attack surface management self-hosted open source

See your attack surface
before someone else maps it.

57 recon tools, aimed at your own perimeter. Every host, service, cert, and exposure they turn up lands in one findings report on your box, and it updates the moment you scan again.

blind spots

You don't know what you're showing.

Somebody runs nmap against your range and walks away knowing more about your infrastructure than half your team does.

Not some scare tactic, but a regular Tuesday for anyone who's done attack surface management on an external environment with more than a dozen exposed services. The tools to check exist, you probably have most of them installed, but nobody's going to run 57 commands and cross-reference the output by hand on a regular basis. So it doesn't get done, gets half-assed, and your knowledge of your actual live environment drifts.

how it works

Four steps. You only do the first.

Point it at yourself, watch it work, read the report, act on what matters. Everything under the hood hangs off those four steps, so there's no pipeline to wire together yourself.

01
scan

Point it at yourself

Your domains, ranges, and hosts. Grab a template or pick tools by hand, then set rate limits, jitter, and time windows per scan so you never trip your own alerts.

02
watch

Watch it work and chain

Output streams in live as each tool runs, and findings trigger their own follow-ups, an open HTTPS port audits its TLS, a WordPress hit runs WPScan, and so on and so on.

03
review

Read one findings report

Every host, service, finding, and credential collapses into one deduplicated report that survives across runs. Scan next month and it shows you what moved, not a second pile to reconcile.

04
act

Test what matters

Export to JSON, CSV, or STIX 2.1, or forward the whole thing to pwnpwl and find out which of those exposures someone can actually walk through.

the armory

Everything an attacker would run against you anyway.

57 tools. The same ones usually used against you, now run by you first so it's useless to threat actors. Add your own in one easy wrapper file.

OSINT & Footprint08
ct-logscloud-bucketsrdaplookalikeshodancensysurlscanhost-infra
Web Vuln07
nucleiniktosqlmaparjunwpscancors-probesearchsploit
AD / SMB / SNMP07
enum4linuxsnmpwalkonesixtyoneresponderget-np-usersget-user-spnssecretsdump
DNS & Subdomain06
amasssubfinderdnsrecondig-axfrtheharvestersubdomain-takeover
Content & Paths06
gobusterffufferoxbusterkatanagaukiterunner
Hosts & Ports04
nmapmasscanarp-scanalive6
TLS & Posture04
sslscantestsslsecurity-headersdns-hygiene
Secrets04
trufflehogsecretfinderdotfilesjwt-tool
Capture03
gowitnessweb-surfacepage-body
Credentials03
hydrakerbrutedefault-creds
Fingerprint02
whatwebwafw00f
Email02
email-infraemail-auth
Wordlist01
cewl
access

Know what you're showing.

In active development. Not publicly released yet, but access is granted on request. If you want to talk about what this could do for your environment, same address.