Probe Security Headers
Check HTTP security headers across your web properties to identify missing protections like CSP, HSTS, and X-Frame-Options.
Find hidden or forgotten web services running on your infrastructure that may be exposed without your knowledge.
ToolSecurity HTTPxEvery organization has services they have forgotten about. A test server deployed two years ago and never decommissioned. A staging environment accidentally exposed to the internet. An admin panel on a non-standard port. A debug service running alongside production. These hidden services are prime targets for attackers because they are typically unpatched, unmonitored, and unprotected.
Host probing discovers HTTP services running across your IP ranges and subdomains. It identifies what is responding, on which ports, with what technologies, and whether it is intentionally exposed. The probe_hosts skill efficiently scans large ranges and returns details about every responding service.
This is critical for security teams managing large infrastructures, companies that have gone through acquisitions, and any organization where multiple teams deploy independently. You cannot secure what you do not know exists. Regular discovery scanning ensures no hidden service becomes the entry point for a breach.