Attack Surface Monitoring

If it's on your network, it's on your radar.

Eyes in the Network discovers every new subdomain the moment it appears, enriches it with DNS, HTTP, and port data, scans it for vulnerabilities, and alerts your team before attackers find it first.

Request a Demo
eyes — attack surface watch
▸ eyes watch --target example.com ✓ Baseline: 47 known subdomains ✓ 8 discovery sources active — DNS, certs, scraping... ✗ NEW: dev-staging.example.com (detected 23 min ago) ✗ NEW: old-portal.example.com (port 8080 exposed) ⚠ WARN: admin.example.com — no auth wall detected ✓ Alert dispatched — 3 new assets flagged 569 automated tests · 11 recon tools orchestrated

A 7-stage pipeline that never stops watching.

1. Discovery: 8 sources running in parallel
2. Deduplication: checked against history
3. DNS Resolution: A / AAAA / CNAME stored
4. HTTP Probing: status, title, tech stack
5. Screenshots: visual proof for every live host
6. Vuln scan (Nuclei) + Takeover check (subzy) + Port scan, running in parallel
7. Alerting: new assets and CRITICAL/HIGH findings pushed instantly

Built to not fail at 3 AM.

8-Source Parallel Discovery

subfinder, amass, assetfinder, findomain, crt.sh, Chaos, VirusTotal, and SecurityTrails, all running concurrently.

Source Attribution

Every finding logs which source discovered it first, so you know what's actually new.

Takeover Detection with Human Review

Every resolved subdomain runs through subzy. Candidates stay pending until an admin confirms or dismisses them from the dashboard — only then does it alert and count as real risk, so no noisy false positives.

URL Discovery

Each new live host is crawled with katana (scoped to the root domain), and the URLs found are stored in the database — ready to feed the next iteration of targeted fuzzing or scanning.

Visual Proof

Automated screenshots of every live host, captured as soon as it's discovered.

Dashboard, CLI & REST API

Web dashboard with per-subdomain detail and severity-colored findings, a full CRUD REST API, and a scriptable CLI with JSON/CSV export. Trends page charts subdomains, findings, and takeovers over 7/30/90 days.

Multi-User with Roles

Optional signed-cookie login — admin (full control) or auditor (read-only), with login rate limiting and a CSRF token on every write action.

Fail-Soft Architecture

A missing tool or an expired API key produces a warning, not a crash. The pipeline keeps running, and the last scan is always recorded.

Docker Install

One multi-stage image ships all 11 recon tools (Chromium for gowitness included), pre-compiled. docker compose up -d --build brings up the daemon and dashboard — nothing else to install by hand.

Multi-Channel Alerting

Telegram, Slack, and Discord notifications, filtered by severity. Every dispatch is audited in the alerts table.

11
Recon Tools Orchestrated
7
Stage Pipeline
569
Automated Tests
3
Alert Channels

Stop searching. Start watching.

Request a Demo