Toolkit access

Enter the access password to continue.

SMTP / Secret Toolkit

checking…

Dashboard

Host tool availability and activity counters.

SMTP credential check

One credential per line. Formats: host|port|user|pass|label, host:port user:pass, host:port|user|pass.

API key validator

Paste any text, .env, or config dump. Keys are auto-detected by shape and validated with read-only calls across AWS, SendGrid, OpenAI, GitHub, Stripe and more.

Secret hunt

Upload a file or paste content. Runs trufflehog with verified-only detection — no noise, live secrets only.

Target builder

Turn a domain list into scanner-ready targets. Accepts domains, wildcards, URLs, IPs, CIDRs, and ranges.

Web probe

Chains the target builder into an HTTP probe: builds URLs, then fingerprints live hosts with status, title, tech and server. Capped at 500 targets per run.

Vulnerability scan

Chains the target builder into nuclei — template-based CVE, exposure, misconfiguration and default-login detection. Live targets, capped at 500 per run.

nuclei sends intrusive/active requests. Only scan systems you are authorised to test.

Mass target generator

Generate millions of domains / IPs from a seed, fully self-contained (built-in wordlists, no downloads). Output is written to a file and streamed to your browser on download — nothing is loaded into RAM.

Tip: pick num with range 1-1000000, or perm for prefix×suffix permutations. Dedup keeps output unique.

Mass DNS resolver

Resolve a large target list to live hosts (pure Python, no dnspython/massdns). Use a previous Mass Gen job id to chain millions of hosts straight through.

Jobs

All runs are persisted. Open a job to view results, download CSV/JSON, or replay the input.