pwnsy

Exposure Graph

Passive recon map for a domain.
Try:
Enter a domain to map its public footprint.
How this works

Public sources only: DNS over HTTPS (dns.google), certificate transparency (crt.sh, Cert Spotter), passive DNS (HackerTarget), RDAP for registration, ipwho.is for the network owner of each IP, and Hudson Rock counts for infostealer logs.

Each discovered name is resolved (A and AAAA, first 150 names). Dangling means the name has a CNAME whose target no longer exists (NXDOMAIN): if the target is a hosted service, someone else may be able to claim it. No answer names are usually retired hosts still listed in old certificates.

Risk labels are triage prompts for an analyst to verify. Click a graph node to jump to its row.