# Monitor a domain's public attack surface

**Use case:** 

The subdomain someone spun up for a demo two years ago is still live, still unpatched, and it's the first thing an attacker checks. This example runs 20 passive, legal checks on any domain - CVEs with a public exploit, exposed files and buckets, forgotten subdomains, weak SSL - reporting only what's newly exposed. Swap in your own domains.

## Input

```json
{
  "domains": [
    "example.com"
  ],
  "checks": [
    "headers",
    "tls",
    "exposed_files",
    "cms",
    "dns_spoofing",
    "subdomains",
    "exposed_buckets",
    "exposed_ports",
    "breach_history",
    "cookies",
    "cors",
    "http_downgrade",
    "robots_disclosure",
    "js_libraries",
    "subdomain_takeover",
    "dns_hygiene",
    "server_software",
    "source_maps",
    "wp_plugins",
    "db_admin_panels"
  ],
  "request_timeout_secs": 15,
  "max_results": 25
}
```

## Output

```json
{
  "domain": {
    "label": "Domain"
  },
  "category": {
    "label": "Category"
  },
  "severity": {
    "label": "Severity"
  },
  "finding": {
    "label": "Finding"
  },
  "detail": {
    "label": "Detail"
  },
  "checked_at": {
    "label": "Checked at"
  }
}
```

## About this Actor

This example demonstrates how to use [Exploit Radar — Website Attack Surface Monitor](https://apify.com/0xgollum/exploit-radar.md) with a specific input configuration. Visit the [Actor detail page](https://apify.com/0xgollum/exploit-radar.md) to learn more, explore other use cases, and run it yourself.


## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.
This Task's input is already configured above — use it as-is rather than inventing a new one.

- **AI agents and MCP clients** — the [Apify MCP server](https://docs.apify.com/integrations/mcp.md) at `https://mcp.apify.com` (remote, streamable HTTP, OAuth on first use).
- **Agentic workflows and local Actor development** — [Agent Skills](https://apify.com/.well-known/agent-skills/index.json) with the [Apify CLI](https://docs.apify.com/cli/docs.md): `npm install -g apify-cli`, then `apify login`.
- **JavaScript/TypeScript projects** — the official [JS/TS client](https://docs.apify.com/api/client/js/docs.md): `npm install apify-client`.
- **Python projects** — the official [Python client](https://docs.apify.com/api/client/python/docs.md): `pip install apify-client`.
- **Any other language** — the [REST API](https://docs.apify.com/api/v2.md).

For full API examples (JavaScript, Python, CLI, MCP, OpenAPI), see this Task's Actor page: https://apify.com/0xgollum/exploit-radar.md

For more details, see Apify documentation as [Markdown index](https://docs.apify.com/llms.txt) and [Markdown full-text](https://docs.apify.com/llms-full.txt).
