ScopeHunter

ScopeHunter · Tools

Default credential scanner

Check a domain you can prove you own for known default and compromised credential combinations — the ones attackers try first.

What it does

Shipped appliances, admin panels, and forgotten services often keep their factory logins — admin/admin, vendor defaults, credentials already exposed in public breaches. The scanner checks a domain against a small, curated set of those known combinations so you find them before someone else does.

Built so it can't be abused

  1. Prove you own the domain. You verify control with a DNS TXT record before any test runs — you can only scan domains you actually hold.
  2. Authorization is explicit. Verification attests you're authorized to security-test the target, not merely that you control its DNS.
  3. Testing is conservative. A small curated credential set, and a scan stops on first success rather than hammering the service.
  4. Results are private. Findings are yours; the domain itself is stored encrypted, and ownership is re-verified over time since domains change hands.
This is an authorized-testing tool for domains you own or are cleared to test — not a way to probe third parties. Unauthorized credential testing is out of scope and against the acceptable-use policy.

Where it fits

The scanner is one of ScopeHunter's practitioner tools, alongside a live CISA KEV / NVD / HIBP security bulletin feed and the compliance workspace for CMMC 2.0, SOC 2, and ISO 27001. Default-credential exposure maps directly to access-control and authentication requirements in each of those frameworks.

Sign in to run a scan → Compliance & security FAQ

See also: automating CMMC 2.0 hardening · FAQ · security policy · privacy policy · ScopeHunter home.

ScopeHunter is built and operated by L-IT Technical Solutions, a Texas IT consultancy — the same people who run the CMMC automation described here against their own production infrastructure.