Authorized-use attack-surface recon

Evaluate your perimeter defenses from an outside perspective.

A fast desktop recon tool that maps your external footprint, finds what's exposed, and grades your risk — then watches it for changes.

Runs locally on macOS · Windows · Linux — no account, no telemetry, no vendor cloud.

One tool, the whole external surface

Point it at a domain and it runs the full toolchain — discovery, exposure, and a graded verdict.

Attack-surface audit

Subdomains, ports, TLS, DNS/email posture and web checks rolled into ranked findings with an A–F grade.

Subdomain discovery

Passive OSINT + CT logs, DNS brute force and permutations — de-duplicated and takeover-checked.

Known-CVE detection

Passively fingerprints tech + versions and matches them against a refreshable NVD-derived ruleset.

Secrets & exposed files

Scans HTML + first-party JS for leaked keys and probes for .git/.env/dashboards — masked, tuned to cut false-positive noise.

Cloud buckets & look-alikes

Finds public S3/GCS/Azure buckets and registered typosquat domains before someone else does.

Site crawler

Same-host, GET-only spider maps every page + form so the checks see the whole site, not just the root.

Continuous monitoring

Re-scan on a schedule and get a Slack/Teams/email alert the moment your surface changes.

Authenticated scope

Replay a session to scan behind a login — credentials encrypted at rest in your OS keychain.

Reports & history

Shareable HTML/CSV, run history with grade trends, and per-product breakdowns for multi-asset orgs.

Close the loop on every finding Pro

Findings carry a stable identity across scans, so the ticket you open today re-attaches itself on every rescan — and you never log the same issue twice.

3 open2 ticketed (67%)oldest 90 dcritical without ticket: 1
SevFindingDays openTicket
criticalRDP exposed on port 338990
highMissing HSTS90SEC-742 · in progress
mediumDMARC policy is p=none90SEC-750 · open
  • Link any tracker — Jira, GitHub, Linear, ServiceNow… paste the ticket key or URL and keep its status alongside the finding.
  • Duplicate-safe — a finding that already has an active ticket warns before you open another, in the app and on the CLI.
  • Aging you can act on — days open, oldest, median and criticals with no ticket, on one board; rows turn red at 90 days.
  • CI gatecrow-recon findings --older-than 30 --no-ticket --severity critical --fail-on fails the build when a critical goes a month untracked.

Built to automate

Not just a desktop app — a scriptable CLI that drops straight into CI/CD and your own tooling.

 crow-recon
# emit JSON for your pipeline
$ crow-recon audit example.com --json > surface.json

# exits non-zero on a D/F grade — fail the build on a regression
$ crow-recon audit example.com && ./deploy.sh

# save + diff + alert on any change
$ crow-recon audit example.com --save-report nightly --alert
  • JSON on every scan command — pipe results straight into your own tools.
  • CI-friendly exit codes — a D/F grade exits non-zero, so a pipeline can fail on a regression.
  • HTML / CSV / JSON reports — machine-readable and share-ready.
  • Importable Python engine — embed the scanner directly in your own scripts and tooling.

Works with the sources you already trust

Crow Recon folds the best OSINT & Certificate-Transparency feeds into one de-duplicated result — free sources out of the box, plus your own API keys for the premium ones.

crt.sh VirusTotal Shodan SecurityTrails Chaos · ProjectDiscovery FullHunt AlienVault OTX NVD · CVE data

Bring your own keys — stored locally with owner-only permissions, and only ever sent to the service that issued them.

Free to start. Pro when it's your job.

The scanner is free forever. Pro makes it continuous, authenticated, and automation-ready.

CapabilityFreePro
Full audit, CVE, secrets, buckets, typosquat
Reports + diff any two runs (HTML/CSV)
Root domains per scan3unlimited
Site crawler25 pagesunlimited
Continuous monitoring + change alerts
Scan-diff history + grade trendslast 5 runsunlimited
Authenticated scope (scan behind a login)
Finding tickets + aging board (duplicate-safe)

Free

$0
  • The full one-shot scanner
  • All detection modules
  • Local reports + manual diff
  • macOS / Windows / Linux
Download

Pro most popular

$99 / year
  • Everything in Free
  • Continuous monitoring + alerts
  • Unlimited crawl, history & targets
  • Authenticated scope
  • Finding tickets & aging board
  • Priority support
Get Pro

Download Crow Recon

Free, no account required. Signed builds are coming soon for macOS, Windows and Linux.

macOS (Apple Silicon) soon macOS (Intel) soon Windows soon Linux soon

Authorized use only — scan only assets you own or have explicit permission to test.