Attack surface
Open Port Scanning
Every port your server exposes is an invitation for someone to try the handle. The trouble is rarely the ports you opened deliberately — it's the one opened during a deployment and never closed. Specula maps what your server exposes to the internet and compares it against what you said to expect.
Compared against an expected list
80 and 443 being open is normal. You define the expected set so that 8080 appearing overnight can be told apart from business as usual.
Service fingerprinting
It doesn't just report an open port; it identifies the service and version behind it. An old version matching a known CVE raises the alert.
Change-triggered alerts
The port map is diffed on every scan. A newly opened port is reported as quickly as a service that disappeared.
1 unexpected port · 8080 · opened at 09:41
Other features
Run this check on your own domain.
Add a domain and Specula finishes the first scan within minutes. No credit card needed.