Skip to content
n0xnullPublic

About

๐ŸŒŠ Fathom โ€” Attack Surface Intelligence, Made Simple. Discover subdomains, uncover Shadow IT, fingerprint technologies, and prioritize your external attack surfaceโ€”no API keys required.

Topics

Resources

Security policy

Stars

1 star

Watchers

0 watching

Forks

Latest commit

ย 

History

15 Commits

Folders and files

Repository files navigation

Fathom

๐ŸŒŠ Fathom

Attack Surface Intelligence Engine โ€” reveal everything exposed before attackers do.

Discover a domain's subdomains, see which are alive, where they're hosted, what they run, and which look like Shadow IT โ€” then get fix recommendations. No API keys. No sign-ups. One Windows app, click and run.

License: MIT Platform Python Build Release LinkedIn

โฌ‡๏ธ Download ยท โœจ Features ยท ๐Ÿ“– Usage ยท โš™๏ธ How it works ยท โš ๏ธ Disclaimer

Fathom

Important

Educational & Defensive Security Research Disclaimer
This project is developed strictly for educational purposes, defensive security research, and authorized security auditing. The developer (@n0xnull) does not condone or support unauthorized testing or malicious use. Users are solely responsible for complying with all applicable local, national, and international laws. See DISCLAIMER.md for full terms.

๐Ÿ‡ฎ๐Ÿ‡ฉ Baca dalam Bahasa Indonesia

Fathom โ€” Mesin Intelijen Attack Surface

Fathom adalah aplikasi Windows desktop yang membantu tim keamanan memetakan permukaan serangan (attack surface) domain mereka โ€” gratis, tanpa API key.

Ketik sebuah domain, Fathom akan menemukan subdomain tersembunyi, memvalidasi mana yang aktif, mendeteksi teknologi yang berjalan, dan mengidentifikasi Shadow IT (subdomain terlupakan, panel admin terbuka, potensi subdomain takeover) โ€” lengkap dengan rekomendasi perbaikan dan skor risiko transparan.

Mode: Pasif (hanya sumber publik) dan Penuh/aktif (DNS brute force + HTTP probing). Output: Laporan HTML, JSON, dan CSV. Antarmuka & laporan bilingual ID/EN.

โš ๏ธ Gunakan hanya pada domain milik Anda atau yang telah memberikan izin tertulis. Lihat DISCLAIMER.md.

๐ŸŽฌ Demo

Fathom in action

Scanning a domain: subdomain discovery, live validation, and per-asset findings.

โ–ถ๏ธ Watch the full walkthrough (85s, with audio) โ€” attached to the latest release.


๐Ÿงฉ The Problem

Organizations lose track of what they expose on the internet. Forgotten dev, staging, and old-api subdomains, dangling DNS records, and exposed admin panels โ€” collectively Shadow IT โ€” are exactly what attackers look for first. Professional discovery tools usually need paid API keys and a steep learning curve.

Fathom maps a domain's external attack surface using only free, public sources and an offline database โ€” wrapped in a clean desktop app that anyone can run. Type a domain, get an actionable intelligence report. Like a sailor's sounding line measuring the depths before sailing further, Fathom measures how deep and how wide a domain's exposed footprint really goes.

โœจ Key Features

  • ๐Ÿ” Subdomain discovery (no API key) โ€” Certificate Transparency (crt.sh), Wayback Machine, and DNS brute force.
  • ๐Ÿงช Wildcard-aware โ€” detects wildcard DNS and filters out false positives.
  • โšก Active host validation โ€” alive/dead with precise statuses (timeout, TLS error, refused), status code, server, and page title.
  • ๐ŸŒ Offline geolocation & ASN โ€” country/city/org per IP, no network call.
  • ๐Ÿงฌ Technology fingerprinting โ€” WordPress, Next.js, Laravel, Nginx, Cloudflare, and more.
  • ๐Ÿ•ต๏ธ Shadow IT, exposed-panel & subdomain-takeover detection with fix recommendations.
  • ๐Ÿ“Š Transparent risk score โ€” every point is explained.
  • ๐ŸŒ Bilingual โ€” full Indonesian / English UI and reports.
  • ๐Ÿ“ Reports โ€” self-contained HTML, JSON, and CSV; reopen saved scans.
  • ๐ŸŽจ Modern GUI โ€” dark/light themes, sortable/filterable table, helpful hints on every menu.
  • ๐Ÿ’ป Single .exe โ€” install nothing else.

๐Ÿ–ผ๏ธ Screenshots

Main window

Asset details & findings

HTML report

๐Ÿ’ป System Requirements

Minimum
OS Windows 10 or 11, 64-bit (Qt 6 dropped Windows 7/8)
RAM 2 GB
Disk ~150 MB free
Network Internet connection for online sources (the app itself needs no install)

Cross-platform note: the code also runs on Linux/macOS from source (python main.py), but official binaries are Windows-only for now.

โฌ‡๏ธ Installation

For users (recommended)

Two options โ€” pick whichever suits you:

  1. Go to Releases.
  2. Installer โ€” download FathomSetup.exe, run it, get a Start Menu shortcut and a proper uninstaller. (Recommended for most people.)
  3. Portable โ€” download Fathom.exe and double-click to run, no installation needed. Good for USB sticks / no-admin environments.

First launch on Windows may show SmartScreen ("Windows protected your PC") because the .exe is not yet code-signed. Click More info โ†’ Run anyway. You can verify integrity with the published *.sha256.txt checksum.

For developers (run from source)

git clone https://github.com/n0xnull/Fathom.git
cd Fathom
python -m venv .venv && .venv\Scripts\activate     # Windows
pip install -r requirements.txt
python main.py

Build the .exe yourself

# Windows, one click:
build.bat
# or manually:
pip install -r requirements-dev.txt
pyinstaller fathom.spec --noconfirm
# -> dist\Fathom.exe

Build the installer yourself

# Requires Inno Setup 6 (https://jrsoftware.org/isdl.php)
installer\build-installer.bat
# -> installer\Output\FathomSetup.exe

๐Ÿ“– How to Use

  1. Type a domain (e.g. example.com) in the input box.
  2. Pick a mode:
    • Passive (safe) โ€” public sources only; never touches the target server.
    • Full (active) โ€” adds DNS brute force + HTTP/HTTPS probing; asks you to confirm you're authorized.
  3. Click Start Scan. Watch progress + live log; Cancel any time.
  4. Browse the subdomain table (sort/filter), click a row for details.
  5. Review Shadow IT / findings and recommendations.
  6. Export an HTML report, JSON, or CSV โ€” each export is saved with a unique Fathom_[domain]_[timestamp] filename, so nothing gets overwritten. Saved scans can be reopened later.

What each menu does (beginner hints)

Every menu item also shows a hint in the status bar when you hover it.

Menu What it does
File โ–ธ New Scan Clear results and start a fresh domain.
File โ–ธ Open Result Reopen a previously saved .json scan.
File โ–ธ Save Result Save the full scan to reopen later.
File โ–ธ Export HTML report (share/print), JSON (automation), CSV (Excel).
Scan โ–ธ Start / Cancel Run or stop a scan.
Scan โ–ธ Mode Switch between Passive (safe) and Full (active).
View โ–ธ Theme Toggle dark/light.
View โ–ธ Language Indonesian / English (also top-right).
Help โ–ธ Docs / Disclaimer / Updates / About Guide, terms, latest version, credits.

Command line (optional)

python -m fathom.cli example.com --mode passive --lang en --format all

โš™๏ธ How it Works

input domain
  โ†’ apex intel (DNS records, SPF/DMARC, RDAP, TLS)
  โ†’ wildcard guard
  โ†’ enumeration (crt.sh + Wayback + brute force[Full])
  โ†’ DNS resolve  โ†’ active probe[Full]
  โ†’ GeoIP/ASN (offline)  โ†’ fingerprint + TLS
  โ†’ Shadow IT / takeover / posture analysis
  โ†’ transparent risk score
  โ†’ report (HTML / JSON / CSV)

Free, no-key data sources: Certificate Transparency (crt.sh), Wayback Machine CDX, live DNS, RDAP, direct TLS handshakes, and an offline GeoIP database (DB-IP Lite / GeoLite2 โ€” see fathom/data/geoip/README.md).

Honest note: without paid intelligence APIs, subdomain coverage is smaller than tools like Amass + Shodan. In exchange, Fathom is offline-friendly, dependency-free for the user, and ideal as a trusted internal tool.

๐Ÿ—บ๏ธ Roadmap

  • v1.1 โ€” Wayback link mining, HTML/JS crawling, AXFR, richer TLS analysis. โœ… (unique export filenames + installer)
  • v1.2 โ€” reverse DNS, PDF reports, expanded takeover signatures.
  • v2.0 โ€” multi-domain view, scan history & diffing, scheduling.

๐Ÿค Contributing

Issues and PRs welcome. Add a new subdomain source by subclassing BaseSource and registering it in sources/registry.py โ€” the engine needs no other change.

๐Ÿ“„ License

MIT ยฉ Abil Khosim. GeoIP data is provided under its respective license (DB-IP: CC-BY / MaxMind: GeoLite2 EULA).



๐Ÿ‘ค Developed by Abil Khosim

Cybersecurity Specialist

LinkedIn

Fathom is an original project by Abil Khosim, an independent security tool by Abil Khosim (NoxNull). Released under the MIT License โ€” ยฉ 2026 Abil Khosim. Please keep this attribution when reusing or redistributing.

Know your depth before you're in over your head. ๐ŸŒŠ

About

๐ŸŒŠ Fathom โ€” Attack Surface Intelligence, Made Simple. Discover subdomains, uncover Shadow IT, fingerprint technologies, and prioritize your external attack surfaceโ€”no API keys required.

Topics

Resources

Security policy

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages