Home Scanner Overview
Scanner overview

What hunts inside the dashboard

One domain in, full org perimeter out. Three modules sweep the surface, hunt exploitable vulnerabilities, and exhume hardcoded secrets — all evidence-backed.

OPERATORanalyst
ACTIVE1 sweep
QUEUE3 pending
P1 OPEN28

Dashboard

Operator overview · last 30 days
● LIVE
Scans this month
22
controlled monthly volume
Critical findings
18
critical issues surfaced
Hosts mapped
18,420
across 73 properties
Avg time-to-finding
5-10m
avg critical discovery
RECENT SCANSSTATUSHITSSTARTED
target.comHUNTING122m ago
api.target.comDONE4714m ago
staging.target.comDONE91h ago
admin.target.comDONE03h ago
The dashboard

Plug and play scanning

Add a target and get vulnerabilities without building a workflow first. The dashboard shows live progress, module state, and findings as the scanner moves from discovery to validation.

Live progress per module
Findings counted as they land
Drill into evidence with one click
MODEAPEX
TARGETtarget.com
PHASESTAGE 1 · ENUM
HITS12

Apex Hunter

Hunts every module across the discovered surface
● STAGE 1
Subdomain Enumeration
51FINDINGS
Exposed Console Logins
1FINDINGS
Subdomain Takeover
2FINDINGS
Misconfiguration
418FINDINGS
CVE Detection
Scanning…
Sensitive File Exposure
Scanning…
Web Vulnerabilities
14FINDINGS
Technology Detection
Clean
Zone Analysis
Scanning…
Surface Discovery

Multi-Domain Discovery

No subdomain left behind

Plug in a single domain and the platform pivots through related infrastructure — sister brands, forgotten staging, vendor-hosted properties, expired marketing sites. Every live host, every open port, every IP that routes into the same blast radius gets pulled into one searchable inventory. The P1s usually live on the asset nobody remembered.

One domain in — full org perimeter out
Live host fingerprinting + port profile
Sister-property and vendor-host pivots
Searchable inventory across every run
1 → allPIVOT DEPTH
65PORTS PROFILED
ZeroMANUAL SETUP
discovery · target.com
MAPPING
$ discover target.com
✓ 73 subdomains · 12 sister properties · 65 ports
→ asset inventory:
api.target.com200
staging.target.comCONSOLE
admin.target.comPANEL
old-cdn.target.comTAKEOVER
dev.target-corp.comJENKINS
vpn.target.io443
apex hunter · target.com
HUNTING 84%
$ hunt target.com
4,217 hosts swept · 12 critical · 47 high
CRIT
XZ Utils backdoor → sshd RCE
CVE-2024-3094 · api-staging
10.0
CRIT
Subdomain takeover · dangling CNAME
old-cdn.target.com
9.6
HIGH
Default credentials on admin panel
jenkins.target.com
8.8
HIGH
SQL injection in /api/v2/users
api.target.com
8.6
MED
TLS 1.0 enabled on edge LB
lb-01.target.com
5.3
The Predator

Apex Hunter

Hunts vulnerabilities like a predator

The Apex Hunter does not guess. It actively probes every alive host across the surface, validates exposures with the exact request that proved them, and ranks results by real exploitability instead of banner noise. One sweep covers up to 5,000 subdomains with high-concurrency hunting, so critical issues surface while the operator is still watching the live run.

Active validation, not banner guessing
Reproducible evidence on every finding
CVSS + EPSS + exposure → real priority
Sweeps up to 5,000 subdomains in one run
5,000TARGET CEILING
HighCONCURRENCY
CVE·CVSS·EPSSRISK MODEL
The 2nd Predator

JS Forensics

Sees what other scanners miss

While the rest are still enumerating, JS Forensics tears apart every JavaScript bundle on the surface and exhumes hardcoded credentials, leaked AWS keys, API tokens, internal endpoints, and the secrets that should never have shipped. The kind of finding that ends a bug-bounty engagement in one report — and rewrites a client's incident-response week.

Hardcoded credentials and API tokens
Leaked AWS, GCP, Stripe, GitHub keys
Undocumented internal endpoints
Bundle and sourcemap deep inspection
40+SECRET PATTERNS
AWS·GCP·StripePROVIDER COVERAGE
Bundles+mapsDEPTH
js forensics · target.com
EXTRACTING
$ forensics target.com --deep
1,847 bundles parsed · 9 secrets exposed
CRIT
AKIA••••••••••QXYZ · production access key
AWS · main.bundle.js · cdn.target.com
P1
CRIT
sk_live_•••••••••5gT4 · live secret key
STRIPE · checkout.chunk.js · app.target.com
P1
HIGH
eyJhbG•••• · static signing token
JWT · admin.vendor.js · admin.target.com
P2
HIGH
internal /api/v2/users/_admin route
API · analytics.js · www.target.com
P2
Three modules, one sweep

The predator pack

01
Surface mapping

Multi-Domain Discovery

One domain in, the whole org perimeter out — sister brands, staging, vendor hosts, every routable IP.

02
The predator

Apex Hunter

Actively hunts exploitable vulnerabilities across up to 5,000 subdomains, ranked by real risk.

03
The 2nd predator

JS Forensics

Tears apart JavaScript bundles for hardcoded creds, AWS keys, and secrets other tools miss.

Three modules. One sweep. Real signal.

Run the full pipeline against your perimeter and see what the predators surface. First scan in under a minute.