scanrub
Automated security scanner

It finds bugs while you sleep.

Point the scanner at any domain. It maps the attack surface, runs 25 security tools, and reports what it finds, with proof and fix suggestions. See how it works →

scanrub recon target.io
$ scanrub recon target.io
target.io
├── api.target.io 200
├── admin.target.io 200 no auth
├── staging.target.io 403
├── dev.target.io 200 debug mode
└── docs.target.io 200
2 CRITICAL - Firebase public, SQLi in /search
3 HIGH - GraphQL introspection, exposed maps, default creds
2 MEDIUM - Missing CSP, CORS misconfigured
who it's for

Built for two kinds of security work.

For security researchers & bug bounty hunters

Find real leads faster, then verify and write them up yourself - most programs reject raw scanner output.

Better-verified findings, fewer false positives
Pre-drafted HackerOne / Bugcrowd write-ups to verify, not submit as-is
Track bounty programs and scan history over time
See researcher pricing
For engineering & security teams

Continuously scan the app you ship - not someone else's target.

Catch new vulnerabilities on every pull request, before they ship
Get alerted before an outside researcher - or attacker - finds it
Integrate into CI/CD with an API key
Read the API & CI/CD docs
live findings feed

Real vulnerabilities. Found automatically.

This is what the agent finds in a typical scan. See all features →

scanning target.io - 1 findings
14:23:07critical
Firebase database publicly readableapp.target.io
scan methodology

Every finding gets validated before it's reported.

The scanner explains each step, what it checked, why, and what it found. Learn about the platform →

Mapping attack surface
Running subfinder + assetfinder on target.io
23 subdomains discovered
subfinderassetfinder
2
Probing live hosts
Admin panels often exist on hidden subdomains
3
Checking authentication
admin.target.io has no auth - testing defaults
4
Scanning for known CVEs
Running nuclei templates against live hosts
5
Validating findings
Confirming exploitability with proof-of-concept
how a scan works

From domain to report in minutes.

01
Maps attack surface
1,243 assets discovered
subfinder · assetfinder · httpx
02
Selects tools
12 tools chosen for this target
nuclei · katana · dalfox · nmap
03
Validates findings
17 findings, 3 critical
proof-of-concept generation
04
Explains fixes
Ready for engineering
severity · impact · remediation
25
security tools orchestrated
182
research playbooks published
21
vulnerability classes documented
8,598
HackerOne disclosures analyzed
Powered by open-source security tools

25 security tools, orchestrated

The best open-source tools, integrated into one adaptive pipeline.

nucleisubfinderhttpxkatanaffufdalfoxsqlmapniktonmapwafw00fwhatwebassetfinderwaybackurlsgaucmseekgitleakstrufflehogplaywrightamassnaabualterxarjuns3scannercloud_enumhashcat
Privacy-first

Your scan data is isolated per tenant. Never sold, never shared.

Ethical only

Explicit authorization required. Guardrails built into the platform.

Fast results

Full attack-surface map in a few minutes.

Open research

182 playbooks derived from real disclosed reports, freely browsable.

Frequently asked

Common questions

ScanRub is an automated security scanner that maps your attack surface, runs 25 specialized security tools, filters false positives with AI, and produces an evidence-rich vulnerability report. Point it at any domain you own and it handles the rest.

Run your first scan.

No signup. No credit card. Just a domain.

Weekly security research

New vulnerability playbooks, tool updates, and bug bounty insights - delivered to your inbox. No spam.

Unsubscribe anytime. We respect your inbox.
Press ⌘K to search×