See what you expose — before someone else finds it.

h0SINT maps everything your organisation has reachable from the internet, works out which parts actually matter, and writes it up as a report you can defend. Self-hosted — your asset inventory never leaves your network.

Passive only · nothing touched on your systems No login, no agents to install
h0sint@mission-control: ~/portfolio LIVE
$ h0sint scan --target acme.com --deep
├─ resolving attack surface ............ 142 hosts
├─ owned vs. mention .................... confidence-scored
├─ exploit cross-check .................. 3 exploitable
└─ recording evidence ................... done
$ h0sint report --audience board
▸ synthesizing → triaging → verifying...
▸ quality gate ............ 94/100 PASS
$ _
// the problem

The gap between what you think is exposed and what an attacker can actually reach is where breaches start.

From a domain to a report you can defend.

One pipeline. Every step leaves evidence behind, so any claim in the output traces back to the thing that produced it.

[01]
analyze

Maps the estate and synthesizes scan, exploit and infrastructure data into a draft.

[02]
triage

Confirm what is real, teach it the false positives. It remembers both.

[03]
verify

Adversarial fact-checking removes what the evidence does not support.

[04]
qa

A grader marks the report against its own evidence and sends it back until it holds.

[05]
export

PDF, HTML, or straight into Google Docs and Slides.

Overnight it re-checks every domain you track and connects them to each other — shared hosting, reused certificates and repeat problems surface without anyone asking. Anything it infers is checked before it is trusted.

What you actually get.

Three screens do most of the work. The rest is documented screen by screen.

h0sint://target/overview
Per-target overview with DNS, IP, ports, URLs, vulnerabilities and tech stat cards, an Analyze to Export workflow rail and a vulnerability-severity chart
// the footprint

Everything you expose, in one view

DNS, IPs, ports, URLs, vulnerabilities and the technology behind them — beside a severity breakdown and the workflow rail that carries it to a finished report.

h0sint://target/findings
Security findings table, severity-tiered with CVE badges and a severity filter
// triage

Ranked by what is actually exploitable

Findings are scored on whether an exploit exists and is being used in the wild — not on a raw severity number alone. Mark a false positive once and it stays marked.

h0sint://correlations
Cross-target correlations view with shared-infrastructure KPIs and shared-IP cards linking targets
// blast radius

What one weak host costs you elsewhere

Shared IPs, ASNs, certificates and technologies surface the links between the domains you own — the exposure a single-domain scan can never show you.

// dogfood

We run it on ourselves, in public.

14 scans of h0sint.com over 21 days, through the same passive pipeline the free scan runs. Every number here came out of the tool, and the findings it raised against us were fixed and re-verified externally.

14
scans over 21 days
41
assets tracked, up from 9
102
changes detected
€0
cost to scan your domain
0204107-10 19:23 — 9 assets07-10 21:12 — 19 assets07-10 22:16 — 19 assets07-11 10:46 — 19 assets07-11 11:22 — 20 assets07-11 11:33 — 0 assets07-11 11:47 — 24 assets07-11 12:06 — 23 assets07-12 07:56 — 24 assets07-12 10:08 — 21 assets07-12 11:43 — 23 assets07-28 23:26 — 35 assets07-29 11:05 — 40 assets07-30 10:40 — 41 assets941partial scan07-10 19:2307-11 12:0607-30 10:40

Assets tracked per scan. The dips are not the estate shrinking — they are scans that covered less. We show them unsmoothed, because “absent from a scan” and “gone from the internet” are different claims, and conflating them is how a scanner ends up lying to you.

// see it yourself

What does your domain expose right now?

Real passive reconnaissance, run live from public sources. Nothing is touched on your systems and nothing is stored — the result is computed for this page and forgotten when you close it.

// working together

Three ways to work with me.

Every engagement starts with a conversation. I scope it against your actual estate, and I tell you straight if it is not worth doing.

01

The report

A full scan of your external estate, then the part that matters: I triage every finding by hand, remove what is noise, and write it up so it survives review. You get the deliverable, not raw tool output.

from €2,500 per engagement
02

Do it together

We run it side by side. Calls where we scan your estate live, I explain what each finding means and how it was reached, and we review the results together — so your team leaves understanding their exposure and the tradecraft, not just holding a PDF.

from €900 per session
03

Run it yourself

The platform, self-hosted on your infrastructure, with an annual licence. Your data never leaves your network. Guided installation and a walkthrough for whoever will own it; you run it on your own terms.

from €8,000 per year

Indicative starting points. Final scope and price depend on the size of your estate — we agree both before anything runs.

// start here

Tell me what you need.

Which domains you care about, what you are trying to find out, and any deadline. I read every message and reply to every serious one.

Goes to Hostin Technologies (EU) — contact@h0sint.com. Used only to reply to you, never sold or shared. Ask any time and we delete it. Privacy notice.

Passive reconnaissance only · EU-hosted · nothing active runs without your written authorization.