Skip to content
FullHunt

Internet intelligence infrastructure for security products. Via API. Via data feeds. Via MCP.

Embed internet asset, service, vulnerability, and exploit data without building scanners. Map complete external footprints in minutes.

Security vendors embed it. Enterprises monitor exposure. MSSPs run it across clients.

examples: domain:kaspersky.com kaspersky.com port:80 has_ipv6:true Read more about search filters

Search across domains, subdomains, hosts, IPs, open ports, services, technologies, certificates and CVEs.

One intelligence engine. Multiple delivery paths.

FullHunt supplies discovery, exposure, exploit, and credential intelligence through APIs, the enterprise platform, and the multi-tenant MSSP workspace.

Compare delivery paths

Asset Discovery

Internet-scale enumeration of subdomains, IPs, services, and cloud assets - continuously updated.

Exposures

Open ports, misconfigurations, expired certificates, and exposed admin panels surfaced automatically.

Alerts

Change events when new assets appear or known assets change state, configuration, or risk posture.

Vulnerabilities

CVEs matched to your live attack surface, each carrying an exploitability-weighted score.

Vulnerability and Exploit Intelligence

Curated exploit PoC tracking and KEV alignment so you remediate what attackers will actually use.

Dark Web Monitoring

Credential leaks, breached accounts, and dark web mentions tied back to your monitored domains.

A FullHunt Console search for acme.com: 29 discovered assets, 114 external ports, cloud
            and CDN counts, per-host detail with open ports, and results mapped by country.

FullHunt Intelligence APIs

For Security Vendors, Builders & AI Workflows

Query host, domain, exposure, vulnerability, exploit, and passive DNS data through the console, REST APIs, or Model Context Protocol server.

The FullHunt Enterprise vulnerability view: each finding with its affected asset,
            category, status, severity and automated validation result, newest first.

FullHunt Enterprise

For Enterprises & MSSPs

Use FullHunt's intelligence directly for continuous external exposure monitoring, vulnerability validation, dark web monitoring, and reporting across your organization or client environments.

Internet intelligence, delivered through REST APIs.

Query host, domain, passive DNS, vulnerability, and exploit data for product features, enrichment pipelines, and investigations.

  • Documented endpoints
  • Python and cURL examples
  • Per-endpoint rate limits

Read the docs

FullHunt API
GET /api/v1/host/{host} Host intelligence
GET /api/v1/domain/{domain}/subdomains Subdomain enumeration
GET /api/v1/intel/ip-to-hosts?ip={ip} IP → hosted assets
GET /api/v1/nexus/passive-dns/lookup?domain={domain} Passive DNS history
GET /api/v1/vulnerability-intelligence/vulnerability-search CVE & exploit search
GET /api/v1/attack-surface/on-demand-scan?target={target} On-demand scan
POST /api/v1/oem/attack-surface/search OEM attack surface
Response 200 OK 12ms
{
  "host": "legacy-vpn.acme-corp.com",
  "ip_address": "185.220.101.47",
  "is_live": true,
  "network_ports": [443, 8443, 4433],
  "technologies": ["Pulse Secure 9.1R3", "Apache 2.4.49"],
  "vulnerabilities": [
    {
      "cve_id": "CVE-2021-22893",
      "cvss_v3_score": 10.0,
      "severity": "CRITICAL",
      "is_kev": true,
      "epss_score": 0.974,
      "has_public_exploit": true,
      "exploit_count": 14
    }
  ],
  "metadata": { "last_seen": "2026-03-08T14:22:00Z", "validated": true }
}
CRITICAL · CVSS 10.0 CISA KEV EPSS 97.4%
acme-corp.com 25 hosts
resolved 3 ports open 9 fingerprinted 10 cve matched 2 public exploit 1 hosts 2 4 1 6 2 5 3 2 1 4 7 9 4 2 1 5 3 8 4 2 3 6 not scanned legacy-vpn · CVE-2021-22893
resolved
is_live
ports open
network_ports
fingerprinted
technologies
cve matched
vulnerabilities[].cve_id
public exploit
has_public_exploit

One intelligence layer for products, enterprises, and MSSPs.

Embed FullHunt data in a security product, monitor your own perimeter, or operate across client environments.

Run FullHunt across separate client environments.

Create a workspace for each client, control access with roles, and send alerts and reports from one MSSP account.

  • Multi-tenant client workspaces
  • Role-based access
  • Alerts for MSSP and client teams
  • Client-ready reports
  • API access

View the MSSP offering

FullHunt Enterprise All Organizations view with asset, vulnerability, certificate, domain, and IP totals

The data infrastructure behind FullHunt, available to license.

Internet hosts indexed 2B+
CVE-to-host mappings 800M+
Average data freshness cycle 24 hr

Embed internet intelligence directly into your product.

Add discovery, exposure, vulnerability, and exploit data to your product through APIs and feeds, without building and maintaining scanners.

Explore OEM APIs

Raw data feeds & licensing

Host, port, CVE, and tech stack data, delivered as structured feeds or via API.

Private API deployments

Dedicated infrastructure isolated from shared tenants. Your SLA, your capacity.

Custom SLAs & volume pricing

Flexible commercial terms for enterprise integrations and high-volume use cases.

On-demand scanning & end-to-end workflow

Trigger scans programmatically and receive structured results through the full pipeline: discovery, fingerprinting, vulnerability mapping, and alerting in one flow.

From internet data to action in four stages.

FullHunt discovers infrastructure, tracks change, validates exposures, and delivers findings to products and security teams.

Step 1

Discover

Enumerate domains, subdomains, IPs, cloud services, technologies, and certificates from internet-facing infrastructure.

Step 2

Monitor

Continuous monitoring records newly observed assets, service changes, certificate changes, and configuration drift.

Step 3

Detect

Runtime checks map CVEs to observed assets and add Exploit Prediction Scoring System and CISA Known Exploited Vulnerabilities context.

Step 4

Deliver

Send structured findings through APIs, data feeds, webhooks, security integrations, or the FullHunt platform.

APIs and integrations.

Query FullHunt through REST, Python, or Model Context Protocol. Send findings to SIEM, SOAR, ticketing, and messaging tools.

FullHunt integration bearings LLMs OpenAI · Anthropic Claude Skill Agent workflows API & SDK REST · Python Ticketing Jira · ServiceNow SOAR XSOAR · FortiSOAR SIEM Splunk · Sentinel MCP Server Native AI tools Messaging Slack · Teams FullHunt INTELLIGENCE HUB
FullHunt
Intelligence hub
LLMs
OpenAI · Anthropic
Claude Skill
Agent workflows
API & SDK
REST · Python
Ticketing
Jira · ServiceNow
SOAR
XSOAR · FortiSOAR
SIEM
Splunk · Sentinel
MCP Server
Native AI tools
Messaging
Slack · Teams

API and SDK

REST API and Python SDK.

Model Context Protocol

FullHunt tools for MCP-compatible clients.

SIEM and SOAR

Splunk, Microsoft Sentinel, Cortex XSOAR, and FortiSOAR.

Ticketing and messaging

Jira, ServiceNow, Slack, and Microsoft Teams.

AI agents that understand your attack surface.

Connect Claude, Copilot, or any MCP-compatible AI agent to FullHunt data. Query infrastructure, trigger authorized scans, and retrieve vulnerability and exploit context.

Ship internet intelligence under your own brand.

Use FullHunt APIs and data feeds for discovery, exposure management, vulnerability intelligence, and threat intelligence features inside your product.

Constantly Evolving Intelligence

5,376 Web Tech Signatures Fingerprints across frameworks, CMSs, CDNs, and web services. Continuously updated.
1,866 Product Signatures Version-aware detection across network devices, cloud APIs, and software stacks.
130,000+ Exploits Tracked PoC and weaponized exploit records updated as new sources are processed and mapped to observed assets.

Vulnerability and Exploit Intelligence

Curated security research and continuously updated exploit tracking, delivered through the console and APIs.

Explore Vuln Intel

One intelligence layer. Six security workflows.

Use FullHunt data in your product, enterprise program, MSSP service, or investigation workflow.

Internet-Scale Discovery

Map observed external-facing assets: subdomains, IPs, cloud services, and shadow IT. Records update as the footprint changes.

Continuous Monitoring

Track newly observed services, certificate changes, and configuration drift. Alerts identify changes between observations.

High-Fidelity Scanning

Run maintained vulnerability checks against observed services and keep the affected asset, evidence, and validation status together.

Vulnerability and Exploit Intelligence

Map CVEs to observed assets and add EPSS, CISA KEV, and public exploit context for prioritization.

Dark Web Monitoring

Credential leaks, breached accounts, typosquatting, and phishing domains, detected and tied back to your monitored assets.

Third-Party Risk

Extend visibility to vendors and subsidiaries with scoped monitoring, risk scoring, and consolidated reporting.

Explore FullHunt products

Continuously Updated Vulnerability Checks

FullHunt maps newly added checks to observed internet-facing assets and exposes the results through the platform and APIs.

Loading vulnerability check data…

Explore FullHunt products

Built from internet-scale security research.

FullHunt began with continuous external exposure monitoring. That discovery and enrichment engine now supplies APIs, enterprise workflows, and multi-tenant MSSP operations.

  • Internet Discovery
  • Exposure Monitoring
  • Exploit Context
  • API Delivery
FullHunt external infrastructure monitoring interface

From exposure monitoring to internet intelligence infrastructure.

The FullHunt platform mapping an organisation's external attack surface

The Start

FullHunt started by helping security teams understand and continuously monitor their external exposure.

The Growth

The discovery and validation engine expanded into vulnerability, exploit, passive DNS, and historical infrastructure data.

The Expand

Security vendors embed that intelligence through OEM APIs. Enterprises use it directly. MSSPs operate it across client environments.

Deliver FullHunt intelligence where it is used.

Send findings to SIEM, SOAR, ticketing, and messaging platforms, or query the same data through APIs and Model Context Protocol.

Native integrations and delivery options

Microsoft Teams
Slack
PushOver
Palo Alto
Jira Software
Sumo Logic
Slack Webhook

Use FullHunt intelligence your way.

Embed it in a product, query it directly, or run the enterprise platform across your organization or client environments.

A FullHunt Console search for acme.com: 29 discovered assets, 114 external ports, cloud
            and CDN counts, per-host detail with open ports, and results mapped by country.

FullHunt Intelligence APIs

For Security Vendors, Builders & AI Workflows

Query host, domain, exposure, vulnerability, exploit, and passive DNS data through the console, REST APIs, or Model Context Protocol server.

The FullHunt Enterprise vulnerability view: each finding with its affected asset,
            category, status, severity and automated validation result, newest first.

FullHunt Enterprise

For Enterprises & MSSPs

Use FullHunt's intelligence directly for continuous external exposure monitoring, vulnerability validation, dark web monitoring, and reporting across your organization or client environments.

Choose how you use FullHunt intelligence.

Embed it in your product, monitor your enterprise, or run it across client environments.