attack-surface-mcp-server
Provides DNS resolution services as part of passive reconnaissance, querying multiple public resolvers including 1.1.1.1 to enumerate DNS records.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@attack-surface-mcp-serverMap the external attack surface of example.com"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Authorized, defensive use only. Point this server only at assets you own or are explicitly authorized to assess. It performs passive, non-intrusive reconnaissance — it reads public records (Certificate Transparency logs, DNS, RDAP/WHOIS) and each target's own published surface (one TLS handshake and one HTTP GET per host). It does not port-scan, exploit, brute-force, fuzz, or probe for vulnerabilities; that capability is excluded from the surface by design, not gated behind a flag. Output is descriptive — what exists and what the security posture is — never an exploitation plan. Every outbound connection passes an SSRF guard that refuses private, loopback, link-local, and cloud-metadata targets.
Overview
Passive external attack-surface mapping (EASM) over Certificate Transparency logs, DNS, TLS, HTTP, and RDAP/WHOIS registries, with optional Shodan host intelligence. Discover subdomains, resolve DNS records, and inspect TLS and HTTP security posture across a domain's live hosts. Runs as a stdio process or a local Streamable HTTP server.
Tools
Tool | Description |
| Flagship workflow. Maps a domain's external surface end to end: CT-log subdomain discovery → DNS liveness → (standard+) DNS records, TLS posture, HTTP headers/tech → optional RDAP/WHOIS → (thorough + key) per-IP Shodan enrichment. Returns a structured surface map and a defensive assessment of observable facts. |
| Passive subdomain discovery from Certificate Transparency logs (crt.sh → Certspotter → TLS-SAN fallback chain), with DNS resolution to mark which names are live. Per-source provenance; no DNS brute-forcing. |
| Resolve and enumerate DNS records (A/AAAA/CNAME/MX/NS/TXT/CAA) for one or more hosts across multiple public resolvers, with optional reverse DNS (PTR). Per-resolver values surface propagation gaps. |
| Inspect TLS/SSL posture via a real read-only handshake: protocol, cipher, leaf certificate and chain depth, SANs, validity window, days-to-expiry, issuer, validation status. Reports invalid/expired/self-signed certs instead of failing. |
| Passive HTTP(S) probe: one GET following redirects. Returns status, redirect chain, headers, a security-header audit (HSTS/CSP/X-Frame-Options/cookie flags/CORS reflection), and an evidence-bound technology fingerprint. |
| Registration and ownership lookup via RDAP (JSON; WHOIS fallback). A domain returns registrar, status, lifecycle events, nameservers, DNSSEC; an IP/CIDR returns netblock, allocation CIDRs, origin ASN, country. |
| Infrastructure intelligence for a single IP (open ports, banners, software versions, ASN, geo) or a faceted internet-wide search, via Shodan. Requires |
| Offline synthesis over findings gathered so far. Returns a prioritized defensive review plan plus pre-filled follow-up calls (which certs to renew, which hosts to inspect, which software versions to check for CVEs against an external NVD/OSV server). No external calls. |
Resources
Resource | Description |
| Read-once snapshot of a domain's mapped external surface (subdomains, live hosts, per-host TLS/HTTP posture summary), equivalent to a standard-depth |
All resource data is also reachable via tools — tool-only clients lose nothing, since attacksurface_map_domain covers the same ground.
Related MCP server: External Reconnaissance MCP Server
Capability reference
attacksurface_map_domain tool
depth:quickdiscovers subdomains and liveness;standardadds DNS records, TLS, and HTTP posture;thoroughadds per-IP Shodan data when a key is present, otherwise a note.Returns a structured surface map and defensive
assessmentof observable facts. Failed sources or unreachable hosts become notes; subdomain resolution is capped byATTACKSURFACE_MAX_SUBDOMAINS(default 200), with truncation disclosed.includeRegistrationadds RDAP/WHOIS data for the apex at standard or thorough depth.
attacksurface_enumerate_subdomains tool
Discovers names through crt.sh → Certspotter → the apex TLS certificate SANs, then resolves DNS liveness.
includeUnresolved: falsekeeps only live hosts.Returns each name's source provenance and per-source status; no DNS brute-forcing or target-resolver probing.
attacksurface_resolve_dns tool
Accepts up to 50 hosts and queries A, AAAA, CNAME, MX, NS, TXT, and CAA across public resolvers (default
8.8.8.8,1.1.1.1,9.9.9.9); reverse DNS (PTR) is optional.Returns per-resolver answers to expose propagation gaps. Private or loopback resolver IPs produce
blocked_resolver; an individual host failure becomes a per-host error.Canonical records come from the first configured resolver. Resolver failures (including SERVFAIL) remain in
queryErrorandhostErroralongside any successful records; absent records are error-free.
attacksurface_inspect_tls tool
Accepts up to 50 hosts; port defaults to 443 and handshake timeout to 8000ms (1000–30000ms).
Returns negotiated protocol, cipher, leaf certificate and chain depth, SANs, issuer, validity window, days to expiry, and validation status. Invalid, expired, and self-signed certificates are reported; one host failure becomes a per-host error.
Unparseable validity bounds retain their raw values and add findings.
daysUntilExpiryis null only when expiry cannot be parsed; a malformed start date does not erase a known expiry.
attacksurface_probe_http tool
Accepts one HTTP(S) URL; timeout defaults to 10000ms (1000–30000ms). Follows up to ten redirects with an SSRF check at every hop; a refused target produces
blocked_target. Another redirect at the limit returnsfinalStatus: 0and atransportError.Returns status, redirect chain, headers, security-header findings (HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, cookie flags, CORS reflection), and technology detections with their triggering evidence.
Cloudflare server banners identify a CDN; AWS ELB banners identify edge infrastructure (
other). Neither banner alone establishes WAF protection.
attacksurface_lookup_registration tool
Accepts a domain, IP, or CIDR;
type(auto/domain/ip) controls interpretation. Uses RDAP first, then WHOIS port 43 when needed.Domain results include registrar, EPP statuses, lifecycle events, nameservers, and DNSSEC; IP/CIDR results include netblock, allocation CIDRs, ASN, and country. Sparse or redacted fields stay unknown.
attacksurface_lookup_host tool
mode: "host"(default) looks up one IP;mode: "search"accepts an internet-wide query with optionalfacetsand may consume Shodan query credits. RequiresSHODAN_API_KEY.Both modes reject blank targets. Host mode accepts bare IPv4/IPv6 addresses and returns
invalid_targetfor other syntax before contacting Shodan; search queries are preserved verbatim.Returns ports, banners, software versions, hostnames, ASN, and geography from Shodan's last scan. Missing credentials produce
source_unavailable; no host data producesno_data. The server performs no port scans.
attacksurface_recon_guidance tool
Takes prior findings (hosts, certificates, missing headers, software versions, ports);
topic(triage/posture/coverage) selects the plan's emphasis.Returns markdown guidance, structured priority items, and pre-filled follow-up calls, including external NVD/OSV lookups. Runs offline and produces a defensive remediation or visibility plan.
attacksurface://surface/{domain} resource
Takes a domain and returns an
application/jsonsnapshot equivalent to a standard-depthattacksurface_map_domaincall.Includes subdomain and live-host counts plus per-host TLS/HTTP posture. Caps host detail at 50 live hosts, discloses omissions, and points to
attacksurface_map_domainfor the full set.
Features
Built on @cyanheads/mcp-ts-core: stdio and Streamable HTTP transports, pluggable auth (none / jwt / oauth), swappable storage (in-memory, filesystem, Supabase, Cloudflare KV/R2/D1), structured logging with optional OpenTelemetry tracing.
Attack-surface-specific:
Passive and non-intrusive by mandate — public records plus each target's own single published response; active scanning, exploitation, and brute-forcing are excluded from the surface, not toggled by a flag
Keyless core — CT subdomain enumeration, DNS, TLS, HTTP/tech, and RDAP/WHOIS all work with zero API keys; Shodan is strictly additive depth
SSRF guard on every outbound connection — rejects private, loopback, link-local, cloud-metadata, and reserved IPv4/IPv6 ranges before connecting (opt out for trusted internal assessment via
ATTACKSURFACE_ALLOW_PRIVATE_TARGETS)Multi-source aggregation with fallback chains — CT discovery falls through crt.sh → Certspotter → TLS-SAN; registration falls through RDAP → WHOIS
Agent-friendly output:
Provenance on every result — source labels (
source: crt.sh | certspotter | tls-san,source: rdap | whois) and per-source status so agents can assess completeness and trustGraceful partial failure — multi-target and multi-source tools return per-item/per-source
errorfields and operationalnotesinstead of failing the whole call; only malformed input throwsDiscriminated, typed contracts — typed error reasons (
source_unavailable,blocked_target,all_sources_failed) and union output (kind: domain | ip) let callers branch on data, not string parsingNo fabricated signal — technology detections carry their triggering evidence; absent CT/DNS/RDAP fields are reported as unknown, never inferred
Getting started
Add the following to your MCP client configuration file. Every tool except attacksurface_lookup_host works with no configuration — the keyless core boots on an empty environment.
{
"mcpServers": {
"attack-surface-mcp-server": {
"type": "stdio",
"command": "bunx",
"args": ["@cyanheads/attack-surface-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}Or with npx (no Bun required):
{
"mcpServers": {
"attack-surface-mcp-server": {
"type": "stdio",
"command": "npx",
"args": ["-y", "@cyanheads/attack-surface-mcp-server@latest"],
"env": {
"MCP_TRANSPORT_TYPE": "stdio",
"MCP_LOG_LEVEL": "info"
}
}
}
}Or with Docker:
{
"mcpServers": {
"attack-surface-mcp-server": {
"type": "stdio",
"command": "docker",
"args": ["run", "-i", "--rm", "-e", "MCP_TRANSPORT_TYPE=stdio", "ghcr.io/cyanheads/attack-surface-mcp-server:latest"]
}
}
}To enable Shodan host intelligence (attacksurface_lookup_host), add SHODAN_API_KEY to the env block.
For Streamable HTTP, set the transport and start the server:
MCP_TRANSPORT_TYPE=http MCP_HTTP_PORT=3010 bun run start:http
# Server listens at http://localhost:3010/mcpPrerequisites
Bun v1.4.0 or higher (or Node.js v24+).
No API key required for the core tools. Optional: a Shodan API key for
attacksurface_lookup_host, and a Certspotter API key to raise CT-fallback rate limits.
Installation
Clone the repository:
git clone https://github.com/cyanheads/attack-surface-mcp-server.gitNavigate into the directory:
cd attack-surface-mcp-serverInstall dependencies:
bun installConfigure environment (optional):
cp .env.example .env
# edit .env only if you want Shodan, a Certspotter key, or non-default behaviorConfiguration
All variables are optional — the server boots and delivers its keyless core with an empty environment.
Variable | Description | Default |
| Enables | — |
| Raises Certspotter rate limits for the CT-log subdomain fallback. Absent → free unauthenticated tier (rate-limited but functional). | — |
| Comma-separated default DNS resolver IPs for |
|
| Default User-Agent for |
|
| Cap on subdomains resolved during a |
|
| RDAP bootstrap base URL; override for a private/mirrored RDAP. |
|
| Set |
|
| Transport: |
|
| Port for HTTP server. |
|
| HTTP session mode: |
|
| Auth mode: |
|
| Log level (RFC 5424). |
|
| Enable OpenTelemetry instrumentation. |
|
See .env.example for the full list of optional overrides.
Running the server
Local development
Build and run:
# One-time build bun run rebuild # Run the built server bun run start:stdio # or bun run start:httpRun checks and tests:
bun run devcheck # Lint, format, typecheck, security bun run test # Vitest test suite bun run lint:mcp # Validate MCP definitions against spec
Docker
docker build -t attack-surface-mcp-server .
docker run --rm -e MCP_TRANSPORT_TYPE=http -p 3010:3010 attack-surface-mcp-serverThe Dockerfile defaults to HTTP transport, stateless session mode, and logs to /var/log/attack-surface-mcp-server. OpenTelemetry peer dependencies are installed by default — build with --build-arg OTEL_ENABLED=false to omit them.
Project structure
Directory | Purpose |
|
|
| Server-specific environment variable parsing and validation with Zod. |
| Tool definitions ( |
| Resource definitions ( |
| Domain service integrations ( |
| SSRF guard and input validation. |
| Unit and integration tests mirroring |
Development guide
See CLAUDE.md/AGENTS.md for development guidelines and architectural rules. The short version:
Handlers throw, framework catches — no
try/catchin tool logicUse
ctx.logfor request-scoped logging,ctx.statefor tenant-scoped storageRegister new tools and resources via the barrels in
src/mcp-server/*/definitions/index.tsEvery outbound connection to a user-supplied target must pass the SSRF guard (
assertSafeDomain/assertSafeUrl/assertSafeResolverIp) before connectingWrap external API calls: validate raw → normalize to domain type → return output schema; never fabricate missing fields
Contributing
Issues are welcome. Run checks and tests before submitting:
bun run devcheck
bun run testLicense
Apache-2.0 — see LICENSE for details.
This server cannot be deployed
Maintenance
Related MCP Connectors
WHOIS/RDAP, DNS, SSL, live subdomains with IPs, and SPF/DMARC/DKIM for any domain.
Passive domain-perimeter checks — cert expiry, subdomain takeover, lookalikes — as agent tools
Domain intelligence for DNS, WHOIS/RDAP, TLS, reputation, valuation, and brand protection.
Discover exposed assets, leaked secrets, APIs & client-side vulns across your attack surface
Related MCP Servers
- -licenseNot gradedqualityNot gradedmaintenanceEnables ethical security testing and attack surface management through SSL certificate validation, CVE queries, subdomain enumeration, security header analysis, and comprehensive reconnaissance capabilities. Designed for authorized penetration testing workflows with responsible disclosure practices.-
- FlicenseNot gradedqualityDmaintenanceEnables external reconnaissance activities including DNS enumeration, subdomain discovery, email security analysis, and SSL certificate inspection against a target domain.13-
- AlicenseNot gradedqualityCmaintenanceMCP server for passive domain reconnaissance and attack surface monitoring. It scans subdomains, security headers, TLS certs, and tech stack, detects subdomain takeovers, and reports changes since the last scan.2MIT
- AlicenseNot gradedqualityCmaintenanceProvides safe network reconnaissance through DNS resolution, TLS inspection, HTTP security header grading, and bounded port scanning over the stateless MCP protocol.MIT