Authorised recon and reporting workspace

Recon Desk

Review a public web asset using safe passive and configuration checks. Turn validated observations into structured security findings, then export a client-ready assessment report.

Open workspace
Designed for authorised testingNo port scanning, brute force, credential testing or exploitation. The server blocks private and reserved network targets.
recon-desk / safe-mode
01Resolve public DNS and certificate names
02Review TLS certificate and expiry
03Inspect HTTP security headers and cookies
04Check security.txt, robots.txt and sitemap.xml
05Build, edit and export assessment findings
Security research workspace
No scan stored

Assess a public target

Enter a domain or HTTP(S) URL. The service connects only to ports 80 and 443.

Paths are ignored. Private, local and reserved network addresses are blocked.
Running safe passive checks…
HTTP statusPrimary response
DNS records0Supported records
Certificate names0Public CT entries
Observations0Needs validation
Target and method
DNS records
TLS certificate
HTTP response and headers
Standard files
Certificate-transparency names
Observations to validate
Raw JSON

Add finding

Record enough evidence for another reviewer to reproduce and validate the issue.

Confirm action