vulns.co
/
GKData.io MCP

Back to Playbooks

Scaling: Automation & Monitoring

Move from one-off scans to continuous coverage that pings you when a target's attack surface changes.

Tags: automation, monitoring, pipelines

Level: advanced

Method

  1. Make recon idempotent

    Persist per-target state and only surface deltas, so re-runs are cheap and new assets stand out.

    subfinder -d target.com -all -silent | dnsx -silent | anew hosts.txt | httpx -silent | notify

    Tools: anew, subfinder, dnsx, httpx

  2. Diff over time

    Schedule recon; when anew emits new subdomains/URLs/JS, trigger a focused nuclei pass on just the new assets.

    nuclei -l new-hosts.txt -severity critical,high -silent | notify -bulk

    Tools: nuclei, notify

  3. Watch JS & content

    Re-crawl and hash JS; alert on changed bundles (new endpoints/secrets) and newly appearing paths.

    Tools: katana, jsluice

  4. Alert, don't drown

    Route only high-signal events (new host, new critical, changed JS) to Slack/Discord. Noise kills automation.

    Tools: notify

Field notes

  • Continuous monitoring beats deep one-time scans for bounty ROI - you catch new deploys first.
  • Keep resolver lists and templates fresh via cron or the signal quality decays.

References