πŸ¦… ReconHawk β€” Attack Surface & Subdomain Takeover Scanner avatar

πŸ¦… ReconHawk β€” Attack Surface & Subdomain Takeover Scanner

Pricing

from $12.00 / 1,000 domain scans

Go to Apify Store
πŸ¦… ReconHawk β€” Attack Surface & Subdomain Takeover Scanner

πŸ¦… ReconHawk β€” Attack Surface & Subdomain Takeover Scanner

Read-only attack-surface recon for domains you own or are authorized to test: subdomain discovery, WAF/CDN fingerprint, subdomain-takeover risk (36-service reference DB), exposed S3 buckets, and leaked AWS keys in JS. For bug bounty hunters, pentesters & security teams.

Pricing

from $12.00 / 1,000 domain scans

Rating

0.0

(0)

Developer

Hitman studio

Hitman studio

Maintained by Community

Actor stats

0

Bookmarked

2

Total users

1

Monthly active users

4 days ago

Last modified

Categories

Share

Read-only external attack-surface recon (EASM). Subdomain discovery, WAF/CDN fingerprinting, subdomain-takeover risk, exposed cloud storage buckets, and leaked AWS keys β€” for domains you own or are explicitly authorized to test.

Use only on your own infrastructure, or in-scope assets under a bug bounty / pentest engagement. Every check is a read-only GET against a public API or the target's own HTTP server β€” no exploitation, no login bypass, no data exfiltration.


πŸ‘₯ Who needs this

You are a…You get…
🎯 Bug bounty hunterFast recon across every in-scope domain: subdomains, CDN, takeover candidates
πŸ›‘οΈ PentesterA structured attack-surface map before manual testing starts
🏒 Security / AppSec teamContinuous shadow-IT & external attack-surface monitoring for your own domains
πŸš€ Startup / indie devA free sanity check for exposed buckets and leaked keys before launch

✨ What it checks, per domain

  • 🌐 Subdomain discovery β€” certificate-transparency logs, passive DNS archives (Wayback, AnubisDB, ThreatMiner, RapidDNS), plus a common-name wordlist
  • πŸ›‘οΈ WAF/CDN fingerprint β€” Cloudflare, AWS CloudFront/WAF, Akamai, Fastly, Google Cloud, and more
  • 🚨 Subdomain-takeover risk β€” every discovered CNAME checked against the real, community-maintained 36-service "Can I take over XYZ?" reference database (AWS S3/Elastic Beanstalk, GitHub Pages, Heroku, Shopify, Ghost, Bitbucket, Azure's many managed-service CNAME suffixes, help-desk platforms, and more) β€” the same reference Subjack/tko-subs/Nuclei's takeover templates draw from
  • ☁️ Exposed cloud storage β€” anonymous check for publicly-listable S3 buckets, clearly labeled by confidence: CNAME-confirmed (this domain's own subdomain points at it) vs. guessed-name (a common naming guess β€” always verify ownership before reporting, since S3 bucket names are globally unique and a guess can hit an unrelated party's bucket)
  • πŸ”‘ Leaked AWS keys β€” scans the homepage + its own JS bundles for accidentally-hardcoded AKIA…/ASIA… access keys
  • πŸ“Š 0-100 risk score + plain-English summary per domain

πŸš€ How to use

  1. Add one or more domains you own or are authorized to test.
  2. Press Start.
  3. Get one structured result per domain β€” subdomains, takeover risks, exposed buckets, leaked keys, and an overall risk score.

Example 1 β€” quick single-domain check

{
"domains": ["example.com"],
"maxSubdomains": 150,
"checkTakeoverRisk": true,
"checkCloudExposure": true,
"checkWafCdn": true
}

Example 2 β€” bug bounty scope, multiple domains, deep sweep

{
"domains": ["target1.com", "target2.com", "sub.target3.com"],
"maxSubdomains": 1000,
"checkTakeoverRisk": true,
"checkCloudExposure": true,
"checkWafCdn": true,
"maxJsFiles": 30
}

πŸ“¦ Output (per domain)

domain, scanned_at, waf_cdn_vendors[], subdomains_checked, subdomains_found, subdomains[] (hostname, ips, classification, cname_chain), takeover_risks[] (service, hostname, evidence, reference), exposed_buckets[] (bucket, public_list, match_type, keys), leaked_aws_keys[] (access_key, source_url, context), risk_score, summary.


πŸ”Ž Keywords

subdomain takeover scanner, subdomain takeover checker, subdomain takeover vulnerability scanner, attack surface management tool, EASM tool, external attack surface management, attack surface discovery, bug bounty recon tool, bug bounty automation, pentest recon tool, penetration testing recon, CNAME takeover checker, dangling CNAME scanner, dangling DNS record finder, S3 bucket exposure scanner, exposed S3 bucket finder, public cloud storage scanner, open bucket finder, leaked AWS keys scanner, leaked API key finder, exposed AWS credentials scanner, WAF detection tool, CDN detection tool, Cloudflare detector, Akamai detector, Fastly detector, CloudFront detector, subdomain enumeration tool, subdomain finder, certificate transparency scanner, CT log subdomain finder, shadow IT discovery tool, attack surface mapping, external recon automation, security scanner for Apify, Apify security actor, Apify pentest actor, cyber security recon tool, offensive security tool, red team recon tool, HackerOne recon automation, Bugcrowd recon automation, "can I take over xyz" scanner, Subjack alternative, tko-subs alternative, how to find subdomain takeover vulnerabilities, how to check if a subdomain is vulnerable to takeover, how to find exposed S3 buckets, how to scan a domain for leaked AWS keys, free attack surface scan.


βš–οΈ Responsible use

This actor performs read-only reconnaissance only. It does not attempt to exploit any finding (e.g. it never actually claims a dangling bucket/CNAME). Use it only against domains you own, or assets explicitly in-scope under a bug bounty program or a signed pentest engagement. You are responsible for having authorization before scanning any domain.