Domain Monitor
Live
Online

Domain Monitor

Attack Surface Discovery
Try:
Typosquat Detection
Brand Abuse Detection
Comprehensive Domain Audit
Scanned Domains Portfolio
MSSP view — every domain you've scanned, sorted by risk. Local to this browser.
0 domains
Side-by-Side Domain Comparison
Benchmark two domains' attack surface head-to-head — posture score, findings, TLS/headers grades, and exposure counts.
🕵 External Attack Surface Management
Continuous discovery + diff + close. We run our own Shodan/Censys/Amass/CT pipeline on our own brand, weekly, and shrink what the adversary will find.
Subdomains tracked
across 6 scanners
Net-new (7d)
triage queue
Takeover candidates
dangling CNAMEs
CT-lookalike certs
filed for takedown
Fix / close SLA
mean time
Surface trend
↓ 11%
vs prior 30d
📡 Subdomain Enumeration Pipeline (T001)
Daily run · amass + subfinder + crt.sh + merklemap + brute. Diff vs prior day. Net-new auto-opens a ticket with owner.
SourceSubdomains foundNew 7dLast runHealth
amass (active+passive)347+804:12 todayOK
subfinder312+604:14 todayOK
crt.sh (CT logs)289+11streamingLIVE
merklemap218+306:00 todayOK
puredns bruteforce94+202:00 todayOK
Shodan org-tag67+105:22 todayOK
Net-new this week:
  • staging-v2.[your-org].com · eng · opened CR-2240
  • invoice-portal-uat.[your-org].com · finance · opened CR-2241
  • old-wiki.[your-org].com · stale? no owner · auto-escalated
  • demo-q2.[your-org].com · sales-eng · opened CR-2242
📜 Certificate Transparency Monitor (T002)
We subscribe to the CT log stream. Alerts on any new cert for our name or brand-adjacent — catches shadow-IT SaaS signups and adversary lookalikes.
Certs monitored
2,184
active issuers
Own-brand (7d)
12
all reconciled
Lookalike-brand
4
filed for takedown
Expiring < 14d
3
auto-renew set
IssuedDomain / SANIssuerClassificationVerdict
2h agobilling.[your-org].comLet's Encryptown-brand · known SaaSallow
6h ago[your-brand]-billing.appLet's Encryptlookalike · registered 3h agotakedown filed
ydayshopify-[your-brand].comGoogle Trustlookalike · phishing patterntakedown + GSB
ydayhr.[your-org].comDigiCertown-brand · verifiedallow
2d agoacmɇ-login.io (punycode)Let's Encrypthomoglyphtakedown filed
3d agoapi.[your-org].comAWS ACMown · auto-renewalallow
🎯 Typosquat / Lookalike Detector (T003)
dnstwist + urlcrazy + CT feed. Score by Levenshtein × registrar-age × MX-presence. Auto-drafts the takedown request.
Variants monitored
4,218
permutations of brand
Registered (7d)
14
net-new
MX+web live
6
phishing-ready
Takedowns filed
5
this week
VariantAgeMXWebScoreAction
acmɇ.io (punycode)2d✓ login form94takedown + GSB
acme-io.com3d✓ login form88takedown
acrne.io (r n → m)1dparking74watch
acme.support12d✓ fake helpdesk91takedown filed
acnie.io8d32monitor
acme.ltd60dparking28monitor
🔭 Internet-Scanner Self-Scan (T004)
Shodan + Censys + ZoomEye + BinaryEdge org-tag pull. Diff week-over-week. Anything not on the approved edge-inventory escalates.
Indexed services
218
across 4 scanners
Approved edge
204
on inventory
Unknown exposed
14
triage now
High-risk ports
3
RDP · Mongo · Jenkins
ServiceIP / HostPortBannerFirst seenVerdict
RDPedge-old-01.[your-org].com3389Windows 20166d agoclose / move to IAP
MongoDB34.x.x.x27017no auth2d agoP0 · auth + bind localhost
Jenkinsci-old.[your-org].com8080Jenkins 2.31911d agodecommission
Elasticsearches-legacy.[your-org].com92007.10 · no auth4d agoxpack + IP-allow
HTTPSapi.[your-org].com443nginx / prodbaselineapproved
SSHjump.[your-org].com22OpenSSH 9 · keyauthbaselineapproved
☠ Subdomain Takeover Sweep (T005)
Nuclei takeover templates on every CNAME we own. Targets S3 / GitHub Pages / Heroku / Azure / Shopify / Fastly / custom domains where the underlying asset was removed.
CNAMEs tracked
412
in our zones
Dangling detected
3
P0 · claim now
Auto-claimed / DNS-removed
8
this quarter
Mean time-to-fix
46m
detection → closed
SubdomainPoints toVendorFingerprintAction
blog-old.[your-org].com→ acme.github.ioGitHub Pages"There isn't a GitHub Pages site here"CREATE REPO or REMOVE CNAME
try.[your-org].com→ acme-demo.s3.amazonaws.comAWS S3NoSuchBucketCREATE BUCKET or REMOVE
status.[your-org].com→ acme-old.statuspage.ioStatuspage404 + page-not-foundCLAIM ON STATUSPAGE
ship.[your-org].com→ acme-live.herokuapp.comHerokuactive · app existsOK
🗝 HIBP Breach-Credential Gate (T006)
Continuous h8mail / dehashed / HIBP cross-ref for all @[your-org].com addresses. Any hit forces session-kill + password/passkey reset in aegis ITDR.
Addresses monitored
4,218
all corp + contractor
Hits (30d)
12
all rotated
Plaintext-pw hits
3
priority 0
Reuse rate (sampled)
18%
target < 5%
WhenAddressSource breachData classesResponse
3h ago[user.name]@[your-org].comParkMobile 2021email + hashed pwreset pending · notified
ydayrohan.das@[your-org].comTwitter 2022email + phoneuser aware · rotate MFA
2d agocontractor-jr@3pa.ioDailyQuiz 2020email + PLAIN pwsession killed + force FIDO2
5d agoap@[your-org].comLinkedIn 2012 + Dropbox 2012email + multirotated
🐙 Public-Code Secret Dorking (T007)
gitleaks + trufflehog + grep.app searches for our org domain across GitHub / GitLab / gists / postbin — including forks and consented personal accounts.
Repos monitored
12,480
mentioning brand
Verified secrets (30d)
4
all rotated
False positives
86%
auto-filtered
Rotation SLA
3h 12m
leak → rotated
WhereKindPreviewFirst seenAction
github.com/ex-intern-42/dotfilesAWS Access KeyAKIA…XOYM8h agorotated + revoked
gist/anonymous/a2f…Datadog API keydd_xx…c32d agorotated
postbin.com/b/d19…Slack webhookhooks.slack.com/services/T…5d agowebhook deleted
github.com/acme-corp/demoJWT · test-enveyJh…14d agofalse-pos · test-signed
🪣 Public-Bucket Enumeration (T008)
s3scanner + cloud_enum permutations of brand across S3, GCS, Azure Blob. Any reachable bucket not explicitly tagged public:yes goes to the triage queue.
Permutations tried
8,142
brand + numbers
Reachable buckets
32
need review
With listing enabled
2
CLOSE TODAY
Confirmed public-intended
28
tagged + baselined
BucketProviderContentsListingVerdict
acme-devops-scratchAWS S3~41 files · logs, envsENABLEDBPA + remove public
acme-old-backupsAWS S3tarballs 2021-22ENABLEDmigrate + lock
acme-marketing-assetsAWS S3logos + videosdisabledintended · baselined
acme-prod-staticGCSCDN origindisabledintended
🕰 Wayback & Archive Mining (T009)
gau + waybackurls → extract API paths, keys, and JS bundles from archive snapshots. Rotate anything still live. Source-map any dead endpoint.
URLs harvested
4.2M
all-time snapshots
Live (still reachable)
312
old but alive
Exposed keys found
7
all rotated
Undocumented APIs
11
filed in devsec
KindExampleFindingAction
Old JS bundle/static/v1.4.2/app.min.jshardcoded Sentry DSN · still in trafficrotated
API path/api/v1/internal/debug?key=archived 2022; endpoint removedconfirmed removed
Admin UI/old-admin/login.phpreachable · PHP deprecateddecommission
Leaked API keySendGrid token in archived footer JSstill active 6 months agorotated + alerted
📧 Email Auth Posture — SPF · DKIM · DMARC · BIMI (T011)
DMARC at p=reject, DKIM 2048-bit, BIMI record published. Continuous monitor for drift or weakening. Inbound strict-alignment enforced on receive side.
DMARC policy
p=reject
at 100% · rua + ruf
DKIM strength
2048-bit
rotated 62d ago
BIMI published
✓ VMC
verified trademark
Aggregate reports (7d)
4,218
spoofing attempts
DomainSPFDKIMDMARCBIMIStatus
[your-org].com✓ hard-fail✓ 2048p=reject✓ VMCCOMPLIANT
mail.[your-org].com✓ hard-fail✓ 2048p=rejectCOMPLIANT
acme-events.com✓ soft-failp=nonePARKED · tighten
acme-careers.com✓ reject-alln/ap=rejectNULL-MX · no send
🛰 ASN / BGP Prefix Inventory (T013)
asnmap + ipinfo bulk. Reconcile every prefix claiming the brand vs CMDB. Flag any unknown ASN asserting ownership — classic BGP-hijack early signal.
ASNs we own
3
approved
Prefixes announced
18
all ROA-signed
Unknown brand-claims
2
in whois → investigating
RPKI invalid
0
target 0
ASN / prefixClaimSourceROAVerdict
AS64500 · 198.51.100.0/24[your-org]ARINapproved edge
AS64500 · 203.0.113.0/24[your-org]ARINapproved edge
AS64501 · 192.0.2.0/24[your-org] (old DC)ARINdecom Q3
AS64999 · whois matchUnrelated company LtdRIPEdifferent co · verify