Enumerate Hostnames via Root Domain DNS Brute Force
Wordlist DNS brute force against root domains. Finds first-level names OSINT missed. Input is domains plus an optional custom wordlist, not known hostnames.
A module is a nestable subgraph with a typed face: a process you drop into a workflow. 28 public modules, grouped the way Hive groups them.
A tool is one binary and its flags. A workflow is a graph you run as a product. Start from a module when you already have a parent graph and need this process in it.
Wordlist DNS brute force against root domains. Finds first-level names OSINT missed. Input is domains plus an optional custom wordlist, not known hostnames.
Scan URLs for web misconfigurations: exposed APIs, debug surfaces, default-state takeover. Response-validated. Not CVE matching, not config files.
Probe listening services from open-port records for information disclosure, exposed functionality, and takeover. Runs on port-details, rate-limited.
Pattern-match live HTTP responses for exposed secrets like API tokens and credentials. Reuses responses across searches to scan a URL fleet at once.
Web app fuzzing with active DAST. Crawl each app, inject payloads into discovered inputs, report insecure behaviors, and recrawl for stored issues.
Retrieve JavaScript from a URL list, unpack it, and mine endpoints, wordlists, CVEs, secrets, and insecure client-side patterns in one nestable pass.
Probe hostnames, IPs, or CIDR on common HTTP ports and keep the live web servers with title, redirect, status, server header, CDN, and TLS. The web-tail entry for recon pipelines.
Hunt hostname-named backup files like .bak, .sql, zip, and tarball dumps on a URL list. Heuristics cut false positives so hits are real archives.
Tailored CVE scanning for ten web stacks post-fingerprint. WordPress, IIS, Ivanti, Joomla, GitLab, Jenkins, Spring Boot, Jira, Splunk, WebLogic.
Wire findings, ports, DNS, WHOIS, screenshots, and tech fingerprints into one HTML zip. Composition sink for ASM and vuln pipelines, not a scanner.
Crawl live web servers and pull hostnames from links, script, and headers. Input is URLs, not root domains. Last in the hostname enum family; nest after probe.
Replay a Chrome DevTools Recorder login, capture cookies, and write a Cookie header file for downstream Library nodes. Utility, not a scanner.
Pull rows from a Solution dataset into a file for downstream Library nodes. Required: solution and dataset. Query, columns, order-by, and workspace are optional.
Query A, AAAA, CNAME, MX, NS, TXT, CAA, and PTR for a host, IP, or CIDR list. Keep resolving names, addresses, and associated hostnames as line lists.
Enumerate hostnames from passive OSINT sources. No API keys required; optional keys expand sources. Finds related roots, not only subdomains of the target.
Search OSINT sources for a host list to find hidden paths. Historical and recent URLs, normalized. Thousands of hosts. No traffic to the target.
Scan hostnames, IPs, and ranges for the top 1000 TCP ports. Set include and exclude ports and a per-host open-port threshold. Output feeds network service fingerprinting.
Brute-force web server URLs to find hidden paths. Heuristics drop masked 404s. Built-in or custom wordlist. Thousands of servers in parallel.
Generate DNS permutations from hostnames you have. Alter labels for staging, regions, and related software, then resolve. Built-in wordlist or org naming.
Derive DNS brute-force wordlists from known hostnames. Root-class and recursive level lists for the hostname enum modules. Does not resolve names.
CVE scanning for known CVE and CNVD issues on a URL list. Matcher-based checks flag outdated software with published IDs. Not a live feed, not SCA.
Identify the service on each open port. Service fingerprinting returns protocol, banner, product, and version for misconfig and credential tests.
Probe known paths for .env, .git/config, logs, and dev artifacts, and validate the body looks like a real file. Cuts soft-404s across a URL fleet.
Probe URL lists for admin panels across stacks, then try vendor default credentials on a subset. Headers and rate-limit included for fleet-scale runs.
Test weak credentials on SSH, FTP, MySQL, PostgreSQL, and Microsoft SQL Server with per-protocol wordlists. Lockout-aware rate-limit keeps runs safe.
Identify CMS, CDN, and WAF on live web servers. Technology detection names server software, runtimes, and frameworks with version status.
Brute-force sub-subdomains of known hostnames. Rank likely prefixes, generate FUZZ at each DNS level, and resolve. Built-in or custom level wordlists. Caps per level.
Crawl live web server URLs, follow links and parse JavaScript, and emit a path map per asset. Nest when the surface is linked, not guessed or archived.
Get a personalized demo
A 30-minute walkthrough. We map the platform to your stack and answer pricing and deployment questions for your environment.