See Through The Surface
# WHOIS / subdomains / SSL / tech detect / CVE search
# real-time streaming • no database • no signup
// try: google.com • github.com • cloudflare.com
// modules
[ 20+ reconnaissance & vulnerability detection modules ]
WHOIS Lookup
Domain registration details — registrar, creation/expiration dates, name servers, organization info, and DNSSEC status.
Subdomain Enumeration
Passive enumeration via Certificate Transparency logs (crt.sh), AlienVault OTX, URLScan, AnubisDB, DNSDumpster, RapidDNS + DNS brute force with 120+ common subdomains.
SSL Certificate
Full certificate inspection — issuer, validity, cipher suites, SANs, key size, signature algorithm, and expiry status.
Tech & WAF Detection
Identifies 55+ technologies — web servers, frameworks, CMS, CDNs, analytics + WAF detection (Cloudflare, AWS WAF, Cloudfront, ModSecurity, Akamai).
CVE Search
Correlates detected technologies against known vulnerabilities with CVSS scores, severity ratings, and NVD references.
URL & Endpoint Finder
Aggregates URLs from Wayback Machine, AlienVault OTX, URLScan + path scanning + comment crawling. Extracts parameters for fuzzing.
SQL Injection Detection
Tests 35+ error-based payloads on discovered parameters. Detects DBMS (MySQL, PostgreSQL, MSSQL, Oracle, SQLite). False positive filtering applied.
SSRF Detection
Tests parameters with cloud metadata endpoints (169.254.169.254), internal IPs, file://, gopher://, dict://. Detects error patterns and blind SSRF via timeouts.
DNS Security Checks
SPF, DKIM, DMARC record analysis, zone transfer testing, DNSSEC status, NS/MX enumeration. Flags email spoofing risks and DNS misconfigurations.
Cookie Security
Audits all cookies for missing Secure/HttpOnly/SameSite flags. Detects sensitive cookies without encryption (session, token, jwt, auth).
JS Analysis & Secrets
Fetches JS files from discovered URLs, extracts endpoints, detects 70+ secret patterns (AWS, GCP, Azure, GitHub, Slack, Stripe, JWT, Firebase, cloud service credentials). Framework detection + vulnerable version warnings.
Cloud Bucket Enumeration
Enumerates AWS S3, Azure Blob, and GCP storage buckets. Checks for public access, directory listing, and file exposure. Integrates with subdomain enumeration.
Subdomain Takeover
Multi-source takeover detection (subjack, nuclei, CNAME analysis). Checks for dangling DNS records pointing to AWS, GitHub, Heroku, Azure, and other cloud services.
Content Discovery
Brute-forces 130+ common paths (admin, api, backup, config, .git, .env, actuator, swagger, graphql). Flags interesting findings like exposed files and admin panels.
API & GraphQL Discovery
Discovers REST API endpoints, OpenAPI/Swagger docs, tries GraphQL introspection, detects OAuth/OIDC configurations. Tests API authentication requirements.
Port Scanning
Full port scan using naabu/nmap integration. Service version detection, banner grabbing. Identifies open ports with service names and fingerprints.
Directory Traversal
Tests 25+ path traversal vectors including encoded/decoded variants. Checks for /etc/passwd, boot.ini, and Windows system files. False positive detection via content analysis.
Exposed Files & Leaks
Scans for exposed .env files, .git repositories, API keys, tokens, passwords, and credentials in common paths. Checks 60+ leak patterns with false positive filtering.
GitHub Dork & Breach Check
Searches GitHub for exposed credentials, configs, and secrets related to the target domain. Checks domain emails against known breach databases.
AI Analysis & BB Report
Groq AI (Mixtral 8x7B) analyzes all per-module results, provides security insights, prioritizes vulnerabilities. Generates professional bug bounty reports formatted for HackerOne and Bugcrowd.
// standalone tools
[ paste & analyze — no scan needed ]
JavaScript Secret Scanner
Paste JavaScript code to find hardcoded API keys, tokens, passwords, and secrets.
Dependency Checker
Paste package-lock.json content to find known vulnerabilities in dependencies.
GitHub Dork Scanner
Search GitHub for exposed credentials, configs, and secrets related to a domain.
Exposed .env Finder
Check common paths for exposed .env files and leaked credentials.
Directory Traversal Checker
Test for path traversal vulnerabilities using common vectors.
Reverse IP Lookup
Find other domains hosted on the same IP address.
Leaked API Keys Finder
Scan common paths and files for leaked API keys, tokens, and credentials.
Breach Data Checker
Check domain emails against known breach databases.
Live Host Probe
httpx-style probing: status, title, server, response time, content-length.
Content Discovery
Directory/file brute force with 130+ common paths. Flags interesting findings.
SSRF Detection
Test parameters for Server-Side Request Forgery using internal IPs and cloud metadata endpoints.
DNS Security Check
SPF/DKIM/DMARC records, zone transfer test, DNSSEC status, NS/MX enumeration.
Cookie Security
Check cookies for missing Secure, HttpOnly flags and sensitive cookie exposure.
// bug bounty workflow
[ full methodology — recon to disclosure ]
Reconnaissance
Gather everything — WHOIS, subdomains, tech stack, SSL, certificates, reverse DNS, breach data. whois · subdomain · reverse_ip · breach · dorks
Attack Surface Mapping
Find live hosts, open ports, web technologies, WAF, CMS, redirects. Probe every endpoint. livehost · port_scan · tech · waf · cms · wp
Content & API Discovery
Brute-force directories, find API endpoints, JS analysis, URL sources (wayback/otx), graphQL introspection, .env exposure. content_disc · urlfinder · api · graphql · js_analysis · envfinder
Vulnerability Detection
SQL injection, directory traversal, SSRF, CORS misconfigs, OAuth bypass, leaked keys, open redirect, CVE correlation. sqli · ssrf · traversal · cors · leakfinder · oauth · redirect · cve
Cloud & Infrastructure
Subdomain takeover, cloud bucket enumeration (AWS/Azure/GCP), git exposure, DNS security checks, cookie analysis, WAF bypass. takeover · cloud_enum · git_exposure · dns_security · cookie · bypass
JS Deep Analysis & Secrets
Framework detection, vulnerable library versioning, hardcoded API keys/tokens, cloud service credentials, S3/Blob/GCP URLs in JS, webhook leaks. js_analysis · framework_detect · vuln_versions · 70+ secret patterns
AI Analysis & Report
Groq AI analyzes all results, prioritizes findings, generates bug bounty report (HackerOne/Bugcrowd format), and AI assistant answers questions about findings. groq · per-module AI insights · ai assistant
// privacy
[root@reconlens]$ No databases. No signups. No tracking.
All scans use public APIs and passive techniques.
Results live in your browser session — gone when you close the tab.
Open source. Audit-ready. Privacy-first.