USE CASES · HOSTED SCANNERS & SECURITY TOOLS

Know the Network
See your Attack Surface

Thirty hosted scanners and security tools to discover, assess and monitor your perimeter so you know your network as it changes.

Network reconnaissance interface
30 Scanners & Tools
65,535 TCP Ports
Trusted since 2007
184,000 Scans This Month
Continuous security checks

Practical use cases for internet-facing systems

Discover the complete external attack surface. Identify open services, connected infrastructure, web technologies and known vulnerabilities. Run targeted checks, or schedule regular scans to monitor changes.

01 Port Scanning

Nmap Port Scanner

Scan a hostname, IP address, or network.

Find open ports and use service and version detection to identify what is answering. Run a one-off scan or repeat it on a schedule to monitor changes.

Monitoring
Schedule the same scan against a hostname, IP address or network range and identify ports or services that appear or disappear.
Deployment Checks
Troubleshoot an unresponsive service, or check on the port that was just opened on your Internet facing system.
Human Error
Humans and Agents both make mistakes. Find databases and administrative interfaces that were unintentionally exposed.
10 PORTS FREE · All 65,535 TCP Ports WITH MEMBERSHIP
Nmap results showing an open-port summary, heat map and detailed service detection output
OpenVAS results showing CVSS severity gauges and details of a critical Apache HTTP Server vulnerability
02 Vulnerability Scanning

OpenVAS Vulnerability Scanner

Check listening services for known vulnerabilities and weak configurations.

Knowing a port is open is half the answer. OpenVAS tests internet-facing services and web applications, then returns the severity, affected hosts and technical references for each finding.

Coverage
Run tens of thousands of vulnerability checks and review the evidence behind each finding.
Scheduling
Schedule scans weekly or monthly and receive the results after every scan or only when the vulnerability count changes.
Evidence
Review severity, affected hosts and technical references, then export the results for remediation or reporting.
Membership Required · On-demand, weekly or monthly scans
03 Fast Sweep

ZMap Fast Port Scanner

One port. Test a Full /16 in Seconds.

Find the addresses answering on RDP, SSH or another TCP port across your public IP space. ZMap identifies open ports fast, Nmap can then identify what is listening.

Large Ranges
Check large public IP ranges for open TCP ports (up to a Class B or /16).
Port Selection
Scan 12 common services, the top 100 TCP ports or a custom selection of up to 100 ports.
Attribution
High-volume scanning can trigger rate limits and intrusion detection. Scans run from our dedicated ranges, not your office or cloud account.
Business or Enterprise MEMBERSHIP REQUIRED
Layered ZMap scan form and open-port results showing IP addresses discovered across a large address range
04 CMS Security Reporting

WordPress & CMS Security Reporting

You patched the server. The plugin nobody owns is the way in.

Check the WordPress version, exposed plugins and themes, hosting IP and related threat intelligence. Use active scanning to look further for components, users and sensitive files.

Plugin CVEs
Match detected plugin and theme versions against known vulnerabilities, with links to the CVE and fixed release.
Hosting Context
Check the hosting IP against blocklists and threat intelligence. On shared hosting, a result may belong to another site on the same address.
Scan Modes
Start with passive checks, survey multiple sites or use active enumeration for plugins, themes, users and sensitive files.
Passive and Survey Scans Free · ACTIVE Enumeration WITH MEMBERSHIP
WordPress Scan results showing an issue gauge and details of a critical plugin vulnerability
05 Surface Mapping

Domain Profiler

Map the attack surface with zero impact passive recon.

Start with a domain and trace the infrastructure around it: subdomains, DNS records, mail servers, related networks and internet-facing services.

Discovery
Build a map to identify endpoints associated with an organisation using DNS datasets and internet-wide scan data.
Shadow IT
Find forgotten or undocumented systems that remain visible from the internet.
Recon
Review infrastructure associated with any domain for reconnaissance, bug bounty research, red-team assessments and penetration testing.
MEMBERSHIP REQUIRED · Passive OSINT · DNS · INTERNET-WIDE SCAN DATA
Domain Profiler attack surface map showing DNS, mail and host relationships
ASN and IP lookup results grouped by network owner, CIDR block and country
06 ASN Mapping

ASN & IP Address Mapping

Put an owner and network range behind each public IP address.

Paste the addresses from a firewall log, a threat feed or a scan and get back the owning ASN, the CIDR block it sits in, the country of registration and any intel tags sorted, counted and exportable.

Log Triage
Turn a list of hits into named networks. Hosting, cloud, residential or a range you already know is trouble.
Concentration
Top ASNs and CIDR blocks by count show whether activity is concentrated within particular providers or network ranges.
Straight to a Scan
Select the rows that matter and send those ranges into Nmap without retyping them.
free · ASN + CIDR + COUNTRY · XLSX Export
Website analysis results showing detected technologies, scan history and TLS certificate details
07 Technology Fingerprinting

WhatWeb & Wappalyzer Scan

See what a website reveals in a single request.

Paste a list of URLs and identify the server, CMS, JavaScript frameworks, analytics and hosting behind each one. The data is gathered from HTTP headers and page source without sending intrusive requests to the target.

Technology Stack
See the CMS, framework and JS libraries a site is built on.
Outdated Components
Use detected versions as a starting point for checking known vulnerabilities and outdated components.
Low Noise
Scan up to 20 sites for free, or up to 1,000 with a membership. The scan uses regular web requests without path guessing or large numbers of intrusive requests.
FREE · 1,000 TARGETS WITH MEMBERSHIP · PASSIVE analysis

How it works

From sign-up to results, in minutes

1

Sign up

Choose a plan

2

Launch a scan

Paste a target, pick a tool, go

3

Get results

Clear, fast, actionable output

Frequently Asked Questions

Common questions about running scans, results and access.

Only systems you own or have written permission to test.
Formats vary by tool and may include on-screen results, raw output, downloadable reports, dashboard views or email delivery. The API returns plain text by default, with JSON on selected endpoints.
Yes. Free API access is limited to 50 calls per day; membership raises the daily API quota according to the selected plan. All endpoints follow https://api.hackertarget.com/{tool}/?q={target}. See the API documentation for authentication, rate limits and response formats.
Vulnerability Scan results are stored securely for up to 12 months and may be accessed by internal staff when troubleshooting the service. We do not sell, share or publish target data.

These seven scratch the surface. There are thirty.

Free
18 tools, SSL/TLS checks, and Nmap port scanning and CMS checks.
Membership
Active scanners and higher quotas, with scheduling and ZMap available on selected plans.
Do more with a membership
Hunt
Hunt vulnerabilities across your internet-facing assets.
Protect
Improve visibility of the endpoints you already own.
Discover
Find internet-facing assets for any target organisation.
Research
Network research for DFIR, threat hunting and operations.
Test in bulk
Paste lists of targets into supported tools for bulk analysis.
Always on
Scanning infrastructure ready whenever you are.
Simple launch
One form launches the test. Scan results are available by email or from the Dashboard, depending on the tool.
Raw output
Reports carry tactical output you can paste into your own reporting.