Skip to content
FullHunt

Driving Continuous Innovation in Security Monitoring and Management

We constantly improve our products and services to provide you with the best security monitoring and management experience. Here are some of the improvements we have made to our products and services.

Get Started

How FullHunt monitors an external attack surface

Q3 2026

Product Risks

FullHunt Enterprise separates confirmed findings from inferred ones. A vulnerability a scanner validated against the live service sits apart from a CVE matched to a product and version, so you can work the confirmed set first and treat the rest as leads. Filter either list by when a finding was last seen.

Signature AI, ICS and Database Exposure

FullHunt detects exposed AI services, industrial control systems and databases as named exposure classes, alongside network infrastructure and game servers. An exposed inference endpoint or an ICS controller is tagged for what it is, rather than appearing as an open port with a banner attached.

Enhancement Search Filters

Search supports the full documented filter set across certificates, fingerprints and IPv6 addresses. Certificate subject, issuer, signature algorithm and SHA-256 fingerprint all resolve, and a technology and a service can be combined in a single query.

Product New API Documentation

We rebuilt docs.fullhunt.io with generated OpenAPI references, resource catalogues, and full coverage of the OEM, Nexus, enterprise and agent surfaces. A contract check runs against the live API, so the documentation and the endpoints stay in step.

Enhancement FullHunt Console Redesign

FullHunt Console moved onto the same design system as the rest of the site. Search, host records, Org DB, billing, team and settings were rebuilt on it, with accessibility and mobile layouts verified across the app.

Product Open Source Advisories

FullHunt Vulnerability Intelligence now covers open source ecosystem advisories from OSV and GitHub Security Advisories. Plenty of real bugs never receive a CVE ID, which leaves them invisible to CVE-only tooling. They appear in search, in the feed, and on the CVE pages they relate to. Every advisory downloads as JSON.

Feature Exploit Code and Provenance

Exploit records include the actual proof of concept code, its source, and the date exploitation was first observed. You can read and download the exploit inside FullHunt instead of chasing a public link that no longer resolves.

Feature Host Vulnerabilities

Every host view lists the vulnerabilities we found on that host, ranked by severity, across FullHunt Enterprise, FullHunt Console, and public search. Vulnerabilities are surfaced from the service itself, so a host reports what it is exposed to whether or not the software behind it is named.

Feature Open Directory Detection

FullHunt flags exposed open directories on your assets and lists their contents on the host page. Backups, configuration files, and credentials turn up in them regularly.

Feature Tor Exit Node Detection

We tag any asset that resolves to a known Tor exit node, matching against both IPv4 and IPv6 exit lists. You can also check an IP directly through the Nexus API or an AI agent, which answers the triage question of whether an address in your logs is Tor traffic.

Feature Organization Security Scores

Organizations in Org DB have a security score and an exploitability score, calculated from the assets behind every domain the company owns. It is the same A+ to F grade you already see on a single asset, raised to company level. Useful when you are assessing a vendor or sizing an acquisition target.

Enhancement Organization Attribution

Org DB confirms a domain resolves before attributing it to a company, and rechecks domains it dropped earlier so an asset that comes back is picked up again. Subsidiaries we discover on a company become organizations in their own right, with their own footprint and their own score.

Q2 2026

Feature Agentic AI Connectors

FullHunt Agentic AI works in AI clients with strict tool requirements, including ChatGPT Deep Research, alongside Claude and Cursor. 63 Model Context Protocol (MCP) tools cover the API surface, and agents authenticate with a standard Authorization header. Rate limits are applied per API key, so each account gets its own budget.

Product WHOIS Intelligence

New WHOIS lookup and search across the Nexus and OEM APIs. WHOIS records also attach to domain responses on attack surface, subdomain, and domain detail calls. Search by registrant, organization, or expiry date to find infrastructure belonging to a target you already know about.

Product New OEM Endpoints

FullHunt OEM APIs gained vulnerability search, alerts search, and historical hosts search, plus a vulnerability intelligence feed partners can put in front of their own users. Organization management endpoints create organizations and assign assets programmatically, so partners onboard a tenant without waiting on us.

Feature Vulnerability Intelligence Feed API

A feed endpoint returns the newest vulnerabilities and exploits, filtered by keyword, type, and date, with exact CVE lookup. Point it at the products you actually run and route the output into Slack or your alerting pipeline.

Product Attack Surface Change Tracking

FullHunt records what changed on a host and when, across 26 kinds of change: new ports, new products, DNS and certificate changes, cloud and network provider moves, new vulnerabilities, new risk tags, new web technologies, new services. Each change keeps a full snapshot of the host as it was, so you can date an exposure instead of estimating it.

Feature Org DB by Country

Org DB organizations are mapped to the country they operate from, with a country view and country scoped search. National CERTs can work a single jurisdiction. Everyone else can scope research to one market.

Signature New Signatures

Added over 500 new vulnerability checks, bringing coverage past 3,000 CVEs. Web technology detection grew from 5,368 to 6,457 signatures. We rewrote the matcher underneath them, so detections return faster and arrive with product and category context.

Q1 2026

Product FullHunt Console

We rebuilt FullHunt Console. Every asset has a score from A+ to F, and the dashboard, host pages, IP lookup, and organization profiles were redesigned around it. API keys moved into settings, audit logs show who did what, and Global Search joined the rest of the research tooling in Console.

Feature Vulnerability Intelligence Feeds

One feed of new CVEs and new exploits, sorted by recency. Filter by severity, by CISA known-exploited status, by whether a working exploit exists, and by a 7, 30, or 90 day window. Built for the Monday morning question: what landed last week that I need to care about.

Feature Exposures Catalog

A searchable catalog of every exposure check FullHunt runs, filterable by severity and category. Look up what we test for before a scan, or after one, to see what your assets were checked against.

Enhancement KEV and EPSS Enrichment

Vulnerability records include CISA Known Exploited Vulnerabilities (KEV), VulnCheck KEV, and Exploit Prediction Scoring System (EPSS) data. A 9.8 nobody is exploiting is a different problem from a 7.5 attackers are using this week. Your queue can tell them apart.

Feature Phishing and Typosquatting Detection

We rebuilt dark web ingestion and added a dedicated scanner for potential phishing domains alongside typosquatting detection. Lookalike domains registered against your brand surface as they appear.

Enhancement New FullHunt Website

We rebuilt fullhunt.io: new home page, product and use case pages, capabilities, and navigation. The site shows a live feed of the newest vulnerability checks going into the scanner, visible without logging in.

Q4 2025

Product Vulnerability Intelligence

Launched FullHunt Vulnerability Intelligence, a product focused on real-world vulnerability data: exploit availability, active exploitation indicators, and asset-level risk context. Security teams can correlate discovered assets against live threat intelligence to see what's actually being weaponized, not just what has a high CVE score.

Feature Agentic AI with MCP

Added Model Context Protocol (MCP) support for supported AI clients to query FullHunt attack surface data through standard MCP tools. The integration supports triage, investigation, and threat-hunting workflows.

Signature Service Detection and Port Coverage

FullHunt's discovery engine identifies the service and version behind an open port from its response, then maps what it finds to the software identifiers we use for CVE matching. Default port coverage expanded from 256 to 2,823 ports.

Q3 2025

Signature Products and Technologies Detection Expansion

FullHunt expanded Products and Technologies detection from 829 to 1,866 product signatures - that's 1,037 brand new products now detectable across your digital infrastructure. From emerging SaaS platforms to specialized enterprise tools, FullHunt now catches what others miss.

Signature Massive Web Technology Expansion

FullHunt web technology detection has grown from 2,430 to 5,368 signatures - adding 2,938 new web technologies to our arsenal. Whether it's the latest JavaScript frameworks, cutting-edge CDNs, or niche development tools, FullHunt has got you covered.

Q2 2025

Product Org DB (Alpha Release)

Launched the Organizations Database (Org DB), providing comprehensive organization intelligence and attack-surface data. Search for companies by domain or organization name to discover their digital footprint, subsidiaries, attack surface, and associated domains. Map and attribute domain names to organizations and vice versa.

Feature New API Documentation

Released completely revamped API documentation at docs.fullhunt.io with improved developer experience, comprehensive guides, better examples, and enhanced navigation. Features detailed coverage of all API endpoints with interactive examples.

Enhancement New Payment System

Introduced new updates to the FullHunt payment system-automated billing and seamless credit management for an improved user experience.

Product OEM APIs

Launched FullHunt OEM APIs product, enabling partners and resellers to integrate FullHunt's security intelligence directly into their own platforms and solutions.

Q1 2025

Product OEM APIs

We're rolling out OEM APIs, letting you integrate FullHunt's discovery and vulnerability scanning into your own security platform. Offer your customers a seamless integration of FullHunt's ASM database and datasets.

Enhancement New Reporting

We introduced an upgraded reporting engine across all FullHunt modules. Automatically generate executive summaries, compliance breakdowns, and remediation timelines - everything you need for clear, actionable insights.

Signature New Signatures

Added checks for over 150 vulnerabilities to FullHunt Eagle in Q1 2025. These vulnerabilities are now being scanned with FullHunt Eagle, FullHunt's vulnerability scanner.

Q4 2024

Product New APIs - Nexus APIs

FullHunt released the Nexus APIs, which offer access to various datasets provided by FullHunt's R&D.

Enhancement Revised API DB Architecture

Our API database underwent a major revamp to boost speed, reliability, and scalability.

Feature Suggested Domains v2

A new endpoint, suggested-domains, automatically provides domain suggestions you might want to monitor, helping you catch assets you didn't even know existed.

Feature New Tool - IP Lookup

A dedicated IP lookup tool for quick retrieval of geolocation data, associated domains, and asset annotations.

Feature Enterprise On-Demand Scans API

The on-demand-scans API allows you to kick off custom scans on particular domains, subdomains, or IP ranges at any time.

Q3 2024

Product New APIs

FullHunt introduced additional APIs for Dark Web Search.

Enhancement Enhancement

Completely refactored the exposure-engine pipeline to enable additional workflows and faster processing of newly discovered assets.

Signature New Signatures

Added checks for over 300 vulnerabilities to FullHunt Eagle in Q3 2024. These are now being scanned with FullHunt Eagle, FullHunt's vulnerability scanner.

Product Data Intelligence API

FullHunt now offers a Data Intelligence API, delivering assets for discovery through everything from technology stacks to advanced filters to identify products.

Product FullHunt Owl (Beta)

FullHunt Owl is an automated discovery and vulnerability scanning product. It provides companies with automated discovery and high-signal vulnerability scanning for subsidiaries, third-party vendors, and one-time scans.

Enhancement Revised SSO / Okta Updates

Improved Single Sign-On (SSO) integration with Okta, streamlining authentication and user management for enterprises.

Q2 2024

Enhancement Enhancement

Refactored Dark Web Monitoring, enhancing potential phishing and typosquatting detection capabilities.

Product New Product - FullHunt Global Search

Scan the external attack surface of an entire nation and identify vulnerable websites, servers, databases, and VPNs using a blazing-fast API capability. Available to government agencies and customers.

Product New Product - FullHunt Data Intelligence

Leverage advanced search capabilities to explore the FullHunt database, identifying services that match specific patterns and uncovering new attack surfaces unknown to your organization. Additionally, utilize our APIs for extensive investigations at scale.

Signature New Signatures

Added checks for over 200 vulnerabilities to FullHunt Eagle in Q2 2024. These vulnerabilities are now being scanned with FullHunt Eagle, FullHunt's vulnerability scanner.

Q1 2024

Product New Product

Dark Web monitoring beta rollout.

Feature New Feature

Suggested Domains: Discover suggested domains around the clock.

Signature New Signatures

Added checks for over 150 vulnerabilities to FullHunt Eagle in Q1 2024. These vulnerabilities are now being scanned with FullHunt Eagle, FullHunt's vulnerability scanner.

Looking for Enterprise capabilities? Try our FullHunt Enterprise Platform

Request a demo