Mission Control · OSINT Reconnaissance Console

Launch a recon scan. Watch it run live.

A multi-tenant console for OSINT reconnaissance. Point it at a domain, pick a preset, and watch subdomains, open ports, exposed services, and vulnerabilities stream into the dashboard as they're discovered.

First scan in 60 s 10+ scanner modules Free for one workspace
What's in the console

Everything you need to drive an OSINT scan, none of the install.

A purpose-built console for OSINT scanning, plus the operational surface (targets registry, presets, integrations, reports, per-user isolation) you'd otherwise build yourself.

Live scan monitoring

Events per second, total events, DNS queries, HTTP requests, findings — updated in real time. Plus a 3-pane mission-control view: module activity, telemetry graph, terminal log.

events/secmodule activityterminal logpause / resume / stop

Six curated presets

Bundles of modules for the most common scan objectives — subdomain enumeration, web crawl, email harvest, web tech detection, cloud asset discovery, deep spider.

subdomain-enumspider-basicemail-enumweb-basiccloud-enumspider-heavy

10+ scanner modules

Toggle individual modules on or off per workspace. Built-in safety on aggressive scanners — they require an explicit --allow-deadly flip in the launcher.

crtshshodan_dnshttpxnucleiwaybackmasscannmapgithub_codesearch

Output integrations

Stream events to where your team already lives. One-click test endpoint, per-integration enable/disable, last-used-at telemetry.

SlackDiscordNeo4jWebhookS3SplunkElastic

Targets registry & per-user isolation

Persist targets across scans (domains, IPs, CIDRs, ASNs, URLs) with tags. Every resource — scans, targets, presets, keys, reports — is scoped to your workspace.

domainipcidrasnurlper-user scoping

Reports & full REST API

Generate PDF / JSON / CSV / HTML reports per scan. Every console action also exists as a token-authenticated REST endpoint — drive scans from CI, your SIEM, or a notebook.

pdfjsoncsvhtmltoken authOpenAPI
How it works

Three steps. First findings inside a minute.

01 · DEFINE

Drop in your targets

Type, paste, or upload a list. Auto-detects domain / IP / CIDR / ASN / URL. Save to the Targets registry to reuse across scans.

+ target  example.com           domain
+ target  10.0.0.0/24           cidr
+ target  AS12345               asn
02 · CONFIGURE

Pick a preset, tweak modules

Six built-in presets cover common objectives. Toggle individual modules on or off. Aggressive scanners are blocked unless you flip --allow-deadly.

preset   subdomain-enum
modules  crtsh, shodan_dns,
         wayback, dns_brute
03 · WATCH

Launch & monitor live

Pause, resume, or stop. Tail the event log, watch module activity, see findings stream as they happen. Auto-routed to your integrations.

events/sec  1,204
findings     27 (12 high)
status       running 14:22
Presets & modules

Curated bundles or roll your own.

Each preset is a tested combo of modules for one objective. Mix and match individual modules when you need something more surgical, then save the combination as a custom preset for next time.

Built-in presets

Ready to launch — pick one and add targets.

subdomain-enumdiscovery
spider-basiccrawl
email-enumosint
web-basictech detect
cloud-enumbuckets
spider-heavydeep crawl

Modules

Toggle per workspace · category-tagged for safety.

crtshpassive
shodan_dnspassive
waybackpassive
httpxactive
nucleiactive
dns_bruteactive
nmapdeadly
masscandeadly
Pricing

Start free. Scale when you outgrow the seat.

All tiers include the full scanning stack, every preset, every module. Higher tiers unlock more concurrent scans, longer retention, more seats, and priority support.

Free

Free

$0 / month
  • 1 workspace, 1 seat
  • 2 concurrent scans
  • 10 scans / month
  • 30-day scan history
  • All presets & modules
  • 3 integrations
Create free account
Starter

Basic

$19 / month
  • 5 seats
  • 5 concurrent scans
  • 100 scans / month
  • 90-day scan history
  • PDF / JSON / CSV / HTML reports
  • Unlimited integrations
  • Email support
Start with Basic
Enterprise

Enterprise

Custom
  • Unlimited seats & scans
  • SSO + audit log
  • On-prem deploy option
  • Dedicated support & SLA
  • Custom scanner module bundles
  • Private Slack channel
Talk to sales
FAQ

Frequently asked

What can a scan find?

Subdomains (via Certificate Transparency, passive DNS, bruteforce), open ports, HTTP responses, exposed services, leaked credentials, and vulnerabilities matched by nuclei templates. Built-in presets bundle modules for common objectives like subdomain-enum, web-basic, cloud-enum, and email-enum.

Can scans be paused or stopped mid-run?

Yes. The active scan view shows live events per second, per-module activity, and a tail of the event log. Pause, resume, or stop from the same UI — the scan moves to History with its partial results intact.

Where do findings end up?

In the console for triage. Stream events in real time to Slack, Discord, Neo4j, generic webhooks, S3, Splunk, or Elastic via the Output Integrations panel. Export PDF / JSON / CSV / HTML reports per scan when you need an artifact.

Is there an API?

Yes. Every console action is also a REST endpoint under https://api.everwatch.com.br/api/ — token-authenticated, per-user scoped, OpenAPI-described. Drive scans from your CI, your SIEM, or your existing tooling.

What about the aggressive scanners? (nmap, masscan)

Deadly modules are listed in the catalog but disabled by default. They only run if you both (a) toggle them on for your workspace, and (b) flip the --allow-deadly switch when launching the scan. Belt and suspenders.

Is the free tier really free?

Yes. One workspace, two concurrent scans, ten scans per month, no credit card. Upgrade only when your team or scan volume outgrows it.

Get started

Launch your first scan in 60 seconds.

Free workspace, no card, no demos. Sign up, drop in a domain, hit Launch.