apexdrift

Offensive recon, as a service

Everything a domain
forgot it exposed.

Point ApexDrift at a domain and get its attack surface, the secrets leaking in its JavaScript, the subdomains you can take over, and the attack paths inside its Active Directory — then get alerted when any of it changes. No packets touch the target.

2 free scans, no account needed. Sign in to unlock the full suite.

The suite

All tools →

What you'll surface

The subdomain they forgot

Certificate transparency and passive DNS surface staging boxes, old microsites, and forgotten endpoints — the assets nobody remembers owning.

The key in their JavaScript

Pull a target's JS and find the live AWS, Stripe, or GitHub key committed into a bundle — a critical finding hiding in plain sight.

The path to Domain Admin

Turn a BloodHound export into the shortest attack paths and the DCSync, Kerberoast, and delegation findings that outrank them.

The bug you can't see

Plant a canary and get alerted the moment a blind XSS fires in someone's admin panel — with the page, cookies, and source.

Built by red-teamers, for red-teamers.

Every tool works on data you're authorised to hold, shares one account and one subscription, and skips the setup. Start free.