Live external attack surface workshop. See how TargetHunt turns one domain into report-ready evidence.Register
New external surface command center

Find the gaps attackers can reach before they become incidents.

TargetHunt turns any domain into a professional external security assessment. Discover assets, validate vulnerabilities, prioritize risk, and generate report-ready evidence in minutes.

live surface
DNS
API
TLS
CVE
WEB

7

customer-visible phases

0

agents to install

82

risk score example

Built for teams with public products, APIs, and infrastructure

SaaS
Fintech
Healthcare
Agencies
AppSec
Founders
B2B platforms
Cloud teams
Product

Security signal without security theater

TargetHunt is built for teams that need a clear read on their external exposure without a heavy consulting cycle or noisy scanner dashboard.

Map the public surface

Discover live hosts, subdomains, services, DNS posture, public APIs, and exposed application paths from one submitted target.

Validate what matters

Separate noisy scanner output from evidence-backed findings across headers, TLS, CVE intelligence, API behavior, and browser signals.

Ship usable reports

Generate web and PDF reports with impact, affected assets, remediation, standards mapping, evidence, clean checks, and limitations.

Control surface

One domain in, evidence out

The user flow stays calm while the engine runs a seven-phase external assessment behind the scenes.

01

Recon

Resolve domains, services, ports, URLs, DNS records, and browser-observed targets.

02

Analysis

Correlate JavaScript, APIs, headers, TLS, CORS, methods, and service fingerprints.

03

Validation

Run bounded checks to confirm exploitability without storing raw secrets or response bodies.

04

Reporting

Turn normalized evidence into prioritized findings and executive-ready output.

Report workspace

running

Risk score

82

public attack surface

Validated findings

18

4 high or critical

Assets mapped

50K+

daily observation scale

Report status

ready

PDF and web

Seven-phase pipeline

active
Recondone
JS analysisdone
DNSdone
API discoverydone
Vulnerability testingdone
Penetration validationnow
Reportingnext
Coverage

Designed for the parts attackers actually see

External security only works when discovery, validation, evidence, and reporting move together.

External discovery

Subdomains, ports, services, APIs, DNS, TLS, headers

Application behavior

CORS, HTTP methods, GraphQL, OpenAPI, auth-token metadata

Vulnerability checks

CVE intelligence, XSS, SQLi, DAST probes, browser evidence

Evidence handling

Safe retention, normalized findings, redacted payload metadata

Workspace workflow

Projects, scans, reports, PDFs, progress phases, credits

Security reporting

Risk scores, CVSS, standards mapping, remediation, limitations

~/external-surface/run.log

01$ targethunt scan https://app.target-corp.com

02recon complete: 7 live hosts, 38 endpoints, 14 services

03dns posture reviewed: SPF, DMARC, CNAME, takeover candidates

04api discovery: 19 candidate routes, 4 auth-sensitive paths

05high confidence: missing policy enables browser exposure

06critical candidate: service version maps to exploited CVE

07report queued: evidence, remediation, and confidence retained

Operator view

Readable enough for product, useful enough for security

Progress, request counts, evidence, and limitations are visible without exposing raw scanner internals to customers or non-security teammates.

Live progress

Seven clear phases instead of a raw tool dump.

Request estimates

Conservative telemetry helps explain scan activity.

Scope clarity

Domain-bound projects keep scans inside authorized surface.

Safe evidence

Normalized findings avoid raw secrets and response bodies.

Pricing

Simple credits, clear scan counts

Each website security scan consumes 500 credits. Plans include monthly credits; packs add one-time credits when teams need extra runs.

Single Scan

₹999

500 credits · 1 scans

Recon Pack

₹4,499

2,500 credits · 5 scans

TierLevelPrice/moCreditsScans
ReconFree Plan₹05001
OperatorPro Plan₹3,9992,5005
Ethical HackerPro+ Plan₹6,4997,50010
Red TeamerMax₹8,99910,00015
The GodFatherEnterprise PlanCustomPooledUnlimited
Positioning

Between a scanner and a pen test, always on

TargetHunt gives teams a continuous external view without replacing deep manual assessments.

CapabilityTargetHuntTraditional pen testBasic scanner
Target-first scan flowYesNoUsually no
Always-on external visibilityYesPoint in timeLimited
Evidence-backed prioritizationYesManualBasic severity
Report PDF and web UIYesPDF onlyVaries
No agent or code installYesYesVaries
FAQ

Questions before your first scan

Do I need to configure a project before scanning?

No. The primary flow is target-first: type a domain or URL, start the scan, and the backend resolves or creates the correct domain-bound project.

Will TargetHunt modify production systems?

The default external assessment is bounded and non-destructive. It stores normalized evidence and avoids retaining raw secrets, auth headers, response bodies, or scanner artifacts.

What appears in the report?

Reports include findings, severity, affected assets, proof, business impact, remediation, standards mapping, tool status, coverage, clean checks, and limitations.

Where does this fit with penetration testing?

Pen tests remain useful for deep manual review. TargetHunt covers the changing external surface between assessments and keeps teams aware of new exposure.

No agents

No raw secrets

Safe evidence

API-aware

Minutes to signal

Ready to see what attackers see?

Start with one domain and get a professional external security assessment with evidence, prioritization, and report-ready remediation guidance.