Authorized reconnaissance
Map an authorized target before you start testing
Find related hosts and history without losing track of scope.
The question
What belongs to the target, and what is worth validating?
FullHunt provides publicly observable data for reconnaissance. It does not establish ownership or permission, so confirm written authorization before you scan, test, or interact with an asset.
How it works
01
Lock the scope
Write down the permitted domains, IP ranges, exclusions, timing, and test methods.
02
Map the assets
Find observed subdomains, hosts, services, technologies, certificates, and DNS records.
03
Check the history and CVEs
Compare passive DNS, earlier observations, mapped vulnerabilities, and exploit records.
04
Validate manually
Use the records to plan testing that stays inside the written authorization.
The records behind the answer
Related assets
Domains, subdomains, hosts, and IP relationships that may belong to the authorized target.
Service fingerprints
Public ports, technologies, and TLS certificates to check before testing.
Infrastructure history
Passive DNS and earlier observations of the authorized footprint.
Vulnerability research
CVE, EPSS, CISA KEV, and public exploit records for the observed technology.
Keep the records that shape the test plan in one place.
FullHunt supports reconnaissance and research. Only the asset owner can authorize testing.
What you get
- An observed asset map for the authorized scope
- Host, service, certificate, and DNS records
- Vulnerability and exploit data for manual review
- Console, API, and MCP access for scripted work
Try it on a target you are allowed to assess.
Read the API documentation and keep every query inside the authorized scope.