FullHunt supports defensive attack-surface and intelligence workflows. Your organization remains responsible for authorization, data handling, and downstream actions.

Active scanning

Use scan routes only for assets you own or are explicitly authorized to test.
  • Maintain an allowlist outside FullHunt.
  • Validate domains, hosts, public IPs, and CIDR ranges against approved scope.
  • Require explicit confirmation before an agent or automation triggers a scan.
  • Record the requester, target, purpose, and authorization reference.
  • Apply time, request, credit, and polling limits.
  • Stop immediately when authorization changes.
Reserved documentation domains and IP ranges illustrate syntax. They are not FullHunt scan targets.

Passive intelligence

Passive records can still be sensitive or incomplete. Do not publish named third-party exposures without validation and a responsible disclosure process. Treat ownership and attribution fields as evidence requiring corroboration.

Credentials and dark-web data

  • Restrict access to staff with an incident-response need.
  • Redact passwords and unrelated personal fields from logs, tickets, and reports.
  • Do not use exposed credentials to access an account or system.
  • Define retention, deletion, and breach-response requirements before collection.
  • Store only the fields needed for investigation and notification.

Automated decisions

Do not use a model-generated conclusion, suggested domain, Tor observation, or shared-infrastructure relationship as the sole basis for blocking, takedown, or public attribution. Preserve the evidence and require human review for high-impact actions.

Reporting security issues

Use FullHunt support for product or data issues. Do not include API keys, raw passwords, or unnecessary personal data in a support request.