Exposed Admin Page Check
exposure_mapMap an organisation's internet-facing attack surface: discover subdomains and classify exposed admin, dev, VPN, staging and login pages, then get counts, a risk verdict, and next actions.
Instructions
Map what an organisation exposes to the internet beyond its home page: subdomains from Certificate Transparency logs (plus hosts DechoNet has already observed), each opened once from outside and sorted into developer/ops tools, directory listings, admin screens, VPN/remote-access logins, staging servers, default install pages, login pages and so on — the forgotten assets AI-driven attack tools look for first. Use this when a user wants to know their attack surface or after a breach in their sector. Returns counts per category, a verdict (bad/warn/ok) and what to do. Public view only: the per-host list and a sensitive-file check are shown to the verified domain owner on the web report (DNS TXT), never through this tool. Read-only and passive beyond a single first-page request per host; no logins or path guessing; requires no API key; rate-limited (heavier than other tools — up to ~1 minute).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| domain | Yes | The organisation's domain (e.g., 'example.co.kr'). Scheme, path and a leading www. are stripped. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| found | Yes | ||
| counts | Yes | hosts per category (devtool, listing, admin, remote, staging, default_page, login, api, mail, web, …) | |
| issues | Yes | ||
| probed | Yes | ||
| status | Yes | bad | warn | ok | info | |
| reportUrl | Yes |