Domains and subdomains
We enumerate the domains and subdomains tied to your name, including the ones nobody remembers standing up.
Request a free first pass with your domain and permission. Mapping runs in minutes. A person validates the findings. You get a client-ready summary. No card or commitment is required.
The scan starts from your domain and works outward across everything reachable from the open internet. This is the external surface an attacker sees first.
We enumerate the domains and subdomains tied to your name, including the ones nobody remembers standing up.
Open ports, public services, and forgotten infrastructure that an attacker can reach from the open internet.
Admin panels, dashboards, and auth endpoints that are reachable without ever touching your network.
API keys, tokens, and credentials exposed in public code, configs, or responses, validated before we report them.
Leaked secrets → See how the exposed API keys scanner validates leaked credentials, or browse the exposure library.
A raw scanner hands you thousands of alerts and walks away. Adversary validates first, then reports what an attacker can actually reach.
New to the terms? → Read the attack surface glossary
You built the product before you built the security program. That is normal. A first-pass scan tells you what that tradeoff exposed, so you can fix the parts that matter before a customer review, an auditor, or an attacker finds them for you.
Legba is a Chrome extension with two modes. Ghost gives you a private browser route. Shield opens a page in an isolated browser off your device.
Free for 30 days. No card required.
Ghost. A private route for your browser. Shield. An isolated browser, off your device. Choose the mode. Close when finished.