01 Attack surface scanner

Find what's
exposed.

Unauthenticated scan for exposed files, missing security headers, weak TLS, CORS misconfigurations, and subdomain takeover risk — one evidence-backed report.

Public HTTP/S targets only Reports expire after 14 days No login required

03 Built for honest diagnostics

01

Unauthenticated only

Every check runs without credentials, showing what an external attacker can see.

02

Evidence-backed

Every finding includes the raw HTTP response or configuration that revealed it.

03

Safe by default

Private targets, non-standard ports, and exploitation attempts are blocked.

METHOD Evidence boundaries

What VulnScope scans

RECON

DNS & SSL reconnaissance

Resolves DNS records, inspects TLS certificate properties, and checks for protocol-level weaknesses.

HDR

Security header audit

Checks for presence and correctness of HSTS, CSP, X-Frame-Options, X-Content-Type-Options, and other security headers.

PTH

Sensitive path probing

Tests for commonly exposed files: .env, .git/config, backup archives, admin panels, and configuration files.

FNG

Technology fingerprinting

Identifies server software, CMS, frameworks, and CDN from response headers and HTML markers.

CRS

CORS misconfiguration test

Tests whether the target returns permissive Access-Control headers that could enable cross-origin data theft.

TKO

Subdomain takeover check

Queries Certificate Transparency logs for subdomains, then probes for dangling CNAME records pointing to claimable services.

VulnScope does not exploit vulnerabilities, submit forms, bypass authentication, or test for injection. It is a reconnaissance tool, not a penetration tester.