Pentest Scope Checker
Check a proposed target list against explicit inclusion and exclusion rules before an engagement. Compare IPv4, IPv6, networks and domains with interval arithmetic, without expanding networks or performing DNS lookups.
About Scope checkerFeatures & how to use
Compare targets against IP, CIDR and domain scope lists locally. Apply exclusions, detect partial coverage and export only fully included targets.
What it can do
- Accept IPs, CIDRs, domains and HTTP(S) URL targets, plus exact or leading-wildcard domain rules.
- Exclusions always take precedence. Partially covered or partially excluded networks are identified and never exported as fully included.
- Normalize targets, identify duplicates and flag redundant rules. Each list supports up to 25,000 records.
- Wildcards match subdomains, not the parent domain. URL paths and ports are not scope rules, and matching a list does not establish authorization to test.
How to use it
- Paste targets and the engagement's explicit inclusion and exclusion lists.
- Choose Check scope and review invalid, partial, duplicate and excluded entries.
- Copy fully included targets or export a CSV of the comparison, then confirm written authorization.