passive reconnaissance system

See Through The Surface

# WHOIS / subdomains / SSL / tech detect / CVE search
# real-time streaming • no database • no signup

// try: google.com • github.com • cloudflare.com

// modules

[ 20+ reconnaissance & vulnerability detection modules ]

01

WHOIS Lookup

Domain registration details — registrar, creation/expiration dates, name servers, organization info, and DNSSEC status.

02

Subdomain Enumeration

Passive enumeration via Certificate Transparency logs (crt.sh), AlienVault OTX, URLScan, AnubisDB, DNSDumpster, RapidDNS + DNS brute force with 120+ common subdomains.

03

SSL Certificate

Full certificate inspection — issuer, validity, cipher suites, SANs, key size, signature algorithm, and expiry status.

04

Tech & WAF Detection

Identifies 55+ technologies — web servers, frameworks, CMS, CDNs, analytics + WAF detection (Cloudflare, AWS WAF, Cloudfront, ModSecurity, Akamai).

05

CVE Search

Correlates detected technologies against known vulnerabilities with CVSS scores, severity ratings, and NVD references.

06

URL & Endpoint Finder

Aggregates URLs from Wayback Machine, AlienVault OTX, URLScan + path scanning + comment crawling. Extracts parameters for fuzzing.

07

SQL Injection Detection

Tests 35+ error-based payloads on discovered parameters. Detects DBMS (MySQL, PostgreSQL, MSSQL, Oracle, SQLite). False positive filtering applied.

08

SSRF Detection

Tests parameters with cloud metadata endpoints (169.254.169.254), internal IPs, file://, gopher://, dict://. Detects error patterns and blind SSRF via timeouts.

09

DNS Security Checks

SPF, DKIM, DMARC record analysis, zone transfer testing, DNSSEC status, NS/MX enumeration. Flags email spoofing risks and DNS misconfigurations.

10

Cookie Security

Audits all cookies for missing Secure/HttpOnly/SameSite flags. Detects sensitive cookies without encryption (session, token, jwt, auth).

11

JS Analysis & Secrets

Fetches JS files from discovered URLs, extracts endpoints, detects 70+ secret patterns (AWS, GCP, Azure, GitHub, Slack, Stripe, JWT, Firebase, cloud service credentials). Framework detection + vulnerable version warnings.

12

Cloud Bucket Enumeration

Enumerates AWS S3, Azure Blob, and GCP storage buckets. Checks for public access, directory listing, and file exposure. Integrates with subdomain enumeration.

13

Subdomain Takeover

Multi-source takeover detection (subjack, nuclei, CNAME analysis). Checks for dangling DNS records pointing to AWS, GitHub, Heroku, Azure, and other cloud services.

14

Content Discovery

Brute-forces 130+ common paths (admin, api, backup, config, .git, .env, actuator, swagger, graphql). Flags interesting findings like exposed files and admin panels.

15

API & GraphQL Discovery

Discovers REST API endpoints, OpenAPI/Swagger docs, tries GraphQL introspection, detects OAuth/OIDC configurations. Tests API authentication requirements.

16

Port Scanning

Full port scan using naabu/nmap integration. Service version detection, banner grabbing. Identifies open ports with service names and fingerprints.

17

Directory Traversal

Tests 25+ path traversal vectors including encoded/decoded variants. Checks for /etc/passwd, boot.ini, and Windows system files. False positive detection via content analysis.

18

Exposed Files & Leaks

Scans for exposed .env files, .git repositories, API keys, tokens, passwords, and credentials in common paths. Checks 60+ leak patterns with false positive filtering.

19

GitHub Dork & Breach Check

Searches GitHub for exposed credentials, configs, and secrets related to the target domain. Checks domain emails against known breach databases.

20

AI Analysis & BB Report

Groq AI (Mixtral 8x7B) analyzes all per-module results, provides security insights, prioritizes vulnerabilities. Generates professional bug bounty reports formatted for HackerOne and Bugcrowd.

// standalone tools

[ paste & analyze — no scan needed ]

JS

JavaScript Secret Scanner

Paste JavaScript code to find hardcoded API keys, tokens, passwords, and secrets.

DEP

Dependency Checker

Paste package-lock.json content to find known vulnerabilities in dependencies.

GH

GitHub Dork Scanner

Search GitHub for exposed credentials, configs, and secrets related to a domain.

ENV

Exposed .env Finder

Check common paths for exposed .env files and leaked credentials.

DIR

Directory Traversal Checker

Test for path traversal vulnerabilities using common vectors.

RIP

Reverse IP Lookup

Find other domains hosted on the same IP address.

LK

Leaked API Keys Finder

Scan common paths and files for leaked API keys, tokens, and credentials.

BR

Breach Data Checker

Check domain emails against known breach databases.

LH

Live Host Probe

httpx-style probing: status, title, server, response time, content-length.

CD

Content Discovery

Directory/file brute force with 130+ common paths. Flags interesting findings.

SS

SSRF Detection

Test parameters for Server-Side Request Forgery using internal IPs and cloud metadata endpoints.

DNS

DNS Security Check

SPF/DKIM/DMARC records, zone transfer test, DNSSEC status, NS/MX enumeration.

CK

Cookie Security

Check cookies for missing Secure, HttpOnly flags and sensitive cookie exposure.

// bug bounty workflow

[ full methodology — recon to disclosure ]

01

Reconnaissance

Gather everything — WHOIS, subdomains, tech stack, SSL, certificates, reverse DNS, breach data. whois · subdomain · reverse_ip · breach · dorks

02

Attack Surface Mapping

Find live hosts, open ports, web technologies, WAF, CMS, redirects. Probe every endpoint. livehost · port_scan · tech · waf · cms · wp

03

Content & API Discovery

Brute-force directories, find API endpoints, JS analysis, URL sources (wayback/otx), graphQL introspection, .env exposure. content_disc · urlfinder · api · graphql · js_analysis · envfinder

04

Vulnerability Detection

SQL injection, directory traversal, SSRF, CORS misconfigs, OAuth bypass, leaked keys, open redirect, CVE correlation. sqli · ssrf · traversal · cors · leakfinder · oauth · redirect · cve

05

Cloud & Infrastructure

Subdomain takeover, cloud bucket enumeration (AWS/Azure/GCP), git exposure, DNS security checks, cookie analysis, WAF bypass. takeover · cloud_enum · git_exposure · dns_security · cookie · bypass

06

JS Deep Analysis & Secrets

Framework detection, vulnerable library versioning, hardcoded API keys/tokens, cloud service credentials, S3/Blob/GCP URLs in JS, webhook leaks. js_analysis · framework_detect · vuln_versions · 70+ secret patterns

07

AI Analysis & Report

Groq AI analyzes all results, prioritizes findings, generates bug bounty report (HackerOne/Bugcrowd format), and AI assistant answers questions about findings. groq · per-module AI insights · ai assistant

→ PRO TIP: Each result card now has per-module AI insights to help you understand what matters. Check the AI Bug Bounty Roadmap card for the full prioritized attack plan.

// privacy

[root@reconlens]$ No databases. No signups. No tracking.
All scans use public APIs and passive techniques.
Results live in your browser session — gone when you close the tab.

Open source. Audit-ready. Privacy-first.