VOIDSCAN

Methodology & Ethics

VOIDSCAN is a passive reconnaissance and attack-surface awareness platform. It aggregates publicly available intelligence about a target and presents it as a defensive posture report. It is deliberately not a penetration-testing or exploitation tool.

what it does
  • Analyze publicly available metadata and configuration
  • Compute defensive scores from observed signals
  • Cross-reference public vulnerability databases
  • Cache results briefly at the edge for performance
what it never does
  • ×Perform port scanning or active service probing
  • ×Attempt authentication, brute force or fuzzing
  • ×Exploit, confirm or weaponise any vulnerability
  • ×Access non-public content or bypass access controls

Data Sources

DNS-over-HTTPS

A/AAAA/MX/TXT/CAA/NS/SOA resolution and SPF/DMARC posture via Cloudflare & Google resolvers.

Live TLS handshake

A real TLS connection reads the presented X.509 certificate, negotiated protocol and cipher. Certificate Transparency logs are used as a fallback.

HTTP response analysis

The site is fetched as an ordinary web client; only public headers, cookies metadata and returned HTML are inspected.

IP & ASN intelligence

Geolocation and hosting attribution from public IP intelligence providers.

Shodan InternetDB

Passive exposure data (previously-observed open ports, product CPEs, tags) — no active scanning is performed by VOIDSCAN.

NVD 2.0 API

Public vulnerability records from the U.S. National Vulnerability Database, for informational cross-reference only.

Authorised use only

Only scan assets you own or are explicitly authorised to assess. Scores and findings are derived from passively-collected public signals and may be incomplete or out of date — always validate before acting on them.