Methodology & Ethics
VOIDSCAN is a passive reconnaissance and attack-surface awareness platform. It aggregates publicly available intelligence about a target and presents it as a defensive posture report. It is deliberately not a penetration-testing or exploitation tool.
- ›Analyze publicly available metadata and configuration
- ›Compute defensive scores from observed signals
- ›Cross-reference public vulnerability databases
- ›Cache results briefly at the edge for performance
- ×Perform port scanning or active service probing
- ×Attempt authentication, brute force or fuzzing
- ×Exploit, confirm or weaponise any vulnerability
- ×Access non-public content or bypass access controls
Data Sources
DNS-over-HTTPS
A/AAAA/MX/TXT/CAA/NS/SOA resolution and SPF/DMARC posture via Cloudflare & Google resolvers.
Live TLS handshake
A real TLS connection reads the presented X.509 certificate, negotiated protocol and cipher. Certificate Transparency logs are used as a fallback.
HTTP response analysis
The site is fetched as an ordinary web client; only public headers, cookies metadata and returned HTML are inspected.
IP & ASN intelligence
Geolocation and hosting attribution from public IP intelligence providers.
Shodan InternetDB
Passive exposure data (previously-observed open ports, product CPEs, tags) — no active scanning is performed by VOIDSCAN.
NVD 2.0 API
Public vulnerability records from the U.S. National Vulnerability Database, for informational cross-reference only.
Authorised use only
Only scan assets you own or are explicitly authorised to assess. Scores and findings are derived from passively-collected public signals and may be incomplete or out of date — always validate before acting on them.