Each one below is a request that already lands on somebody's desk, answered today with six browser tabs and a spreadsheet. The change is not the collection. It is what you are holding at the end.
Six investigations, with the before and the after.
Case 1Third-party risk, procurement
Vendor due diligence before signature
Before
Three hours across six tabs, ending in a spreadsheet row that reads "checked, no issues, March". Nobody can say what was checked or on which day.
After
A scoped case and a sourced dossier filed against the vendor. Registration age, mail spoofability, infrastructure control, each with its record and UTC retrieval time. An artifact the auditor accepts.
A subdomain list of unknown age. Next quarter nobody can tell what changed, so the review starts again from nothing.
After
Dated findings with the record attached, so the following quarter subtracts cleanly. What changed is the finding, and that is the slide leadership wanted.
Guesswork about what you are buying, assembled from the target's own marketing and a call with their CTO.
After
Registration age, hosting concentration, mail posture and certificate surface, cited and dated. Passive, so it runs before the deal is announced and leaves nothing in their logs.
A deck built from the competitor's marketing material, which describes what they want said about them.
After
Their public stack read from their own records: vendor verification strings, mail provider, DNS delegation, new hostnames in transparency logs. Observation separated from inference.
A phishing report forwarded to legal with a screenshot attached and no registration evidence.
After
Typosquat registrations enumerated with dates, registrar of record and mail configuration attached, which is what a registrar complaint or a UDRP filing actually needs.
What changes between the use cases is the scope you declare and what you do with the artifact.
The collection itself is the same: passive, public sources, every finding carrying the raw record,
the source endpoint and the UTC moment of retrieval.
Domains only. This tool has no input that accepts a person, which is a structural limit rather
than a promise. Read the boundary we publish.
Domain footprint sweep
passive collection only
stamped on the report
Samples:
Every finding will carry four things
1Severity.What the record means for the decision in front of you.
2The raw record.Exactly as the source returned it, unedited.
3The source endpoint.The request that produced it, so it can be re-run.
4The UTC retrieval time.Records change. Without this it is an assertion.
Reads dns.google and rdap.org from your
browser. Nothing is sent to the domain you enter.
Tick the authorization box, then run the sweep.Enter the domain you are authorized to assess, then run the sweep.Run the sweep. The report lands here.
[]
Scope:
findings need attention
source: retrieved:
Analyst summary
PDF and DOCX export opens a signup. No card required.