Know what’s out there.
A connected picture of your domains, applications, and external assets. Built to bring scattered signals into one place.
sudor.io is building an autonomous pentesting and attack surface management platform to help teams find exposed assets, understand security risks, and decide what to fix.
Platform in development. 38 free security tools available now.Designed for security teams assessing internet-facing domains, cloud infrastructure, and applications.
A connected picture of your domains, applications, and external assets. Built to bring scattered signals into one place.
AI-assisted analysis designed to connect findings with the systems and business priorities that matter.
Clear evidence and practical guidance, designed to help security teams decide what deserves attention next.
Platform direction, not a list of released capabilities. Follow the journey through the waitlist.
From a quick DNS check to decoding a token. Practical utilities for the work between the big investigations.
Inspect the public DNS records behind a domain.
Read the domain’s published sender policy.
Read a published vulnerability record by its CVE identifier.
Inspect a JWT header and payload without sending the token.
Calculate a SHA-256 digest locally in your browser.
Calculate network, broadcast, mask and address ranges.
Whether you’re protecting your own business or helping someone protect theirs.
Bring clarity to external exposure and spend more time understanding what matters.
Use everyday research utilities and follow a platform being built around practical assessments.
Understand the security signals behind the products and infrastructure you’re building.
Security research, practical write-ups, and ideas behind sudor.io. Published on Medium, shared here.
Every phone has a modem buried inside it, the chip that handles calls, SMS, and cellular data. That modem doesn’t understand Android or iOS. It understands AT commands, a…
RESEARCH / SUDOR.IOThree days. That’s how long it took me to get Burp Suite seeing traffic from a Flutter app during a security assessment.
RESEARCH / SUDOR.IOEveryone is talking about AI agents like they’re a productivity story. Automate your inbox. Summarize your Slack threads. Let the agent browse the web for you while you sleep.
sudor.io is an AI cybersecurity platform in development, focused on helping teams understand their external attack surface, connect security findings to business context, and act with clarity.
The full platform is not publicly available yet. Join the waitlist for early-access updates. Our public security utilities are available now without an account.
Yes. The current utilities run in your browser or query free public data sources. No subscription or payment is required. Public providers may have availability and rate limits.
No active scanners are included. Local utilities process the text you provide. DNS lookups use a public resolver, and CVE lookups retrieve published records. The certificate tool opens public certificate logs.
Local tools do not upload your input. Public lookups send the query to the provider named on the tool page. Waitlist details go to our Google-hosted signup service. See our privacy notes for the specifics.
Our original articles and write-ups are published on Medium. The Research page links to those stories, where you can read free articles or access member-only stories with the appropriate Medium membership.
Help shape a clearer approach to cybersecurity.
Join the sudor.io early-access waitlist.