ThinRecon · active reconnaissance
Free authorised active reconnaissance of your public surface.
Targeted, hands-on tooling — httpx, nmap, subfinder, sslyze, nuclei, katana, gau, and trufflehog — orchestrated by our reasoning model, now including authenticated, proof-of-vulnerability testing: our agent creates its own throwaway test accounts to exercise logged-in flows. Proof-of-vulnerability only: no bulk data extraction, no denial-of-service, no destruction of real accounts or data. Free while we onboard our first cohort of customers.
- Submit the engagement. Enter your work email and the authorising officer, then accept the Rules of Engagement. We test the domain of your email — scope is optional.
- The authorising officer authorises. We email them a one-click link. The active reconnaissance starts the moment they click it — never before.
- Report by email. When the active recon completes, the findings land in your inbox — with critical issues flagged as critical.
Step 2 of 2 · Authorisation
Check the authorising officer's inbox.
We've emailed a one-click authorisation link for
your-domain.com to the authorising officer.
The active reconnaissance starts the moment they click it — nothing runs until then. The link
expires in 7 days.
Once it's clicked, we'll email the report to your work email when the active recon completes — usually within 15 minutes.
Didn't arrive? Check spam, or reply to inquiry@thinsky.com and we'll re-send it.