# michenriksen/aquatone

A Tool for Domain Flyovers

Repository: https://github.com/michenriksen/aquatone
Canonical: https://ross.abutalabs.com/products/aquatone
Homepage: https://michenriksen.com/blog/aquatone-now-in-go/
Language: Go
License: MIT
License Family: permissive
Topics: security, osint, golang, chrome-headless, reconnaissance, chromium
Archived: true
Last push: 2022-05-22T19:49:32+00:00

## Health v2 (maintenance only)
Score: 10/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 3940, "days_push": 1564, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: archived
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 5961, forks 903 (observed 2026-08-28T04:09:33.759293+00:00)

## What it is
Aquatone is a Go CLI tool for visual inspection of websites across many hosts, taking screenshots via headless Chrome/Chromium and generating an HTML report of the HTTP-based attack surface. It accepts piped input from any host discovery tool, extracting URLs, domains, and IPs automatically.

## Use cases
- take screenshots of many subdomains at once
- visualize the HTTP attack surface of a domain
- generate an HTML report of discovered web services
- pipe nmap or masscan output into a screenshot tool
- reconnaissance during a penetration test
- find web services on non-standard ports across hosts

## When to choose
- you need a quick visual overview of many web hosts during recon
- you want to integrate with existing discovery tools via piped input
- you need automated port scanning for common web ports plus screenshots

## When to avoid
- you need actively maintained tooling - the latest release is from 2022
- you need deep vulnerability scanning rather than visual reconnaissance
- you cannot install Chrome/Chromium in your environment

## Facets
- artifact type: cli-tool
- maturity: maintenance
- function: osint, security, web-scraping, http-client, cli
- domain: security, osint, penetration-testing, developer-tools
- platform: windows, cli, go
- tags: reconnaissance, screenshot-capture, attack-surface, headless-chrome, subdomain-enumeration, html-report, linux, macos

## Member repositories
- michenriksen/aquatone (main) score 10

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:09:33.759293+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:50:24.479981+00:00, confidence not recorded.
  - readme: https://github.com/michenriksen/aquatone (fetched 2026-08-28T04:09:33.759293+00:00, sha a14fb243d1bd)
  - homepage: https://michenriksen.com/blog/aquatone-now-in-go/ (fetched 2026-08-29T08:46:05.697513+00:00, sha 0312f7cd8047)
- Data as of 2026-08-30T08:39:29.467469+00:00.
