First visit · operator briefing

Free vs Pro

Codename Sonar is defensive reconnaissance. Free is enough to ping a host you own — guests get two sweeps a day, signed-in Free gets five. Pro unlocks the full lattice: Apps menu (Zenmap, Lynis, Zeek, Maltego, GSA, Wireshark, ZAP…), optical / infrared / thermal lock, unlimited sweeps, and operator exports — billed monthly or yearly through PayPal.

Included

Free

Default

$0forever

Sign in, run five scans a day (guests two), keep the last three results. Satellite optical / infrared / thermal and quick profiles stay open.

  • Daily scansGuest 2/day · signed-in 5/day
  • Scan profilesPing + Quick
  • Kali Applications menuMenu + ping/quick analogs
  • Timing templatesT1–T3
  • Ping / host discoveryIncluded
  • Reverse DNS + IPv6 AAAAIncluded
  • Geo / ASN / ISP / RDAPIncluded
  • Satellite lockOptical · infrared · thermal
  • Port errata (what each port does)Included
  • Share to X / Instagram / FacebookIncluded
  • Custom ports
  • Traceroute world-map
  • Version / OS / TLS / UDP
  • OAuth 2.0 RFC 8414
  • OpenVAS-style NVTs
  • CIS / NIST / CISA scorecard
  • Analyst briefing
  • SIEM + CSV/PDF + STIX 2.1
  • Packet capture (Wire)Scan rebuild + 2 MB PCAP
  • Scan archiveLast 3
  • Watchlist + asset inventory
  • Certificate expiry watch
  • Mail auth (SPF / DMARC / MX)Included
  • Email address checkSyntax + MX / SPF / DMARC
  • Email origin traceReceived hop parse
  • DKIM / BIMI / MTA-STS
  • DNSSEC + CAAIncluded
  • WAF / CDN / tech stack
  • security.txt + CT names
  • HTTP header observatory
  • Nikto / nuclei path checks
  • WPScan / CMS surface
  • Gobuster / dirb paths
  • Cookie · CORS · TRACE audit
  • theHarvester emails
  • Wayback URL count
  • Zero Trust scorecard
  • CISA KEV + exploit likelihood
  • Ransomware readiness
  • Detection pack
  • IR playbooks (NIST 800-61)
  • Threat hunts + purple tests
  • Telemetry + segmentation plan
  • Governance mapping
  • CISA BOD 22-01 patch queue
  • FAIR-lite residual loss
  • Cyber insurance questionnaire
  • CIS Benchmarks (inferred)
  • SBOM-lite + attack path
  • ACL as code
  • Kali Cloud Desktop

Full lattice

Pro

Recommended

Monthly Professional Subscription

$5.99USD / month

Annual Professional Subscription

$29.99USD / year

Unlimited recon, Apps menu (Kali + Parrot + Blue Team), every profile including Kali recon, OSS toolkit, governance mapping, SIEM/STIX exports, watchlist, and a 50-scan archive. Auto-renews monthly or yearly — pick on checkout.

  • Daily scansUnlimited
  • Scan profilesIntense, comprehensive, web, stealth, Kali recon
  • Kali Applications menuZenmap, qterminal, GSA, Wireshark, ZAP — this sweep
  • Timing templatesT1–T5 including stealth
  • Ping / host discoveryIncluded
  • Reverse DNS + IPv6 AAAAIncluded
  • Geo / ASN / ISP / RDAPIncluded
  • Satellite lockOptical · infrared · thermal
  • Port errata (what each port does)Included
  • Share to X / Instagram / FacebookIncluded
  • Custom portsRanges and lists
  • Traceroute world-mapIncluded
  • Version / OS / TLS / UDPIncluded
  • OAuth 2.0 RFC 8414Discovery + grade A–F
  • OpenVAS-style NVTsFull and fast · version CVE · families
  • CIS / NIST / CISA scorecardIncluded
  • Analyst briefingIncluded
  • SIEM + CSV/PDF + STIX 2.1Included
  • Packet capture (Wire)25 MB PCAP, follow stream, export
  • Scan archiveLast 50 + port diff
  • Watchlist + asset inventoryIncluded
  • Certificate expiry watchIncluded
  • Mail auth (SPF / DMARC / MX)Included
  • Email address checkSMTP mailbox exists, catch-all, DKIM
  • Email origin traceGeo + reverse DNS per hop
  • DKIM / BIMI / MTA-STSMail DNS
  • DNSSEC + CAAIncluded
  • WAF / CDN / tech stackWhatWeb / Wappalyzer-style
  • security.txt + CT namesIncluded
  • HTTP header observatoryA+–F grade (securityheaders)
  • Nikto / nuclei path checks.git, .env, phpMyAdmin, actuators
  • WPScan / CMS surfaceWordPress, Joomla, Next.js
  • Gobuster / dirb pathsShort high-signal wordlist
  • Cookie · CORS · TRACE auditHttpOnly / Secure / SameSite
  • theHarvester emailsHomepage mailboxes
  • Wayback URL countArchive.org CDX
  • Zero Trust scorecardIdentity · device · network · app · data
  • CISA KEV + exploit likelihoodMatched to this sweep
  • Ransomware readinessSMB/RDP/backup posture
  • Detection packSigma · Suricata · Snort · Zeek · Elastic · Splunk
  • IR playbooks (NIST 800-61)Detect · contain · eradicate · recover
  • Threat hunts + purple testsQueries from this surface
  • Telemetry + segmentation planWhat to log and isolate
  • Governance mappingPCI DSS 4.0 · ISO 27001 · SOC 2 · HIPAA · 800-53 · ASVS
  • CISA BOD 22-01 patch queue15-day internet-facing KEV clock + compensating controls
  • FAIR-lite residual lossBoard heat map + USD bands from this host
  • Cyber insurance questionnaireNYDFS / NAIC-style filled from the sweep
  • CIS Benchmarks (inferred)Linux, Windows, Apache, Redis, Docker, K8s
  • SBOM-lite + attack pathInventory + likely kill chain from this vantage
  • ACL as codenftables · iptables · AWS SG · Cloudflare WAF
  • Kali Cloud DesktopAlpha · DigitalOcean Kali + Java GUI

New on Pro

Defender lattice

Kali · Intense · Web · Comprehensive · Stealth

One Pro sweep now folds in the Apps menu (Zenmap, Nikto, Lynis, Zeek, Suricata, Maltego, Gobuster, GSA, Wireshark, ZAP…) plus optical / infrared / thermal satellite lock and a defender suite: Zero Trust, KEV, detection packs, IR playbooks, PCI/ISO/SOC 2/HIPAA mapping, a BOD 22-01 patch queue, FAIR-lite residual loss, CIS Benchmarks, ACL-as-code, YARA, SOAR, and deception — still defensive, no exploit payloads.

Kali Applications

Click a package: Zenmap, qterminal, Greenbone GSA, Wireshark, ZAP, Observatory, Dradis — filled from this sweep

Parrot OS extras

AnonSurf, FinalRecon, Caido, Amass, NetExec, airgeddon, Empire/Sliver — Parrot packages Kali does not ship on its Applications menu

Kali recon profile

Top-160 ports + toolkit + NVT + TLS; Metasploit/Hydra/DoS stay off-lattice

Satellite optical / IR / thermal

NASA GIBS + ArcGIS lock — tabs for daylight, infrared, land-surface temperature

OpenVAS NVTs

Greenbone-style families, OIDs, QoD, banner/version CVE matching, web path tests

Nikto + nuclei paths

Defensive checks for /.git, /.env, phpMyAdmin, actuators, TRACE

WPScan / Joomscan

WordPress login, xmlrpc, wp-json, Joomla administrator

Gobuster / dirb

Short high-signal directory wordlist, no SecLists dump

httpx / WhatWeb / Wafw00f

Status, title, CMS, CDN/WAF from headers — no active WAF trip

theHarvester + recon-ng

Homepage emails, wayback CDX, security.txt, crt.sh names

dnsrecon mail DNS

DKIM selectors, BIMI, MTA-STS besides SPF/DMARC

testssl.sh / sslscan

Certificate, protocol, ALPN, trust flag on 443/8443

Mailbox existence

SMTP RCPT probe, catch-all detection, hop-by-hop Received trace

searchsploit

CVE → Exploit-DB search links only. No payloads.

OAuth 2.0 RFC 8414

Authorization-server discovery, PKCE, HTTPS-only grade

Zero Trust scorecard

NIST 800-207 pillars scored from this host

CISA KEV matching

EternalBlue, BlueKeep, Log4Shell, Exchange, VPN, Redis…

Detection pack

Sigma / Suricata / Snort / Zeek / Elastic / Splunk rules

IR playbooks

NIST 800-61 detect-contain-eradicate-recover plus D3FEND

Hunts + purple team

Hypotheses, queries, and tabletop tests from the surface

Governance mapping

PCI DSS 4.0, ISO 27001:2022, SOC 2, HIPAA, NIST 800-53, OWASP ASVS, CIS IG1

BOD 22-01 patch queue

15-day internet-facing KEV SLA, EPSS rank, compensating controls

FAIR-lite + insurance

Residual USD bands, board heat map, NYDFS/NAIC questionnaire

CIS Benchmarks + SBOM

Inferred checks for the OS/app you actually published

ACL as code

nftables, iptables, AWS security groups, Cloudflare WAF expressions

YARA · SOAR · Engage

Webshell rules, TheHive case, Shuffle isolate, MITRE Engage, canaries

Kali Cloud Desktop

Pro Alpha: DigitalOcean API spins a static Kali 2026.2 droplet; XFCE GUI via Java VNC viewer

Apps arsenal

Every Apps-menu package

Same tiles you open after a sweep, including twenty Blue Team apps (Lynis through Censys, plus checkdmarc, oauth2c, OpenSCAP, MISP, ntopng, CrowdSec, and TheHive). Each card has its man page. Free runs ping/quick analogs. Pro fills the live host. Off-lattice tools still open as apps — then refuse to fire.

Nmap / Zenmap

Information Gathering

man nmap(1)

Free Quick port set · Pro Top-160, custom lists, version/OS

dnsrecon / dnsenum

Information Gathering

man dnsrecon(1)

Free A/AAAA/MX/NS/TXT/PTR · Pro CAA, DNSSEC, related names

whois / RDAP

Information Gathering

man whois(1)

Free Included · Pro Included

WhatWeb / Wappalyzer

Information Gathering

man whatweb(1)

Free · Pro Stack fingerprint

Wafw00f

Information Gathering

man wafw00f(1)

Free · Pro Passive CDN/WAF

Recon-ng / SpiderFoot

Information Gathering

man recon-ng(1)

Free · Pro Wayback, security.txt, crt.sh

lbd

Information Gathering

man lbd(1)

Free Multiple A records · Pro Included

enum4linux / smbmap

Information Gathering

man enum4linux-ng(1)

Free · Pro 139/445 noted · no share brute

OpenVAS / GVM

Vulnerability Analysis

man gvm-cli(8)

Free · Pro NVT families, OID, QoD

Nikto

Web Application Analysis

man nikto(1)

Free · Pro Dangerous path list

WPScan

Web Application Analysis

man wpscan(1)

Free · Pro WP login / REST / XML-RPC

httpx / httprobe

Web Application Analysis

man httpx(1)

Free · Pro Status, title, headers

Gobuster / dirb

Web Application Analysis

man gobuster(1)

Free · Pro Short directory wordlist

Nuclei

Web Application Analysis

man nuclei(1)

Free · Pro Actuator / debug templates

testssl.sh / sslscan

Web Application Analysis

man testssl.sh(1)

Free · Pro Cert, protocol, ALPN

securityheaders

Web Application Analysis

man lynis(1)

Free · Pro A+–F header grade

ZAP / Burp (passive)

Web Application Analysis

man zap(1)

Free · Pro Cookies, CORS, methods

Wireshark / tcpdump

Sniffing & Spoofing

man tshark(1)

Free Sweep reconstruct · 2 MB · Pro 25 MB PCAP, follow stream

Dradis / Faraday

Reporting Tools

man dradis(1)

Free On-screen report · Pro SIEM · STIX · PDF export

FinalRecon

Information Gathering

man finalrecon(1)

Free · Pro DNS + WHOIS + headers + TLS

OWASP Amass

Information Gathering

man amass(1)

Free · Pro Passive related names

subfinder

Information Gathering

man subfinder(1)

Free · Pro Passive subdomains

TruffleHog

Information Gathering

man trufflehog(1)

Free · Pro .env / .git path check

Caido

Web Application Analysis

man caido(1)

Free · Pro Passive proxy analog

Wapiti

Web Application Analysis

man wapiti(1)

Free · Pro Findings as modules

ffuf

Web Application Analysis

man ffuf(1)

Free · Pro Short path fuzz

CMSeeK

Web Application Analysis

man cmseek(1)

Free · Pro CMS fingerprint

NetExec

Information Gathering

man nxc(1)

Free · Pro 139/445 noted · no spray

EyeWitness

Reporting Tools

man eyewitness(1)

Free HTTP title · Pro HTTP title · status

Lynis

Blue Team

man lynis(8)

Free Header / TLS checklist · Pro Full hardening analog

p0f

Blue Team

man p0f(1)

Free OS / Server header · Pro Passive fingerprint

Maltego CE

Blue Team

man maltego(1)

Free DNS + IP graph · Pro Emails, RDAP, related hosts

Sherlock

Blue Team

man sherlock(1)

Free · Pro Usernames from harvested emails

Zeek

Blue Team

man zeek(8)

Free conn.log from ports · Pro http.log + dns.log

osquery

Blue Team

man osqueryi(1)

Free listening_ports · Pro certificates table

Sigma

Blue Team

man sigma(1)

Free · Pro YAML detections from findings

Legion

Blue Team

man legion(1)

Free Port table · Pro Version / OS columns

checkdmarc

Blue Team

man checkdmarc(1)

Free MX / SPF / DMARC if published · Pro DKIM, BIMI, MTA-STS, AXFR

oauth2c

Blue Team

man oauth2c(1)

Free · Pro OIDC discovery + RFC 9700 checks

OpenSCAP

Blue Team

man oscap(8)

Free High-level grade · Pro CIS / NIST / PCI / CISA OVAL

MISP

Blue Team

man misp(1)

Free IP / domain attributes · Pro CVE + ATT&CK + ASN event

ntopng

Blue Team

man ntopng(8)

Free Ping RTT · Pro Hop path + listener latency

CrowdSec

Blue Team

man cscli(1)

Free Hosting/proxy clue · Pro Decisions from WAN listeners

TheHive

Blue Team

man thehive(1)

Free · Pro Cases from NVTs + ATT&CK

Censys

Blue Team

man censys(1)

Free IP + ASN · Pro Cert, CAA, days-to-expiry, listeners

Kali Cloud Desktop

Blue Team

man kali-cloud(8)

Free · Pro Alpha: DigitalOcean Kali 2026.2 + Java VNC GUI

sqlmap

Database Assessment

man sqlmap(1)

Free Documented only · Pro Documented only

Off lattice

Metasploit

Exploitation Tools

man msfconsole(1)

Free Documented only · Pro Documented only

Off lattice

Hydra / Medusa / Patator

Password Attacks

man hydra(1)

Free Documented only · Pro Documented only

Off lattice

John / Hashcat

Password Attacks

man john(1)

Free Documented only · Pro Documented only

Off lattice

Aircrack-ng / Reaver

Wireless Attacks

man aircrack-ng(1)

Free Documented only · Pro Documented only

Off lattice

Ettercap / Bettercap

Sniffing & Spoofing

man ettercap(8)

Free Documented only · Pro Documented only

Off lattice

BeEF

Post Exploitation

man beef(1)

Free Documented only · Pro Documented only

Off lattice

Ghidra / radare2

Reverse Engineering

man ghidraRun(1)

Free Documented only · Pro Documented only

Off lattice

Slowloris / siege / t50

Stress Testing

man slowhttptest(1)

Free Documented only · Pro Documented only

Off lattice

Autopsy / binwalk

Forensics

man autopsy(1)

Free Documented only · Pro Documented only

Off lattice

AnonSurf

Privacy

man anonsurf(8)

Free Documented only · Pro Documented only

Off lattice

OnionShare

Privacy

man onionshare(1)

Free Documented only · Pro Documented only

Off lattice

I2P

Privacy

man i2prouter(1)

Free Documented only · Pro Documented only

Off lattice

macchanger

Privacy

man macchanger(1)

Free Documented only · Pro Documented only

Off lattice

VeraCrypt

Privacy

man veracrypt(1)

Free Documented only · Pro Documented only

Off lattice

airgeddon

Wireless Attacks

man airgeddon(1)

Free Documented only · Pro Documented only

Off lattice

Wifiphisher

Wireless Attacks

man wifiphisher(1)

Free Documented only · Pro Documented only

Off lattice

Cutter / rizin

Reverse Engineering

man cutter(1)

Free Documented only · Pro Documented only

Off lattice

Sliver C2

Post Exploitation

man sliver-server(1)

Free Documented only · Pro Documented only

Off lattice

Armitage

Exploitation Tools

man armitage(1)

Free Documented only · Pro Documented only

Off lattice

Payment processor

PayPal

PayPal, cards, and Apple Pay. Monthly Professional Subscription or Annual Professional Subscription — both auto-renew on PayPal.

Same Pro seat either way. Choose a cadence on your account page after you sign in.