Infrastructure Mapper

Recent Scans
Scan Options
Discovery Scope




Deep Analysis




System & Display
API Keys (Optional)
Add API keys to enable optional OSINT sources.
Keys are stored only in your browser and are not included in copied links.
Please agree to the privacy notice to use the tool.
Global Diagnostics
CT fetch, DNS batches, and Identity Provider probes.
No CT attempts yet.
No DNS queries yet.
No IdP probes yet.
Unknown Record Log
Logs TXT and SPF `include`/`redirect` domains that don't match known service signatures.
Unknown TXT Records
No unknown TXT records logged yet.
Unknown SPF Records
No unknown SPF records logged yet.
Cloud Bill of Materials (CBoM)

This tool makes direct browser connections where possible and uses proxy.php for selected CORS-restricted sources. Here is a list of all external services used:

DNS-over-HTTPS (DoH) Providers

Services: Cloudflare DNS, Google DNS

Purpose: Performs DNS lookups for consistent, unfiltered results, bypassing local/ISP resolvers.

Endpoints:

Data Sent: The domain name or IP address being queried (e.g., `?name=example.com&type=A`).

Certificate Transparency (CT) Logs

Service: crt.sh (via server-side proxy)

Purpose: Discovers subdomains by searching public logs of SSL/TLS certificates.

Endpoint:

Data Sent: The domain name being scanned. The request is made server-side, so crt.sh sees the server's IP address, not yours.

Internet Archive (Wayback Machine)

Service: Archive.org

Purpose: Discovers subdomains and historical URLs matching the domain.

Endpoint: https://web.archive.org/cdx/search/cdx

Data Sent: The domain name being scanned. The request is attempted directly from your browser and falls back to this application's own server-side proxy when the Internet Archive blocks the cross-origin request.

ProjectDiscovery (Chaos)

Service: ProjectDiscovery Chaos API

Purpose: Discovers subdomains using the Chaos dataset.

Endpoint: https://dns.projectdiscovery.io/dns/{domain}/subdomains

Data Sent: Domain name and your API key. The request runs through this application's own server-side proxy, which forwards the key to ProjectDiscovery as an Authorization header; a browser cannot send that header to Chaos directly. The Chaos dataset only covers domains from public bug bounty programmes, so most domains return no results.

OpenID Connect Discovery

Service: The identity hosts discovered during the scan.

Purpose: Reads the publicly published discovery document to establish whether a host acts as an OpenID Connect provider and which endpoints it advertises.

Endpoint: https://{host}/.well-known/openid-configuration and /.well-known/oauth-authorization-server

Data Sent: Nothing beyond the request itself. No credentials are sent and no authentication is attempted; the request runs through this application's own server-side proxy, so the target sees the server's IP address, not yours.

AlienVault OTX

Service: AlienVault Open Threat Exchange

Purpose: Passive DNS lookup for subdomain discovery.

Endpoint: https://otx.alienvault.com/api/v1/indicators/domain/{domain}/passive_dns

Data Sent: Domain name and your API Key (X-OTX-API-KEY header). Sent directly or via proxy to AlienVault.

Autonomous System Number (ASN) Lookups

Service: Team Cymru

Purpose: Identifies the network owner (e.g., Google, Amazon) of an IP address via its ASN.

Endpoint: DNS queries are made to `*.asn.cymru.com`.

Data Sent: The reversed IP address being queried (e.g., for `8.8.8.8`, a query is sent for `8.8.8.8.origin.asn.cymru.com`).

IP Address Range Lookups

Service: RIPEstat

Purpose: To determine the parent IP address range (prefix) for a given public IP.

Endpoint: https://stat.ripe.net/data/network-info/data.json

Data Sent: The IP address being queried (e.g., `?resource=8.8.8.8`).

Cloud Identity Probes

Purpose: To check for cloud identity services (like Microsoft Entra ID) by querying well-known public configuration endpoints.

Microsoft Entra ID / M365

Services: Microsoft Online Services (Commercial, US Government, China)

Endpoints: Your browser attempts to connect to endpoints such as:

  • https://login.microsoftonline.com/{domain}/.well-known/openid-configuration
  • https://login.microsoftonline.com/getuserrealm.srf?login=info@{domain}
  • https://login.microsoftonline.us/... (US Gov)
  • https://login.chinacloudapi.cn/... (China)

Data Sent: The domain name being scanned.

WebFinger

Service: Generic Identity Provider Discovery

Endpoint: https://{domain}/.well-known/webfinger

Data Sent: The domain name being scanned (e.g., `...webfinger?resource=acct:info@example.com`).

ADFS Metadata

Service: Active Directory Federation Services

Endpoint: If an ADFS server is identified, the tool queries its public metadata endpoint, typically https://{adfs_server}/FederationMetadata/2007-06/FederationMetadata.xml.

Data Sent: A request to the discovered ADFS server hostname.

Third-Party Libraries

Service: Cloudflare CDN

Purpose: To load the Punycode.js library, which is required for handling internationalized domain names (IDNs).

Endpoint: https://cdnjs.cloudflare.com/ajax/libs/punycode/2.3.1/punycode.min.js

Data Sent: A standard request to fetch the JavaScript file.

Signature Definitions

Service: AntiHacker.nl

Purpose: Loads the latest DNS and SPF service signatures.

Endpoint: https://antihacker.nl/infra-mapper/js/definitions.js

Data Sent: A standard request to fetch the JavaScript file.