Asset inventory
Map a target's hosts, subdomains, ports, and tech, and catch subdomain takeovers, before you attack.
Before you attack a target you need its shape: every host, every subdomain, the ports they expose, and what runs on them. The asset inventory is that map. It collects what recon turns up into one list you can filter, group, and drill into — and it flags the subdomains you can take over.
The asset inventory
Every discovered host and IP lands as a row: its source, open ports, how many speak HTTP, and the flows you've already captured against it. The bar across the top counts total hosts, open ports, HTTP hosts, and how many are in scope, with a lifecycle strip showing how far each host has moved through Discovered → Fingerprinted → Crawled → Scanned — so you see at a glance what you haven't looked at yet.
Filter by host, by source (subdomain discovery, the Crawler, or manual entry), or by lifecycle status. Group by domain to collapse a sprawl of subdomains under their registrable root. Select a host to open its detail tabs:
Open ports with protocol, state, service, version, TLS, and page title.
The paths you've captured on that host, grouped by path with their methods and status codes.
Web servers, services, TLS issuers, JARM and favicon hashes, ASN, and country — the stack, and a way to cluster related hosts.
WHOIS, resolved IPs, tags, the scope toggle, and the subdomain-takeover verdict.
A timeline of what touched the host and when.
Subdomain discovery
Subdomain discovery feeds the inventory. It pulls names passively from certificate transparency (crt.sh), VirusTotal, SecurityTrails, and other public datasets without touching the target, then brute-forces more with a wordlist and your own DNS resolvers. Wildcard detection filters the DNS wildcards that would otherwise drown a brute-force in fake hits, and each name is resolved to its IPs and CNAMEs, with its cloud provider identified.
Subdomain takeover
Discovery checks every name for takeover: a subdomain whose CNAME still points at a deprovisioned service — GitHub Pages, an unclaimed S3 bucket, and the like — that you can claim and serve your own content from. A confirmed hit names the service and lands on the host's Intelligence tab marked Vulnerable.
A subdomain takeover is a high-value finding on its own, and a foothold for phishing, cookie theft, and OAuth abuse against the parent domain. The flagged ones are worth claiming first.
Feed it onward
Tick the hosts worth attacking and send them to the Crawler to map their endpoints, or flip a host into scope so the Proxy and every attack tool stay locked to your real target.
The asset inventory and subdomain discovery, takeover detection included, are Community features.