Skip to content
All security projects
Security projectDemo readyAttack surface

ShadowSurface

Attack surface monitoring tool — scans domains, subdomains, SSL certificates, open ports, exposed admin paths, and security headers to surface external-facing risk.

Builds an external attack surface picture for a domain you own. Enumerates subdomains, checks SSL certificate validity and expiry, scans known ports, flags exposed admin paths and dev endpoints, and audits security headers. Prioritized risk-scored inventory plus analyst handoff report.

PythonCLISubdomain enumSSL/port audit

Catalog entry only — a full write-up lands closer to release.

Related across catalogs

Want a heads-up when ShadowSurface releases?

Subscribe via blog