# 🦅 ReconHawk — Attack Surface & Subdomain Takeover Scanner (`inexhaustible_glass/reconhawk`) Actor

Read-only attack-surface recon for domains you own or are authorized to test: subdomain discovery, WAF/CDN fingerprint, subdomain-takeover risk (36-service reference DB), exposed S3 buckets, and leaked AWS keys in JS. For bug bounty hunters, pentesters & security teams.

- **URL**: https://apify.com/inexhaustible\_glass/reconhawk.md
- **Developed by:** [Hitman studio](https://apify.com/inexhaustible_glass) (community)
- **Stats:** 2 total users, 1 monthly users, 100.0% runs succeeded, 0 bookmarks
- **User rating**: No ratings yet

## Pricing

from $12.00 / 1,000 domain scans

This Actor is paid per event. You are not charged for the Apify platform usage, but only a fixed price for specific events.

Learn more: https://docs.apify.com/actors/running/actors-in-store.md#pay-per-event

## What's an Apify Actor?

An Actor is a serverless cloud program that runs on the Apify platform. It has two run modes.
In Batch mode, an Actor accepts a well-defined JSON input, performs an action which can take anything from a few seconds to a few hours,
and optionally produces a well-defined JSON output, datasets with results, or files in key-value store.
In Standby mode, an Actor provides a web server which can be used as a website, API, or an MCP server.

Apify vocabulary and the platform model are defined once, in the agent quickstart at https://apify.com/agents.md.

## How to integrate an Actor?

If asked about integration, you help developers integrate Actors into their projects.
You adapt to their stack and deliver integrations that are safe, well-documented, and production-ready.

Do not guess an integration path. Every one of them is in the agent quickstart at https://apify.com/agents.md: the Apify MCP server, Agent Skills with the Apify CLI, the JavaScript and Python clients, the REST API, and the account-free path for an agent with no human to sign in. It also carries the rule on stating cost before the first paid run.

For examples already wired to this Actor's own input schema, see the [API](#api) section below.

Each client library has reference documentation the quickstart does not restate: [JavaScript/TypeScript](https://docs.apify.com/api/client/js/docs.md) (`npm install apify-client`) and [Python](https://docs.apify.com/api/client/python/docs.md) (`pip install apify-client`).

# README

## 🦅 ReconHawk — Attack Surface & Subdomain Takeover Scanner

> **Read-only external attack-surface recon (EASM).** Subdomain discovery, WAF/CDN
> fingerprinting, subdomain-takeover risk, exposed cloud storage buckets, and
> leaked AWS keys — for domains you own or are explicitly authorized to test.

**Use only on your own infrastructure, or in-scope assets under a bug bounty /
pentest engagement.** Every check is a read-only GET against a public API or
the target's own HTTP server — no exploitation, no login bypass, no data
exfiltration.

***

### 👥 Who needs this

| You are a… | You get… |
|---|---|
| 🎯 **Bug bounty hunter** | Fast recon across every in-scope domain: subdomains, CDN, takeover candidates |
| 🛡️ **Pentester** | A structured attack-surface map before manual testing starts |
| 🏢 **Security / AppSec team** | Continuous shadow-IT & external attack-surface monitoring for your own domains |
| 🚀 **Startup / indie dev** | A free sanity check for exposed buckets and leaked keys before launch |

### ✨ What it checks, per domain

- 🌐 **Subdomain discovery** — certificate-transparency logs, passive DNS archives (Wayback, AnubisDB, ThreatMiner, RapidDNS), plus a common-name wordlist
- 🛡️ **WAF/CDN fingerprint** — Cloudflare, AWS CloudFront/WAF, Akamai, Fastly, Google Cloud, and more
- 🚨 **Subdomain-takeover risk** — every discovered CNAME checked against the real, community-maintained **36-service** ["Can I take over XYZ?"](https://github.com/EdOverflow/can-i-take-over-xyz) reference database (AWS S3/Elastic Beanstalk, GitHub Pages, Heroku, Shopify, Ghost, Bitbucket, Azure's many managed-service CNAME suffixes, help-desk platforms, and more) — the same reference Subjack/tko-subs/Nuclei's takeover templates draw from
- ☁️ **Exposed cloud storage** — anonymous check for publicly-listable S3 buckets, clearly labeled by confidence: CNAME-confirmed (this domain's own subdomain points at it) vs. guessed-name (a common naming guess — always verify ownership before reporting, since S3 bucket names are globally unique and a guess can hit an unrelated party's bucket)
- 🔑 **Leaked AWS keys** — scans the homepage + its own JS bundles for accidentally-hardcoded `AKIA…`/`ASIA…` access keys
- 📊 **0-100 risk score** + plain-English summary per domain

***

### 🚀 How to use

1. Add one or more domains you own or are authorized to test.
2. Press **Start**.
3. Get one structured result per domain — subdomains, takeover risks, exposed buckets, leaked keys, and an overall risk score.

#### Example 1 — quick single-domain check

```json
{
  "domains": ["example.com"],
  "maxSubdomains": 150,
  "checkTakeoverRisk": true,
  "checkCloudExposure": true,
  "checkWafCdn": true
}
```

#### Example 2 — bug bounty scope, multiple domains, deep sweep

```json
{
  "domains": ["target1.com", "target2.com", "sub.target3.com"],
  "maxSubdomains": 1000,
  "checkTakeoverRisk": true,
  "checkCloudExposure": true,
  "checkWafCdn": true,
  "maxJsFiles": 30
}
```

***

### 📦 Output (per domain)

`domain`, `scanned_at`, `waf_cdn_vendors[]`, `subdomains_checked`, `subdomains_found`,
`subdomains[]` (hostname, ips, classification, cname\_chain), `takeover_risks[]`
(service, hostname, evidence, reference), `exposed_buckets[]` (bucket,
public\_list, match\_type, keys), `leaked_aws_keys[]` (access\_key, source\_url,
context), `risk_score`, `summary`.

***

### 🔎 Keywords

subdomain takeover scanner, subdomain takeover checker, subdomain takeover
vulnerability scanner, attack surface management tool, EASM tool, external
attack surface management, attack surface discovery, bug bounty recon tool,
bug bounty automation, pentest recon tool, penetration testing recon, CNAME
takeover checker, dangling CNAME scanner, dangling DNS record finder, S3
bucket exposure scanner, exposed S3 bucket finder, public cloud storage
scanner, open bucket finder, leaked AWS keys scanner, leaked API key finder,
exposed AWS credentials scanner, WAF detection tool, CDN detection tool,
Cloudflare detector, Akamai detector, Fastly detector, CloudFront detector,
subdomain enumeration tool, subdomain finder, certificate transparency
scanner, CT log subdomain finder, shadow IT discovery tool, attack surface
mapping, external recon automation, security scanner for Apify, Apify
security actor, Apify pentest actor, cyber security recon tool, offensive
security tool, red team recon tool, HackerOne recon automation, Bugcrowd
recon automation, "can I take over xyz" scanner, Subjack alternative,
tko-subs alternative, how to find subdomain takeover vulnerabilities, how to
check if a subdomain is vulnerable to takeover, how to find exposed S3
buckets, how to scan a domain for leaked AWS keys, free attack surface scan.

***

### ⚖️ Responsible use

This actor performs read-only reconnaissance only. It does not attempt to
exploit any finding (e.g. it never actually claims a dangling bucket/CNAME).
Use it only against domains you own, or assets explicitly in-scope under a
bug bounty program or a signed pentest engagement. You are responsible for
having authorization before scanning any domain.

# Actor input Schema

## `domains` (type: `array`):

Root domains you own or are authorized to test, e.g. example.com. Do not include http:// — just the bare domain.

## `maxSubdomains` (type: `integer`):

Caps how many candidate hostnames (from certificate-transparency logs, passive DNS archives, and a built-in common-name wordlist) get actively resolved and checked per domain. Higher = more thorough, slower.

## `checkTakeoverRisk` (type: `boolean`):

Matches every discovered subdomain's CNAME against the real, community-maintained 'Can I take over XYZ?' database (36 services: AWS S3/Beanstalk, GitHub Pages, Heroku, Shopify, Ghost, Azure, and more) — flags dangling CNAMEs anyone could claim and hijack.

## `checkCloudExposure` (type: `boolean`):

Anonymous check for publicly-listable S3 buckets tied to the domain, plus a scan of the homepage + its JS files for accidentally-leaked AWS access keys.

## `checkWafCdn` (type: `boolean`):

One read-only request to identify which CDN/WAF (if any) fronts the domain — Cloudflare, AWS CloudFront/WAF, Akamai, Fastly, Google Cloud, and more.

## `maxJsFiles` (type: `integer`):

Used only when 'Check cloud storage exposure' is on.

## Actor input object example

```json
{
  "domains": [
    "example.com"
  ],
  "maxSubdomains": 300,
  "checkTakeoverRisk": true,
  "checkCloudExposure": true,
  "checkWafCdn": true,
  "maxJsFiles": 15
}
```

# Actor output Schema

## `results` (type: `string`):

No description

# API

You can run this Actor programmatically using our API. Below are code examples in JavaScript, Python, and CLI, as well as the OpenAPI specification and MCP server setup.

## JavaScript example

```javascript
import { ApifyClient } from 'apify-client';

// Initialize the ApifyClient with your Apify API token
// Replace the '<YOUR_API_TOKEN>' with your token
const client = new ApifyClient({
    token: '<YOUR_API_TOKEN>',
});

// Prepare Actor input
const input = {
    "domains": [
        "example.com"
    ]
};

// Run the Actor and wait for it to finish
const run = await client.actor("inexhaustible_glass/reconhawk").call(input);

// Fetch and print Actor results from the run's dataset (if any)
console.log('Results from dataset');
console.log(`💾 Check your data here: https://console.apify.com/storage/datasets/${run.defaultDatasetId}`);
const { items } = await client.dataset(run.defaultDatasetId).listItems();
items.forEach((item) => {
    console.dir(item);
});

// 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/js/docs

```

## Python example

```python
from apify_client import ApifyClient

# Initialize the ApifyClient with your Apify API token
# Replace '<YOUR_API_TOKEN>' with your token.
client = ApifyClient("<YOUR_API_TOKEN>")

# Prepare the Actor input
run_input = { "domains": ["example.com"] }

# Run the Actor and wait for it to finish
run = client.actor("inexhaustible_glass/reconhawk").call(run_input=run_input)

# Fetch and print Actor results from the run's dataset (if there are any)
print(f"💾 Check your data here: https://console.apify.com/storage/datasets/{run.default_dataset_id}")
for item in client.dataset(run.default_dataset_id).iterate_items():
    print(item)

# 📚 Want to learn more 📖? Go to → https://docs.apify.com/api/client/python/docs/quick-start

```

## CLI example

```bash
echo '{
  "domains": [
    "example.com"
  ]
}' |
apify call inexhaustible_glass/reconhawk --silent --output-dataset

```

## MCP server setup

```json
{
    "mcpServers": {
        "apify": {
            "type": "http",
            "url": "https://mcp.apify.com/?tools=fetch-actor-details,inexhaustible_glass/reconhawk"
        }
    }
}
```

The hosted server signs you in with OAuth on first connect, so no API token belongs in this config. Clients without OAuth support can send an `Authorization: Bearer <APIFY_API_TOKEN>` header instead, using a token from API & Integrations in Apify Console (https://console.apify.com/settings/integrations).

## OpenAPI specification

Download the OpenAPI definition: https://api.apify.com/v2/actors/CpEfncdGiCWf9DdOk/builds/FgB1M9X1bfsr9gEfO/openapi.json
