Offensive recon, as a service
Everything a domain
forgot it exposed.
Point ApexDrift at a domain and get its attack surface, the secrets leaking in its JavaScript, the subdomains you can take over, and the attack paths inside its Active Directory — then get alerted when any of it changes. No packets touch the target.
2 free scans, no account needed. Sign in to unlock the full suite.
The suite
All tools →Passive subdomain and asset discovery with change detection.
Turn a BloodHound export into ranked attack paths and a client-ready report.
Build targeted credential wordlists from a roster you already have.
Decode a JSON Web Token and flag security issues and weak secrets.
Find subdomains with dangling DNS pointing at unclaimed cloud services.
Scan a target's JavaScript and assets for leaked API keys and credentials.
Pull hidden API endpoints and paths out of a target's JavaScript.
Catch blind XSS and out-of-band interactions with alerting callback URLs.
What you'll surface
The subdomain they forgot
Certificate transparency and passive DNS surface staging boxes, old microsites, and forgotten endpoints — the assets nobody remembers owning.
The key in their JavaScript
Pull a target's JS and find the live AWS, Stripe, or GitHub key committed into a bundle — a critical finding hiding in plain sight.
The path to Domain Admin
Turn a BloodHound export into the shortest attack paths and the DCSync, Kerberoast, and delegation findings that outrank them.
The bug you can't see
Plant a canary and get alerted the moment a blind XSS fires in someone's admin panel — with the page, cookies, and source.
Built by red-teamers, for red-teamers.
Every tool works on data you're authorised to hold, shares one account and one subscription, and skips the setup. Start free.