Attack Surface

Attack surface management tools for discovering, monitoring, and reducing external attack vectors to minimize cybersecurity risks.

Explore 98 curated cybersecurity tools, with 14,802+ visitors searching for solutions

FEATURED

Proton Pass Logo

Password manager with end-to-end encryption and identity protection features

NordVPN Logo

VPN service providing encrypted internet connections and privacy protection

Mandos Fractional CISO Services Logo

Fractional CISO services for B2B companies to accelerate sales and compliance

Get Featured

Feature your product and reach thousands of professionals.

python-builtwith Logo

A Python API client for BuiltWith that enables programmatic access to website technology profiling and reconnaissance data.

0
2tearsinabucket Logo

A tool for enumerating and analyzing Amazon S3 buckets associated with specific targets to identify potential security misconfigurations.

0
HostileSubBruteforcer Logo

A tool for bruteforcing subdomains of a given domain

0
Secret Bridge Logo

Secret Bridge monitors GitHub repositories to detect and alert on leaked secrets and sensitive data exposure.

0
censys-subdomain-finder Logo

A tool for performing subdomain enumeration using Censys API

0
SubOver Logo

A powerful tool for finding and exploiting subdomain takeover vulnerabilities

0
Trufflehog-Chrome-Extension Logo

A Chrome browser extension that uses machine learning to detect and alert users about sensitive data exposure and potential data breaches across web environments.

0
autoSubTakeover Logo

A tool to identify potential subdomain takeovers by checking if a CNAME record resolves to the scope address.

0
CloudScraper Logo

CloudScraper is an enumeration tool that discovers cloud storage resources including S3 buckets, Azure blobs, and DigitalOcean Spaces across target environments.

0
TypeError/domained Logo

A multi-tool for subdomain enumeration

0
S3BucketList Logo

A Chrome extension that automatically detects and lists Amazon S3 buckets while browsing websites.

0
Knock Logo

A subdomain scan tool that helps you find subdomains of a given domain.

0
crawley Logo

A Go-based web crawler that supports multiple protocols and authentication methods for systematic web resource discovery and collection.

0
GitGot Logo

A tool for identifying sensitive secrets in public GitHub repositories

0
Findomain Logo

A domain reconnaissance tool that automates subdomain discovery, port scanning, and monitoring with support for multiple data sources and notification integrations.

0
cnames Logo

A tool for taking a list of resolved subdomains and outputting any corresponding CNAMES en masse.

0
csprecon Logo

A tool to discover new target domains using Content Security Policy

0
WayMore Logo

A tool that finds more information about a given URL or domain by querying multiple data sources.

0
Internet-Wide Misconfiguration Scanner Logo

Scan the internet for publicly exposed network components

0
ScanCannon Logo

A Python-based tool for external attack surface discovery and reconnaissance across large-scale networks, focusing on IP address and subdomain enumeration.

0
ONYPHE Logo

ONYPHE is a cyber defense search engine that discovers exposed assets and provides real-time monitoring to identify vulnerabilities and potential risks.

0
aws-inventory Logo

A Python script that inventories and lists main AWS account resources to provide visibility into cloud infrastructure components that may impact billing or security.

0
Censys Logo

A search engine for the Internet of Things (IoT) that provides real-time information about connected devices.

0