subrecon is a multi-source subdomain reconnaissance and pentest-kickoff tool. Point it at a
domain and it discovers subdomains, resolves and probes them, then runs a battery of
external-surface security checks — producing a prioritized findings report instead of
raw scan output.
Why the lock screen?
Several checks this tool runs are active — they send crafted requests (directory
brute-force, path-traversal probes, port scans, CORS/HTTP-method tests) rather than just
passively reading public records. An access code keeps this instance from being used
against domains its operator hasn't authorized.
Authorized use only
Only scan domains you own or have explicit written permission to test.