging., the vpn. that never had a certificate.
Every subdomain the brute force finds, with the IP it points to.
Which cloud each subdomain lives in, and whether it answers on the web right now.
Subdomains pointing at services that no longer exist โ the unlocked door nobody remembers leaving open.
As many queries as you want, no wait between them, forever.
Dangling CNAME pointing at S3, GitHub Pages, Heroku and other providers known to allow hijacking. We tell you which ones are up for grabs.
Every scan compared against the last one. A new subdomain since last time? We point it out.
The whole list, downloaded in one click, in whatever format your spreadsheet or script prefers.
A screenshot of every subdomain that answers on the web โ see what is running there without opening tab after tab.
You confirm on the next screen, before anything is charged.
weeConsole โ type wallet.ticket or wallet.balance.