Map the public surface
Discover live hosts, subdomains, services, DNS posture, public APIs, and exposed application paths from one submitted target.
TargetHunt turns any domain into a professional external security assessment. Discover assets, validate vulnerabilities, prioritize risk, and generate report-ready evidence in minutes.
7
customer-visible phases
0
agents to install
82
risk score example
Built for teams with public products, APIs, and infrastructure
TargetHunt is built for teams that need a clear read on their external exposure without a heavy consulting cycle or noisy scanner dashboard.
Discover live hosts, subdomains, services, DNS posture, public APIs, and exposed application paths from one submitted target.
Separate noisy scanner output from evidence-backed findings across headers, TLS, CVE intelligence, API behavior, and browser signals.
Generate web and PDF reports with impact, affected assets, remediation, standards mapping, evidence, clean checks, and limitations.
The user flow stays calm while the engine runs a seven-phase external assessment behind the scenes.
Resolve domains, services, ports, URLs, DNS records, and browser-observed targets.
Correlate JavaScript, APIs, headers, TLS, CORS, methods, and service fingerprints.
Run bounded checks to confirm exploitability without storing raw secrets or response bodies.
Turn normalized evidence into prioritized findings and executive-ready output.
Report workspace
runningRisk score
82
public attack surface
Validated findings
18
4 high or critical
Assets mapped
50K+
daily observation scale
Report status
ready
PDF and web
Seven-phase pipeline
activeExternal security only works when discovery, validation, evidence, and reporting move together.
Subdomains, ports, services, APIs, DNS, TLS, headers
CORS, HTTP methods, GraphQL, OpenAPI, auth-token metadata
CVE intelligence, XSS, SQLi, DAST probes, browser evidence
Safe retention, normalized findings, redacted payload metadata
Projects, scans, reports, PDFs, progress phases, credits
Risk scores, CVSS, standards mapping, remediation, limitations
~/external-surface/run.log
01$ targethunt scan https://app.target-corp.com
02recon complete: 7 live hosts, 38 endpoints, 14 services
03dns posture reviewed: SPF, DMARC, CNAME, takeover candidates
04api discovery: 19 candidate routes, 4 auth-sensitive paths
05high confidence: missing policy enables browser exposure
06critical candidate: service version maps to exploited CVE
07report queued: evidence, remediation, and confidence retained
Progress, request counts, evidence, and limitations are visible without exposing raw scanner internals to customers or non-security teammates.
Seven clear phases instead of a raw tool dump.
Conservative telemetry helps explain scan activity.
Domain-bound projects keep scans inside authorized surface.
Normalized findings avoid raw secrets and response bodies.
Each website security scan consumes 500 credits. Plans include monthly credits; packs add one-time credits when teams need extra runs.
Single Scan
₹999
500 credits · 1 scans
Recon Pack
₹4,499
2,500 credits · 5 scans
| Tier | Level | Price/mo | Credits | Scans |
|---|---|---|---|---|
| Recon | Free Plan | ₹0 | 500 | 1 |
| Operator | Pro Plan | ₹3,999 | 2,500 | 5 |
| Ethical Hacker | Pro+ Plan | ₹6,499 | 7,500 | 10 |
| Red Teamer | Max | ₹8,999 | 10,000 | 15 |
| The GodFather | Enterprise Plan | Custom | Pooled | Unlimited |
TargetHunt gives teams a continuous external view without replacing deep manual assessments.
| Capability | TargetHunt | Traditional pen test | Basic scanner |
|---|---|---|---|
| Target-first scan flow | Yes | No | Usually no |
| Always-on external visibility | Yes | Point in time | Limited |
| Evidence-backed prioritization | Yes | Manual | Basic severity |
| Report PDF and web UI | Yes | PDF only | Varies |
| No agent or code install | Yes | Yes | Varies |
No. The primary flow is target-first: type a domain or URL, start the scan, and the backend resolves or creates the correct domain-bound project.
The default external assessment is bounded and non-destructive. It stores normalized evidence and avoids retaining raw secrets, auth headers, response bodies, or scanner artifacts.
Reports include findings, severity, affected assets, proof, business impact, remediation, standards mapping, tool status, coverage, clean checks, and limitations.
Pen tests remain useful for deep manual review. TargetHunt covers the changing external surface between assessments and keeps teams aware of new exposure.
No agents
No raw secrets
Safe evidence
API-aware
Minutes to signal
Start with one domain and get a professional external security assessment with evidence, prioritization, and report-ready remediation guidance.