XowiaScan

The XowiaScan toolbox

42 tools across 5 categories — free to start.

Recon & Discovery (16)

Vulnerability Scanner

All-in-one passive + opt-in active scanner — feed a URL or a raw HTTP request and surface misconfigurations and vulnerabilities, graded by severity.

Subdomain Discovery

Aggregate subdomains from crt.sh, OTX, Shodan, CertSpotter & more.

WHOIS Lookup

Query registrar WHOIS records over port 43.

Port Intelligence

Passive open-port & CVE exposure lookup (Shodan InternetDB) plus ready-to-run nmap/naabu/rustscan commands — no scan traffic leaves our servers.

CNAME / DNS Checker

Resolve A/AAAA/CNAME/MX/NS/TXT/CAA, follow the CNAME chain, flag subdomain-takeover candidates and check SPF/DMARC + wildcard DNS.

Wayback URL Extractor

Pull historical URLs from the Internet Archive, then mine parameters, subdomains and sensitive files for testing.

SiteMapper Pro

Turn a URL list into a visual site tree with sensitive-path/file highlighting, stats and export.

HTTP ProbeMaster

Bulk-probe hosts in parallel — status, redirects, title, tech stack, server, IP & timing — flags notable findings (dir listing, phpinfo, API docs) with filtering & export.

Image EXIF Extractor

Batch-extract EXIF + IPTC + XMP metadata (GPS, device serials, owner, software) from uploaded images or remote URLs — with a leak summary & reverse-geocoded GPS.

URL Extractor

Extract unique URLs from text or files.

Security Header Analyzer

Fetch a URL and grade its security headers.

CORS Misconfig Tester

Probe CORS ACAO/ACAC behavior with a spoofed Origin.

CIDR / IP Calculator

Expand CIDR ranges, netmask, host count.

DNS Recon Pro

AXFR test, SPF/DMARC/DKIM, DNSSEC & dangling-CNAME check.

Robots & Sitemap Harvester

Pull disallowed paths and sitemap URLs.

Tech Fingerprint

Detect server, CMS, frameworks & libraries.

Sign up to use them →