For bug bounty hunters & red teams

Full attack-surface recon + executive report
in one run.

Stop babysitting 40 CLI tools. SquidScan runs 45 agents, diffs what changed since last week, validates CVEs against real versions, and emails a Grok report when the job finishes.

Start your free scan

First scan free No subscription Tokens never expire

Only scan domains you own or are authorized to test. Unauthorized use is prohibited.

demo-target.example
AGENTS ACTIVE
subfinder✓ done
httpx + nuclei✓ done
scan_diff✓ 12 new hosts
known_exploitsrunning

Same flow as production — paste domain, agents run, report lands.

45
Specialized recon agents
8
Phases · OSINT → CVEs
Auto-diff
What changed since last run
Live demo

How it works

Three steps. Zero infra.

01

Submit an authorized domain

Create an account — first scan is free. Paste a target you own or are in-scope to test. Optional: sync HackerOne / Bugcrowd scope.

02

Agents run the full pipeline

45 agents across 8 phases: passive OSINT, DNS, live hosts, active checks, and Known Exploits with version-validated CVEs.

03

Report, diff & deliver

Recon Intelligence dashboard, Grok executive summary emailed on complete, PDF export, and auto-diff vs your prior run on re-scans.

Why not DIY?

Not another scanner dump.

You already know subfinder and nuclei. SquidScan is the orchestration, intelligence, and client-ready output layer — without owning the stack.

Full agentic pipeline

Every tool has a dedicated agent that parses, filters, and feeds the next phase — not a shell script that dumps raw logs.

Change detection that matters

Schedule weekly recon. Wake up to new hosts, tech, CVEs, and paths — not another full dump to re-triage.

CVEs + Grok report

Version-validated exploit research and an executive narrative you can send to clients or paste into a bounty write-up.

SquidScan vs DIY toolchain
Capability DIY stack SquidScan
Run 40+ recon tools You glue it Built-in · 45 agents
Attack-surface diffs Manual / scripts Automatic on every re-scan
Version-validated CVEs Spreadsheet roulette Known Exploits phase
Exec / client report You write it Grok · email · PDF
H1 / Bugcrowd scope Copy-paste lists Live scope sync
Infra & upkeep Your VPS forever Zero — pay per scan

Platform

Everything operators actually use

Recon Intelligence

KPI tiles, charts, word maps, click-through to raw evidence.

Bounty scope sync

HackerOne & Bugcrowd — pick targets or Run All In Scope.

Scheduled scans

Daily, weekly, or monthly in your timezone. Full pipeline on autopilot.

Active + passive coverage

Subdomains, secrets OSINT, nuclei, GraphQL, CORS, SSRF, and more.

PDF & public shares

Sectioned exports including scan changes. Share links for stakeholders.

Operator badges

100+ achievements for discovery milestones — share on LinkedIn & X.

Proof

Real product. Real report.

Screenshots from production — and a completed job you can open right now.

SquidScan jobs dashboard
Submit domains · track all 45 agents
Recon Intelligence dashboard
Recon Intelligence — KPIs & charts
Technology map and Grok report
Tech fingerprinting · Grok AI report
HackerOne scope integration
HackerOne scope sync
Scheduled scans settings
Scheduled scans that auto-diff
Operator badge system
Operator badges · shareable wins

Coverage

45 tools. One dedicated agent each.

wayback crtsh github dork subfinder dnsx httpx nuclei nikto katana ffuf naabu graphql ssrf cors testssl wordpress cloudenum known exploits + 27 more

Full tool-by-tool breakdown for decision-makers on the For teams overview.

Pricing

Simple. Transparent. Pay as you go.

First scan free after you create an account. Then buy tokens — no subscription. Scans never expire.

Every paid scan includes the full 45-agent pipeline, Recon Intelligence, Grok report, and PDF export options.

START HERE
1
Scan
Free

$0.00 / scan

Start free
1
Scan
$5

$5.00 / scan

Get tokens
10
Scans
$15

$1.50 / scan

Get tokens
MOST POPULAR
25
Scans
$25

$1.00 / scan

Get tokens
50
Scans
$45

$0.90 / scan

Get tokens
100
Scans
$75

$0.75 / scan

Get tokens

Need volume for a consultancy or team? Email us for bulk pricing.

FAQ

Before you hit register

Is the first scan really free?

Yes. Create an account and run one full pipeline scan at no charge. After that, buy pay-as-you-go tokens. Tokens never expire and there is no monthly subscription.

What am I allowed to scan?

Only assets you own or are explicitly authorized to test (for example in-scope bug bounty targets). Unauthorized scanning is prohibited. Domain owners can permanently opt out via our opt-out form.

How is this different from running my own tools?

You still get the tools you trust — but with agent orchestration, a visual intelligence layer, automatic scan-to-scan diffs, bounty scope sync, and a Grok executive report you do not have to write. No VPS babysitting.

What is version-validated CVE research?

The final Known Exploits phase aggregates technologies found on the target and matches public CVEs only when the installed version falls in the affected range — so you spend less time on theoretical noise.

How long does a scan take?

Depends on target size and live surface. Many jobs complete in well under an hour; large attack surfaces take longer. The dashboard auto-refreshes so you can watch agents finish in real time.

Are HackerOne / Bugcrowd credentials safe?

Credentials are stored for scope sync on your profile so you can pick in-scope assets and run authorized targets. Use API tokens with least privilege where the platform allows. You control connect and disconnect.

Who sees my targets and findings?

Jobs are private to your account by default. You can optionally share a public report link. See our Terms for data handling details.

What if a scan fails?

If something goes wrong on our side, contact support with the job ID. We work to make sure you are not stuck paying for a broken run — reach us at contact@squidhacker.com.

Evaluating for a team or BA / IT stakeholders?

See the plain-language SquidScan 101 overview — ROI framing, compliance notes, and full tool list without the neon deep-dive.

Run your first authorized domain in minutes.

Pay only for scans you use. First one is free.

Create account & start free scan →

Already have an account? Log in