PhonePe / PhonePe/mantis

New Subdomain, Login Page, and Path Detection Feature

Open
#96 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
1k
Forks
136
PR merge metrics
No merged PRs in 30d

Description

Overall, this tool is very good. I just have a few suggestions. For example, let's say I work for a corporate company.

In general, monitoring an organization's IP address and subdomains is important. Subdomains should be identified using tools that track both subdomains via reverse IP and regular subdomain tracking. It's crucial to detect and alert about new login pages and paths belonging to the organization. Furthermore, it's important to scan newly emerging valid subdomains for vulnerabilities using tools like Nuclei and report any new vulnerabilities. Could you add this feature to the tool? This feature would be truly useful.
This company has its own root domains and public subnet IP addresses. Could the tool be modified to constantly monitor the company's subdomains, reverse IPs, etc., and alert and record/notify when a new subdomain, a new directory within an existing directory, or a new login page is detected? This suggestion could also track bug bounty coverage, automatically scanning for vulnerabilities and reporting them when a new development occurs. It would be good if the tool were developed to use tools like GAU and Waybackmachine for web URLs, recording previous scan results and notifying when a new change occurs, including new subdomains/directories and login pages.

https://github.com/killua889/subdomain-monitor
https://github.com/xalgord/reconx

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No files, tests, or entry points are identified in the issue. Start by reviewing Mantis's existing discovery, reconnaissance, and vulnerability-scanning workflow, then compare the requested subdomain, reverse-IP, URL-history, login-page, path, alerting, and Nuclei/GAU/Wayback Machine behavior with its current scope. Done would require an agreed, testable specification for monitoring, change detection, notifications, historical results, and vulnerability scanning.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.