What problem does it solve?
Manual reconnaissance across many small-business targets in the same industry repeats identical probes with only paths and platforms changing, wasting time and producing inconsistent coverage.
Core Features & Use Cases
- Sector-aware probing: Loads per-industry platform and high-value path data from references/sectors.yaml covering 25 sectors such as plumbing, dentists, and automotive dealers.
- Standard probe suite: Checks WordPress presence, REST API user enumeration, CORS credential reflection, XMLRPC exposure, debug log PII leakage, directory listing, and source leaks like .env and .git.
- Verification discipline: Defines explicit confirmation criteria so parked domains, wildcard DNS, and non-exploitable CORS headers are not reported as findings.
- Use Case: Given a list of dental clinic domains, run the plumbing-style probe suite with the dentists sector to surface exposed debug logs, patient-portal paths, and XMLRPC endpoints, saving per-target markdown reports.
Quick Start
Run sector reconnaissance on my authorized target list by loading the dentists sector data and probing each domain for WordPress, CORS, XMLRPC, and exposed debug logs.