Analyze JavaScript Code
Retrieve JavaScript from a URL list, unpack it, and mine endpoints, wordlists, CVEs, secrets, and insecure client-side patterns in one nestable pass.
Aug 13, 2026
loading
A module is a nestable subgraph with a typed face: a process you drop into a workflow. 28 public modules, grouped the way Hive groups them.
A tool is one binary and its flags. A workflow is a graph you run as a product. Start from a module when you already have a parent graph and need this process in it.
28 items
Retrieve JavaScript from a URL list, unpack it, and mine endpoints, wordlists, CVEs, secrets, and insecure client-side patterns in one nestable pass.
Aug 13, 2026
Crawl live web server URLs, follow links and parse JavaScript, and emit a path map per asset. Nest when the surface is linked, not guessed or archived.
Aug 13, 2026
Brute-force web server URLs to find hidden paths. Heuristics drop masked 404s. Built-in or custom wordlist. Thousands of servers in parallel.
Aug 13, 2026
Search OSINT sources for a host list to find hidden paths. Historical and recent URLs, normalized. Thousands of hosts. No traffic to the target.
Aug 13, 2026
Query A, AAAA, CNAME, MX, NS, TXT, CAA, and PTR for a host, IP, or CIDR list. Keep resolving names, addresses, and associated hostnames as line lists.
Aug 13, 2026
Crawl live web servers and pull hostnames from links, script, and headers. Input is URLs, not root domains. Last in the hostname enum family; nest after probe.
Aug 13, 2026
Generate DNS permutations from hostnames you have. Alter labels for staging, regions, and related software, then resolve. Built-in wordlist or org naming.
Aug 13, 2026
Enumerate hostnames from passive OSINT sources. No API keys required; optional keys expand sources. Finds related roots, not only subdomains of the target.
Aug 13, 2026
Brute-force sub-subdomains of known hostnames. Rank likely prefixes, generate FUZZ at each DNS level, and resolve. Built-in or custom level wordlists. Caps per level.
Aug 13, 2026
Wordlist DNS brute force against root domains. Finds first-level names OSINT missed. Input is domains plus an optional custom wordlist, not known hostnames.
Aug 13, 2026
Identify the service on each open port. Service fingerprinting returns protocol, banner, product, and version for misconfig and credential tests.
Aug 13, 2026
Identify CMS, CDN, and WAF on live web servers. Technology detection names server software, runtimes, and frameworks with version status.
Aug 13, 2026
Web app fuzzing with active DAST. Crawl each app, inject payloads into discovered inputs, report insecure behaviors, and recrawl for stored issues.
Aug 13, 2026
Derive DNS brute-force wordlists from known hostnames. Root-class and recursive level lists for the hostname enum modules. Does not resolve names.
Aug 13, 2026
Wire findings, ports, DNS, WHOIS, screenshots, and tech fingerprints into one HTML zip. Composition sink for ASM and vuln pipelines, not a scanner.
Aug 13, 2026
Replay a Chrome DevTools Recorder login, capture cookies, and write a Cookie header file for downstream Library nodes. Utility, not a scanner.
Aug 13, 2026
Pull rows from a Solution dataset into a file for downstream Library nodes. Required: solution and dataset. Query, columns, order-by, and workspace are optional.
Aug 13, 2026
Probe hostnames, IPs, or CIDR on common HTTP ports and keep the live web servers with title, redirect, status, server header, CDN, and TLS. The web-tail entry for recon pipelines.
Aug 13, 2026
Probe URL lists for admin panels across stacks, then try vendor default credentials on a subset. Headers and rate-limit included for fleet-scale runs.
Aug 13, 2026
Hunt hostname-named backup files like .bak, .sql, zip, and tarball dumps on a URL list. Heuristics cut false positives so hits are real archives.
Aug 13, 2026
Pattern-match live HTTP responses for exposed secrets like API tokens and credentials. Reuses responses across searches to scan a URL fleet at once.
Aug 13, 2026
Scan URLs for web misconfigurations: exposed APIs, debug surfaces, default-state takeover. Response-validated. Not CVE matching, not config files.
Aug 13, 2026
Scan hostnames, IPs, and ranges for the top 1000 TCP ports. Set include and exclude ports and a per-host open-port threshold. Output feeds network service fingerprinting.
Aug 13, 2026
CVE scanning for known CVE and CNVD issues on a URL list. Matcher-based checks flag outdated software with published IDs. Not a live feed, not SCA.
Aug 13, 2026
Probe known paths for .env, .git/config, logs, and dev artifacts, and validate the body looks like a real file. Cuts soft-404s across a URL fleet.
Aug 13, 2026
Tailored CVE scanning for ten web stacks post-fingerprint. WordPress, IIS, Ivanti, Joomla, GitLab, Jenkins, Spring Boot, Jira, Splunk, WebLogic.
Aug 13, 2026
Probe listening services from open-port records for information disclosure, exposed functionality, and takeover. Runs on port-details, rate-limited.
Aug 13, 2026
Test weak credentials on SSH, FTP, MySQL, PostgreSQL, and Microsoft SQL Server with per-protocol wordlists. Lockout-aware rate-limit keeps runs safe.
Aug 13, 2026
Get a personalized demo
A 30-minute walkthrough. We map the platform to your stack and answer pricing and deployment questions for your environment.