SurfaceScan
activeWeb attack-surface mapper. Subdomain discovery, tech fingerprinting, endpoint discovery.
- Passive-first discovery via crt.sh and SecurityTrails before any active probing
- SSRF guard rejects private, loopback and cloud-metadata addresses before requests go out
- Headless browser via Playwright for JavaScript-rendered surfaces, depth- and page-capped
TypeScript · Node.js 18+ · Python · Docker · PostgreSQL · Redis
Details