Specula
All features

Attack surface

Open Port Scanning

Every port your server exposes is an invitation for someone to try the handle. The trouble is rarely the ports you opened deliberately — it's the one opened during a deployment and never closed. Specula maps what your server exposes to the internet and compares it against what you said to expect.

  • Compared against an expected list

    80 and 443 being open is normal. You define the expected set so that 8080 appearing overnight can be told apart from business as usual.

  • Service fingerprinting

    It doesn't just report an open port; it identifies the service and version behind it. An old version matching a known CVE raises the alert.

  • Change-triggered alerts

    The port map is diffed on every scan. A newly opened port is reported as quickly as a service that disappeared.

port scan185.12.4.9
80http · nginxexpected
443https · nginxexpected
8080http-alt · unknownunexpected
22sshclosed

1 unexpected port · 8080 · opened at 09:41

Other features

Run this check on your own domain.

Add a domain and Specula finishes the first scan within minutes. No credit card needed.