Research your pentest targets and save the evidence.
Search hosts, DNS records, certificates and WHOIS for the targets in your pentest scope. Save the relevant records and your notes in a client engagement for colleagues to review.

Steps
Start from an agreed scope
Create a client, then an engagement with the domains covered by the agreed scope. Search those domains across hosts, DNS, certificates and WHOIS. Use the organization discovery tool to investigate additional names, then validate their relevance against the agreed scope.
Inspect connected infrastructure
Use Pivot to inspect links through DNS, certificates, tracking identifiers or favicons. Compare candidate domains and open the underlying records before treating a connection as meaningful. Separate exact observations from your interpretation.
Prepare the client report
Save useful records in an engagement, add notes and prepare a report version. Review it before publishing. Named client users can be granted access to the relevant client and given a credit allowance for their own research.
Example: investigate an unfamiliar hostname
A certificate search reveals api.example.com. Inspect its observed hosts and DNS answers, compare the connection with the client’s declared domains, then save the records supporting your conclusion. A matching favicon is a lead to review, not proof that a target is in scope.
san:"api.example.com"Data and service limitations
Search results do not confirm a vulnerability or authorize testing a target outside the agreed scope. Dataset coverage and observation dates vary; verify the current state before acting.
Practical questions
Is this an automated pentesting service?
No. The tool supports reconnaissance, collaboration and reporting. Testing and validation remain the responsibility of your team.
Can a solo consultant use Profundis?
Yes. Individual plans support professional research. Organization plans add clients, engagements, access management, client accounts and shared billing.
Tools and documentation
Related guides
Monitor changes across your company’s domains.
Organize company domains by scope, monitor observed DNS, hosts and certificates, review changes and prepare recurring reports with your security team.
MSSPs and recurring client servicesManage monitoring and reports for each client.
Keep research separate for each client, assign credit allowances and review scheduled infrastructure changes with reports and delivery diagnostics.
Security engineering and automation teamsQuery Profundis through the API and MCP.
Connect infrastructure research to your tools with the Profundis API and MCP server. Use scoped organization credentials, credit limits and signed webhooks.