Attack Surface Intelligence

See Everything.
Miss Nothing.

Sharingan is a continuous attack surface monitoring platform built for security professionals. Enumerate subdomains, track DNS mutations, fingerprint HTTP services, and surface critical signals — automatically.

5+
Discovery engines
Real-time
CT log monitoring
5 tiers
Flexible plans
Passive DNS enumeration Certificate Transparency logs Active DNS resolution HTTP service fingerprinting DNS brute-force with wordlists Real-time CT log streaming HackerOne scope CSV import Signal alerting & Telegram bot Multi-company workspace Passive DNS enumeration Certificate Transparency logs Active DNS resolution HTTP service fingerprinting DNS brute-force with wordlists Real-time CT log streaming HackerOne scope CSV import Signal alerting & Telegram bot Multi-company workspace

Capabilities

Everything in your attack surface,
nothing left in the dark.

Sharingan chains passive enumeration, active probing, and continuous monitoring into a single platform — so you always know what's exposed.

Passive Discovery
Harvest subdomains from certificate transparency logs, subfinder, crt.sh, and more — without touching the target network.
DNS Resolution & Brute-force
Resolve every discovered hostname with dnsx and run wordlist-driven brute-force with multi-million entry lists stored in optimised volumes.
HTTP Fingerprinting
Run httpx across live subdomains to capture status codes, titles, tech stacks, and etc. — continuously updated.
Signal Intelligence
Every DNS change, new subdomain, and HTTP state transition emits a severity-graded signal. Triage from a unified feed or get Telegram alerts.
Real-time CT Streaming
Subscribe to live certificate issuance feeds. New subdomains matching your scope are ingested seconds after the certificate is signed.
HackerOne Import
Drop in a HackerOne program scope CSV and Sharingan automatically parses wildcard and explicit scope entries into your asset inventory.

Workflow

From zero to full visibility in three steps.

01
Define your scope
Add companies and seed domains manually, via bulk upload, or by importing directly from a HackerOne program scope CSV. Sharingan instantly scaffolds your asset tree.
manual add bulk upload hackerone scope CSV
02
Enumerate & probe
Workers fire across dedicated VPS nodes — passive engines find subdomains, dnsx resolves them, httpx fingerprints every live service, and CT streams watch for new certs in real time.
subfinder dnsx httpx ct-stream dns brute
03
Monitor & act on signals
Every state change — new subdomain, DNS mutation, HTTP status flip — produces a severity-graded signal. Review in the dashboard or receive instant Telegram notifications.
signal feed telegram bot severity grading

See it in action

A single scan, start to finish.

Here's what a real recon run looks like — from passive discovery to a graded signal, in seconds.

sharingan — discovery
$ sharingan scan --target acme-corp.com --engines ct,subfinder,dns_brute
[*] Querying certificate transparency logs...
[*] Running subfinder passive enumeration...
[*] DNS brute-force: 10,000,000 words loaded ...
 
[+] api.acme-corp.com:80 → HTTP 200 · Index of /
[+] staging.acme-corp.com:80 → HTTP 302 · redirect to /login
[+] admin.acme-corp.com:443 → HTTPS 403 · Admin Panel
[+] admin.acme-corp.com:8443 → HTTPS 200 · Welcome Admin
[+] vpn.acme-corp.com:8080 → HTTPS 500 · Internal Server Error
 
[!] SIGNAL · HIGH  → New subdomain: dev-internal.acme-corp.com (CT log) is alive.
[!] SIGNAL · MED  → DNS change: mail.acme-corp.com A-record updated from 1.2.3.4 to 5.6.7.8
 
[*] Scan complete · 2534 subdomains · 260 resolved · 603 HTTP services · 2 signals
$

New · Agent Integration

Awaken your agents
with Sharingan.

Connect Claude Code, Claude Desktop, or any MCP-compatible agent straight to your attack surface. Companies, domains, subdomains, live HTTP services, and signals — queryable in real time, from inside the tools you already work in.

Included on Two Tomoe and above.

Sharingan-powered AI agent

Pricing

Five eyes. One for every mission.

Plans scale with your program size — from solo hunters to full security teams running continuous recon on enterprise-wide scope.

HTTP Scan Freshness
Select how often HTTP services are re-fingerprinted across your subdomains.
Light frequency
Heavy frequency
Paid Trial
One Tomoe
一 · Sharingan
$5 / 10 days
credited in full toward your first upgrade
1 worker node · 6h freshness
  • Companies 1
  • Domains 1
  • Subdomains 3,000
  • HTTP Services1,000
  • HTTP Freshness6 hours

$5 credited toward your first plan

Start trial →
✓ Selected
Two Tomoe
二 · Sharingan
$30 /mo
2 worker nodes
  • Companies 2
  • Domains 5
  • Subdomains 5,000
  • HTTP Services10,000
✓ Selected
Mangekyō
万華鏡 · Sharingan
$170 /mo
12 worker nodes
  • Companies 15
  • Domains 40
  • Subdomains 40,000
  • HTTP Services80,000
Eternal Mangekyō
永遠の · Sharingan
Custom
  • Companies
  • Domains
  • Subdomains
  • HTTP Services
Contact us

← swipe to compare plans →

Your attack surface doesn't sleep.
Neither does Sharingan.

Boost your Recon.