Panthera(P.)uncia
Official CLI utility for Subdomain Center & Exploit Observer
Puncia is the official command-line client for two A.R.P. Syndicate intelligence APIs — point it at a domain, a brand, or a vulnerability ID and get structured JSON back in seconds, no browser required:
- 🕸️ Subdomain Center — subdomain enumeration, subdomain takeover surfacing, shadow IT discovery, and brand impersonation / lookalike-domain (typosquat) detection at internet scale.
- 💥 Exploit Observer — exploit & vulnerability intelligence across 150+ identifier schemes (CVE, GHSA, EDB, MSF, ZDI, nation-state feeds and more), with CVE/GHSA enrichment (EPSS + VEDAS maturity scoring) and SBOM scanning.
$ puncia subdomain arpsyndicate.io
╭──────────────────────────────────────────────────────────────────────╮
│ Panthera(P.)uncia v0.40 │
│ subdomain recon · brand impersonation · exploit intel · sbom analysis│
│ A.R.P. Syndicate — https://www.arpsyndicate.io │
╰──────────────────────────────────────────────────────────────────────╯
[
"advisories.arpsyndicate.io",
"asm.arpsyndicate.io",
"blog.arpsyndicate.io",
...
]
$ puncia sbom bom.json ./out
puncia ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% (128/128) 0:00:41
Please note that although these results can sometimes be pretty inaccurate & unreliable, they can greatly differ from time to time due to their self-improvement capabilities.
Aggressive rate-limits can be avoided with an API key: https://www.arpsyndicate.io/pricing.html
Practical Applications
- Brand Impersonation & Phishing Domain Detection
Surface replica, lookalike, and typosquat domains riding on your brand before they're used against you or your customers.
- Shadow IT & External Attack Surface Discovery
Identify and monitor exposed subdomains and infrastructure spun up outside official channels.
- Subdomain Takeover Reconnaissance
Enumerate the full subdomain footprint of a target, a key first step in spotting dangling/takeover-prone records.
- Advanced Vulnerability Research & Monitoring
Discover and track known and emerging threats, including obscure or unlisted vulnerabilities.
- Contextual Enrichment of CVE/GHSA Data
Add depth and actionable intelligence (EPSS + VEDAS maturity scores) to known vulnerabilities for better prioritization.
- Vulnerability Detection in Software Bill of Materials (SBOM)
Analyze software components for known exploits and security issues using structured SBOM data.
- Seamless Integration with CI/CD & Threat Intel Workflows
Automate intelligence gathering and vulnerability checks within development or security pipelines.
- Monitoring Nation-State Exploit Trends
Stay ahead of threats by tracking vulnerabilities flagged by foreign actors but not yet recognized by mainstream databases.
- Keyword-Based Subdomain Discovery
Surface hosts carrying a given keyword across the internet, independent of a specific parent domain.
- Bulk Threat Intelligence Processing
Run batch queries (domains, vulnerabilities, etc.) for scalable analysis across large datasets or enterprise asset inventories.
- Passive Reconnaissance for Red Teams
Conduct stealthy reconnaissance by using passive data sources (no direct interaction with targets).
- Open Source Intelligence (OSINT) Collection
Combine subdomain and exploit intelligence to enhance OSINT investigations.
- Compliance & Risk Management Support
Enrich vulnerability data to support compliance audits (e.g., ISO 27001, SOC 2) with deeper context.
Installation
- From PyPi -
pip3 install puncia
- From Source -
pip3 install .
30-second Quickstart
pip3 install puncia
# subdomain footprint of a target (shadow IT / attack surface / takeover recon)
puncia subdomain example.com
# lookalike / typosquat / brand-impersonation domains
puncia replica example.com
# what's known about a CVE
puncia exploit CVE-2021-44228
Usage
puncia <mode> <query> [output] [--match M] [--domain D] [--limit N] [--offset N]
[--crawl] [--filter KEY=VALUE] [--format json|csv]
[--api-key K] [--concurrency N]
[--timeout S] [--retries N] [--quiet]
Run puncia --help for the full reference. Results are printed to stdout; the
banner, progress bars, warnings and errors all go to stderr, so
puncia subdomain example.com > out.json always yields clean, valid JSON.
Exit codes: 0 success · 1 request or input error · 2 usage error.