Discover known endpoints, paths, and URLs for a domain from historical web archives and passive sources — no active scanning.
⌕
Recent scans
Scanning sources…
0%
Endpoints Found
0
Sources Hit
0
Domain
—
Endpoints
File Types
Security
Discovery
#
URL
Status !⚠️ These are historical status codes — recorded the last time that service crawled the URL. A 200 doesn't mean the URL is alive right now. The data could be months or years old.
For live status codes, probe each URL with httpx — that's step 1 in the "What Next" workflow.
Source
◎
Enter a domain above and click Scan to start discovering endpoints.
JS Analyzer
EndpointsSecrets & KeysLinksClient-side
Fetch JavaScript files and mine them for hidden endpoints, leaked secrets/API keys, and referenced hosts — all in your browser via CORS proxies.
JS URLs (one per line) — or paste raw JS source
Fetching & analyzing…
0%
Files Analyzed
0
Endpoints
0
Secrets
0
Links / Hosts
0
Critical findings detected
Findings
Type
Finding
Source File
◎
Paste JS URLs above (or Import from Endpoints) and click Analyze JS.
RECOXRecon Workflow — Export & Next Steps
→
Enumeration Done!
Subdomains found — what should you do next as a bug bounty hunter?
See next steps
→
What to do after Subdomain Enumeration?
Bug bounty recon workflow — step by step
You've mapped the attack surface — now it's time to dig deeper. Below is the proven post-recon workflow used by top bug bounty hunters to find real vulnerabilities from a subdomain list.