π¦ ReconHawk β Attack Surface & Subdomain Takeover Scanner
Pricing
from $12.00 / 1,000 domain scans
π¦ ReconHawk β Attack Surface & Subdomain Takeover Scanner
Read-only attack-surface recon for domains you own or are authorized to test: subdomain discovery, WAF/CDN fingerprint, subdomain-takeover risk (36-service reference DB), exposed S3 buckets, and leaked AWS keys in JS. For bug bounty hunters, pentesters & security teams.
Pricing
from $12.00 / 1,000 domain scans
Rating
0.0
(0)
Developer
Hitman studio
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
4 days ago
Last modified
Categories
Share
Read-only external attack-surface recon (EASM). Subdomain discovery, WAF/CDN fingerprinting, subdomain-takeover risk, exposed cloud storage buckets, and leaked AWS keys β for domains you own or are explicitly authorized to test.
Use only on your own infrastructure, or in-scope assets under a bug bounty / pentest engagement. Every check is a read-only GET against a public API or the target's own HTTP server β no exploitation, no login bypass, no data exfiltration.
π₯ Who needs this
| You are a⦠| You get⦠|
|---|---|
| π― Bug bounty hunter | Fast recon across every in-scope domain: subdomains, CDN, takeover candidates |
| π‘οΈ Pentester | A structured attack-surface map before manual testing starts |
| π’ Security / AppSec team | Continuous shadow-IT & external attack-surface monitoring for your own domains |
| π Startup / indie dev | A free sanity check for exposed buckets and leaked keys before launch |
β¨ What it checks, per domain
- π Subdomain discovery β certificate-transparency logs, passive DNS archives (Wayback, AnubisDB, ThreatMiner, RapidDNS), plus a common-name wordlist
- π‘οΈ WAF/CDN fingerprint β Cloudflare, AWS CloudFront/WAF, Akamai, Fastly, Google Cloud, and more
- π¨ Subdomain-takeover risk β every discovered CNAME checked against the real, community-maintained 36-service "Can I take over XYZ?" reference database (AWS S3/Elastic Beanstalk, GitHub Pages, Heroku, Shopify, Ghost, Bitbucket, Azure's many managed-service CNAME suffixes, help-desk platforms, and more) β the same reference Subjack/tko-subs/Nuclei's takeover templates draw from
- βοΈ Exposed cloud storage β anonymous check for publicly-listable S3 buckets, clearly labeled by confidence: CNAME-confirmed (this domain's own subdomain points at it) vs. guessed-name (a common naming guess β always verify ownership before reporting, since S3 bucket names are globally unique and a guess can hit an unrelated party's bucket)
- π Leaked AWS keys β scans the homepage + its own JS bundles for accidentally-hardcoded
AKIAβ¦/ASIAβ¦access keys - π 0-100 risk score + plain-English summary per domain
π How to use
- Add one or more domains you own or are authorized to test.
- Press Start.
- Get one structured result per domain β subdomains, takeover risks, exposed buckets, leaked keys, and an overall risk score.
Example 1 β quick single-domain check
{"domains": ["example.com"],"maxSubdomains": 150,"checkTakeoverRisk": true,"checkCloudExposure": true,"checkWafCdn": true}
Example 2 β bug bounty scope, multiple domains, deep sweep
{"domains": ["target1.com", "target2.com", "sub.target3.com"],"maxSubdomains": 1000,"checkTakeoverRisk": true,"checkCloudExposure": true,"checkWafCdn": true,"maxJsFiles": 30}
π¦ Output (per domain)
domain, scanned_at, waf_cdn_vendors[], subdomains_checked, subdomains_found,
subdomains[] (hostname, ips, classification, cname_chain), takeover_risks[]
(service, hostname, evidence, reference), exposed_buckets[] (bucket,
public_list, match_type, keys), leaked_aws_keys[] (access_key, source_url,
context), risk_score, summary.
π Keywords
subdomain takeover scanner, subdomain takeover checker, subdomain takeover vulnerability scanner, attack surface management tool, EASM tool, external attack surface management, attack surface discovery, bug bounty recon tool, bug bounty automation, pentest recon tool, penetration testing recon, CNAME takeover checker, dangling CNAME scanner, dangling DNS record finder, S3 bucket exposure scanner, exposed S3 bucket finder, public cloud storage scanner, open bucket finder, leaked AWS keys scanner, leaked API key finder, exposed AWS credentials scanner, WAF detection tool, CDN detection tool, Cloudflare detector, Akamai detector, Fastly detector, CloudFront detector, subdomain enumeration tool, subdomain finder, certificate transparency scanner, CT log subdomain finder, shadow IT discovery tool, attack surface mapping, external recon automation, security scanner for Apify, Apify security actor, Apify pentest actor, cyber security recon tool, offensive security tool, red team recon tool, HackerOne recon automation, Bugcrowd recon automation, "can I take over xyz" scanner, Subjack alternative, tko-subs alternative, how to find subdomain takeover vulnerabilities, how to check if a subdomain is vulnerable to takeover, how to find exposed S3 buckets, how to scan a domain for leaked AWS keys, free attack surface scan.
βοΈ Responsible use
This actor performs read-only reconnaissance only. It does not attempt to exploit any finding (e.g. it never actually claims a dangling bucket/CNAME). Use it only against domains you own, or assets explicitly in-scope under a bug bounty program or a signed pentest engagement. You are responsible for having authorization before scanning any domain.