Playwright Webserver Capture
Feed a list of web servers to playwright. Each URL opens in Chromium, Firefox, or WebKit in parallel and keeps a screenshot, rendered HTML, and meta.json.
27 workflows for mapping what you own and what others can see: subdomain enumeration, company attack surface, passive OSINT, screenshots, sitemaps, and mail posture. Each page is a graph you can open node by node and point at your own domains.
Between them they run httpx, subfinder, amass, gowitness and playwright.
Feed a list of web servers to playwright. Each URL opens in Chromium, Firefox, or WebKit in parallel and keeps a screenshot, rendered HTML, and meta.json.
Enumerate a domain and confirm exposed OpenAPI specs, Spring Actuator endpoints, and debug paths from response content, not from a bare HTTP 200.
Scan a target domain with subfinder and httpx for MCP servers, then write authentication, capability, and poisoning-risk findings to JSONL.
Enumerate a domain and flag weak SSH host keys, key exchange, ciphers, and MACs from an unauthenticated banner. The check does not log in.
Find the origin server behind Cloudflare or another WAF by resolving subdomains, filtering CDN ranges, and confirming which IP serves the site.
Enumerate a domain and read public pages for JavaScript library names and versions, including jQuery, AngularJS, Bootstrap, and Lodash.
Enumerate a domain and fingerprint SAP Commerce HAC, Backoffice, and Data Hub from public pages. The check does not sign in.
Open one URL in Chromium, Firefox, or WebKit with playwright and keep a screenshot, rendered HTML, and meta.json, or a HAR and Playwright trace.
Enumerate a domain and confirm admin panels such as Tomcat Manager, Jenkins, and phpMyAdmin from page markers or auth realms.
Enumerate a domain and classify expired, mismatched, self-signed, and untrusted certificates on port 443. The check reads the handshake only.
Enumerate a domain and probe ports 2375 and 2376 for a Docker Engine API that returns version JSON. The check does not run containers.
Enumerate a domain and confirm web-exposed Terraform state, Docker config, npmrc, and netrc files from their content, not from a bare HTTP 200.
Point one domain, ASN or CIDR at it and get a graded report of every open port and exposed service, distributed and token-free.
Bind AWS, GCP, Azure, and Cloudflare vault config into findmytakeover; emit dangling-DNS findings and an evidence report.
Enumerate live hosts from a domain, fingerprint TLS and post-quantum readiness with AC Scanner, and emit CBOM-style evidence plus remediation.
Read a site's sitemap, fetch every page it lists, and inventory each URL's title, description, page type and metadata gaps in one table.
Map the route, API and parameter attack surface of a modern JS app (Next, Nuxt, React) from its JS bundles. No browser, no auth.
Generate typo, homoglyph, TLD-swap and combosquat variants of a brand domain, probe every candidate, and score the live ones for phishing readiness.
Pull a domain's archived URLs from web archives, fetch the stored response bodies, and scan them for leaked secrets without touching the live site.
Permute a keyword into candidate bucket names and check each anonymously across Amazon S3, Google Cloud, Azure Blob and DigitalOcean.
Read a target's open ports, product versions and matching CVEs out of Shodan's own data, so nothing you run reaches the target.
Confirm which hosts are live, then brute-force paths against each one from a wordlist fetched at run time, and report what answered.
Profile a domain without sending it a packet: subdomains, DNS, WHOIS and certificate history, plus which hosts are live and what they run.
Check whether an attacker can send mail as your domain by querying SPF, DKIM, DMARC, MTA-STS and BIMI across every subdomain.
Find every subdomain of a domain from passive sources and certificate transparency, then resolve and probe the hosts that answer.
Start from a company's registered name and find the domains it has certified, the networks those resolve into, and the hosts that answer.
Screenshot every live web server across a domain's subdomains, ordered so the forgotten dashboard and the staging copy of production surface first.