huntback / surface

Know your exposure before attackers do

huntback maps what the internet can see of you: weak domain configuration, lookalike and typosquat domains impersonating your brand, and certificates tied to hostile infrastructure, all cross-referenced with attacks on our deception network.

Scan my domainSee CVE intelNo credit card required.
Coverage

Your outside-in view

The exposure attackers enumerate, surfaced for you first.

🔎

Domain scan

Headers, TLS, cookies and best-practice checks on your web domains.

🛡

Brand protection

Lookalike and typosquat domains impersonating you, before they are used.

🔡

Permutation engine

Digit-for-letter and multi-TLD permutations that catch the tricks attackers use.

📜

Certificate intel

Certificate-transparency sweeps that reveal hostile and bulletproof-hosted infrastructure.

🏴

BPH attribution

Per-certificate bulletproof-hosting provider attribution.

🔗

Cross-referenced

Every finding checked against live attacks on our sensor network.

FAQ

Attack surface, answered

Do you see internal-only mechanics?

No. You see only outcomes for your own verified domains. Internal sweep mechanics stay operator-only.

How are typosquats found?

A permutation engine generates lookalikes (character swaps, digit-for-letter, extra TLDs) and checks which are registered and how they resolve.

See yourself the way attackers do

Scan your domain and find the exposure before it is used against you.