Discover a domain's subdomains, see which are alive, where they're hosted, what they run, and which look like Shadow IT โ then get fix recommendations. No API keys. No sign-ups. One Windows app, click and run.
โฌ๏ธ Download ยท โจ Features ยท ๐ Usage ยท โ๏ธ How it works ยท
Important
Educational & Defensive Security Research Disclaimer
This project is developed strictly for educational purposes, defensive security research, and authorized security auditing. The developer (@n0xnull) does not condone or support unauthorized testing or malicious use. Users are solely responsible for complying with all applicable local, national, and international laws. See DISCLAIMER.md for full terms.
๐ฎ๐ฉ Baca dalam Bahasa Indonesia
Fathom adalah aplikasi Windows desktop yang membantu tim keamanan memetakan permukaan serangan (attack surface) domain mereka โ gratis, tanpa API key.
Ketik sebuah domain, Fathom akan menemukan subdomain tersembunyi, memvalidasi mana yang aktif, mendeteksi teknologi yang berjalan, dan mengidentifikasi Shadow IT (subdomain terlupakan, panel admin terbuka, potensi subdomain takeover) โ lengkap dengan rekomendasi perbaikan dan skor risiko transparan.
Mode: Pasif (hanya sumber publik) dan Penuh/aktif (DNS brute force + HTTP probing). Output: Laporan HTML, JSON, dan CSV. Antarmuka & laporan bilingual ID/EN.
Scanning a domain: subdomain discovery, live validation, and per-asset findings.
Organizations lose track of what they expose on the internet. Forgotten
dev, staging, and old-api subdomains, dangling DNS records, and exposed
admin panels โ collectively Shadow IT โ are exactly what attackers look for
first. Professional discovery tools usually need paid API keys and a steep
learning curve.
Fathom maps a domain's external attack surface using only free, public sources and an offline database โ wrapped in a clean desktop app that anyone can run. Type a domain, get an actionable intelligence report. Like a sailor's sounding line measuring the depths before sailing further, Fathom measures how deep and how wide a domain's exposed footprint really goes.
- ๐ Subdomain discovery (no API key) โ Certificate Transparency (crt.sh), Wayback Machine, and DNS brute force.
- ๐งช Wildcard-aware โ detects wildcard DNS and filters out false positives.
- โก Active host validation โ alive/dead with precise statuses (timeout, TLS error, refused), status code, server, and page title.
- ๐ Offline geolocation & ASN โ country/city/org per IP, no network call.
- ๐งฌ Technology fingerprinting โ WordPress, Next.js, Laravel, Nginx, Cloudflare, and more.
- ๐ต๏ธ Shadow IT, exposed-panel & subdomain-takeover detection with fix recommendations.
- ๐ Transparent risk score โ every point is explained.
- ๐ Bilingual โ full Indonesian / English UI and reports.
- ๐ Reports โ self-contained HTML, JSON, and CSV; reopen saved scans.
- ๐จ Modern GUI โ dark/light themes, sortable/filterable table, helpful hints on every menu.
- ๐ป Single
.exeโ install nothing else.
| Minimum | |
|---|---|
| OS | Windows 10 or 11, 64-bit (Qt 6 dropped Windows 7/8) |
| RAM | 2 GB |
| Disk | ~150 MB free |
| Network | Internet connection for online sources (the app itself needs no install) |
Cross-platform note: the code also runs on Linux/macOS from source (
python main.py), but official binaries are Windows-only for now.
Two options โ pick whichever suits you:
- Go to Releases.
- Installer โ download
FathomSetup.exe, run it, get a Start Menu shortcut and a proper uninstaller. (Recommended for most people.) - Portable โ download
Fathom.exeand double-click to run, no installation needed. Good for USB sticks / no-admin environments.
First launch on Windows may show SmartScreen ("Windows protected your PC") because the
.exeis not yet code-signed. Click More info โ Run anyway. You can verify integrity with the published*.sha256.txtchecksum.
git clone https://github.com/n0xnull/Fathom.git
cd Fathom
python -m venv .venv && .venv\Scripts\activate # Windows
pip install -r requirements.txt
python main.py# Windows, one click:
build.bat
# or manually:
pip install -r requirements-dev.txt
pyinstaller fathom.spec --noconfirm
# -> dist\Fathom.exe# Requires Inno Setup 6 (https://jrsoftware.org/isdl.php)
installer\build-installer.bat
# -> installer\Output\FathomSetup.exe- Type a domain (e.g.
example.com) in the input box. - Pick a mode:
- Passive (safe) โ public sources only; never touches the target server.
- Full (active) โ adds DNS brute force + HTTP/HTTPS probing; asks you to confirm you're authorized.
- Click Start Scan. Watch progress + live log; Cancel any time.
- Browse the subdomain table (sort/filter), click a row for details.
- Review Shadow IT / findings and recommendations.
- Export an HTML report, JSON, or CSV โ each export is saved with a unique
Fathom_[domain]_[timestamp]filename, so nothing gets overwritten. Saved scans can be reopened later.
Every menu item also shows a hint in the status bar when you hover it.
| Menu | What it does |
|---|---|
| File โธ New Scan | Clear results and start a fresh domain. |
| File โธ Open Result | Reopen a previously saved .json scan. |
| File โธ Save Result | Save the full scan to reopen later. |
| File โธ Export | HTML report (share/print), JSON (automation), CSV (Excel). |
| Scan โธ Start / Cancel | Run or stop a scan. |
| Scan โธ Mode | Switch between Passive (safe) and Full (active). |
| View โธ Theme | Toggle dark/light. |
| View โธ Language | Indonesian / English (also top-right). |
| Help โธ Docs / Disclaimer / Updates / About | Guide, terms, latest version, credits. |
python -m fathom.cli example.com --mode passive --lang en --format allinput domain
โ apex intel (DNS records, SPF/DMARC, RDAP, TLS)
โ wildcard guard
โ enumeration (crt.sh + Wayback + brute force[Full])
โ DNS resolve โ active probe[Full]
โ GeoIP/ASN (offline) โ fingerprint + TLS
โ Shadow IT / takeover / posture analysis
โ transparent risk score
โ report (HTML / JSON / CSV)
Free, no-key data sources: Certificate Transparency (crt.sh), Wayback Machine
CDX, live DNS, RDAP, direct TLS handshakes, and an offline GeoIP database
(DB-IP Lite / GeoLite2 โ see fathom/data/geoip/README.md).
Honest note: without paid intelligence APIs, subdomain coverage is smaller than tools like Amass + Shodan. In exchange, Fathom is offline-friendly, dependency-free for the user, and ideal as a trusted internal tool.
- v1.1 โ Wayback link mining, HTML/JS crawling, AXFR, richer TLS analysis. โ (unique export filenames + installer)
- v1.2 โ reverse DNS, PDF reports, expanded takeover signatures.
- v2.0 โ multi-domain view, scan history & diffing, scheduling.
Issues and PRs welcome. Add a new subdomain source by subclassing BaseSource
and registering it in sources/registry.py โ the engine needs no other change.
MIT ยฉ Abil Khosim. GeoIP data is provided under its respective license (DB-IP: CC-BY / MaxMind: GeoLite2 EULA).
Cybersecurity Specialist
Fathom is an original project by Abil Khosim, an independent security tool by Abil Khosim (NoxNull). Released under the MIT License โ ยฉ 2026 Abil Khosim. Please keep this attribution when reusing or redistributing.
Know your depth before you're in over your head. ๐


