Maps competitor infrastructure: open ports, exposed services, cloud providers, TLS certificates, and known CVEs. Reveals tech stack and security posture without touching their systems.
Free
Dark OSINT
Every 24 hr
Passively maps competitor subdomains via public DNS records. Strategic subdomains (api2, beta, staging, checkout, careers) signal product expansion and infrastructure moves.
Free
Dark OSINT
Every 6 hr
Checks if competitor domains have appeared in known data breaches. Breach history reveals security maturity and can signal customer trust vulnerabilities you can leverage.
Free
Dark OSINT
Every 24 hr
Checks 25 common bucket naming patterns for public accessibility. Publicly listable S3 buckets can reveal build artifacts, marketing assets, exports, and internal docs โ all legally accessible.
Free
Dark OSINT
Every 24 hr
Scans public paste sites for accidental data exposure โ API keys, internal URLs, database strings, credentials. Engineers debugging or onboarding often accidentally share sensitive snippets.
Free
Dark OSINT
Every 6 hr
Searches public GitHub repositories for accidental internal domain references, unreleased feature keywords, and new repos. Catches leaks and roadmap hints in public code.
Free
Dark OSINT
Every 12 hr
Monitors TLS certificate issuance for competitor domains. New certificates for internal subdomains, staging environments, or new products are publicly logged and often reveal stealth projects.
Free
Dark OSINT
Every 60 min
Tracks version updates, changelogs, and rating changes for competitor mobile apps. App updates often telegraph backend changes, new features, and support quality trends.
Free
OSINT
Every 60 min