CSP Header Analysis: Scans websites for Content Security Policy headers
Domain Extraction: Identifies all external domains trusted by CSP policies
Availability Checking: Uses AWS Route53 to check if trusted domains are available for registration
PublicWWW Research: Discovers how available domains are used across the web (optional)
Bug Bounty Reports: Auto-generates professional security reports
High-Performance Scanning: Beast mode with 1000 DNS concurrency
Resume Capability: Continue interrupted scans with wordlist tracking
Automatic Organisation: Scan results organised into hot/archive folders
Bonus Intelligence
Typosquatting Discovery: DNS enumeration naturally uncovers typosquatted domains that resolve but weren't registered by the target
Identifies potential phishing domains
Reveals trademark infringement
Discovers forgotten test/staging domains
Exposes defensive registrations that need monitoring
Using AWS availability checker has some limitations (not full tld support) but it's 100% cheaper than performing a whois lookup
splintersio•42m ago
Bonus Intelligence Typosquatting Discovery: DNS enumeration naturally uncovers typosquatted domains that resolve but weren't registered by the target Identifies potential phishing domains Reveals trademark infringement Discovers forgotten test/staging domains Exposes defensive registrations that need monitoring
Using AWS availability checker has some limitations (not full tld support) but it's 100% cheaper than performing a whois lookup
Supporting article (badly formatted) https://thecontractor.io/ghosted/