SPA Endpoint & Parameter Map
Map the route, API and parameter attack surface of a modern JS app (Next, Nuxt, React) from its JS bundles. No browser, no auth.
Aug 21, 2026
loading
16 workflows for mapping what you own and what others can see: subdomain enumeration, company attack surface, passive OSINT, screenshots, sitemaps, and mail posture. Each page is a graph you can open node by node and point at your own domains.
Between them they run httpx, subfinder, amass, dnsx and gowitness.
16 items
Map the route, API and parameter attack surface of a modern JS app (Next, Nuxt, React) from its JS bundles. No browser, no auth.
Aug 21, 2026
Bind AWS, GCP, Azure, and Cloudflare vault config into findmytakeover; emit dangling-DNS findings and an evidence report.
Aug 21, 2026
Read a site's sitemap, fetch every page it lists, and inventory each URL's title, description, page type and metadata gaps in one table.
Aug 21, 2026
Enumerate live hosts from a domain, fingerprint TLS and post-quantum readiness with AC Scanner, and emit CBOM-style evidence plus remediation.
Aug 21, 2026
Pull a domain's archived URLs from web archives, fetch the stored response bodies, and scan them for leaked secrets without touching the live site.
Aug 21, 2026
Point one domain, ASN or CIDR at it and get a graded report of every open port and exposed service, distributed and token-free.
Aug 21, 2026
Generate typo, homoglyph, TLD-swap and combosquat variants of a brand domain, probe every candidate, and score the live ones for phishing readiness.
Aug 21, 2026
Permute a keyword into candidate bucket names and check each anonymously across Amazon S3, Google Cloud, Azure Blob and DigitalOcean.
Aug 12, 2026
Read a target's open ports, product versions and matching CVEs out of Shodan's own data, so nothing you run reaches the target.
Aug 10, 2026
Check whether an attacker can send mail as your domain by querying SPF, DKIM, DMARC, MTA-STS and BIMI across every subdomain.
Aug 3, 2026
Confirm which hosts are live, then brute-force paths against each one from a wordlist fetched at run time, and report what answered.
Aug 3, 2026
Profile a domain without sending it a packet: subdomains, DNS, WHOIS and certificate history, plus which hosts are live and what they run.
Aug 3, 2026
Find every subdomain of a domain from passive sources and certificate transparency, then resolve and probe the hosts that answer.
Aug 3, 2026
Find the origin server behind Cloudflare or another WAF by resolving subdomains, filtering CDN ranges, and confirming which IP serves the site.
Aug 3, 2026
Start from a company's registered name and find the domains it has certified, the networks those resolve into, and the hosts that answer.
Aug 3, 2026
Screenshot every live web server across a domain's subdomains, ordered so the forgotten dashboard and the staging copy of production surface first.
Jul 31, 2026