ScopeHunter · Tools
Default credential scanner
Check a domain you can prove you own for known default and compromised credential combinations — the ones attackers try first.
What it does
Shipped appliances, admin panels, and forgotten services often keep their factory logins — admin/admin, vendor defaults, credentials already exposed in public breaches. The scanner checks a domain against a small, curated set of those known combinations so you find them before someone else does.
Built so it can't be abused
- Prove you own the domain. You verify control with a DNS TXT record before any test runs — you can only scan domains you actually hold.
- Authorization is explicit. Verification attests you're authorized to security-test the target, not merely that you control its DNS.
- Testing is conservative. A small curated credential set, and a scan stops on first success rather than hammering the service.
- Results are private. Findings are yours; the domain itself is stored encrypted, and ownership is re-verified over time since domains change hands.
Where it fits
The scanner is one of ScopeHunter's practitioner tools, alongside a live CISA KEV / NVD / HIBP security bulletin feed and the compliance workspace for CMMC 2.0, SOC 2, and ISO 27001. Default-credential exposure maps directly to access-control and authentication requirements in each of those frameworks.
See also: automating CMMC 2.0 hardening · FAQ · security policy · privacy policy · ScopeHunter home.