What problem does it solve? Security professionals and bug bounty hunters need to map a target's infrastructure—domains, subdomains, IPs, netblocks, and ASNs—before any assessment, but gathering this intelligence manually across WHOIS, DNS, certificate transparency, and scanning tools is slow and error-prone. ## Core Features & Use Cases - Passive Reconnaissance: WHOIS lookups, DNS enumeration, certificate transparency subdomain discovery, and IPInfo geolocation/ASN data with no authorization required. - Authorized Active Scanning: Port scanning with naabu, HTTP probing with httpx, and service detection after explicit authorization confirmation. - Bounty Program Tracking: Searchable database of public bug bounty programs with in-scope domains for target selection. - AI Scan Analysis: Deep analysis of large nmap/masscan outputs using Gemini 3 Pro to identify high-value targets, anomalies, and attack paths. - Use Case: A pentester receives a new engagement scope, runs passive domain recon to enumerate 47 subdomains, confirms authorization, then port-scans live hosts and generates a structured infrastructure report. ## Quick Start Ask the assistant to do passive recon on a domain you own, such as example.com, to enumerate its subdomains, DNS records, and IP infrastructure.