A.R.P. Syndicate ARPSyndicate

Creators of the world's largest
Subdomain & Exploit Database

Automated Reconnaissance & Pwning Syndicate

An Internet Intelligence Company. We operate the world's largest subdomain and exploit intelligence databases, and build enterprise risk, national security and consumer security products on top of them — plus offensive security services delivered directly by our team.

Products & Services

Data Intelligence API

Subdomain Center

Shadow IT & Subdomain Intelligence Database

Freemium API $100/month

Exploit Observer

Vulnerability & Exploit Intelligence Database

Freemium API $200/month

Enterprise & National Security Platform

Kenzer

Vulnerability Management & Risk Scoring Platform — TPRM, EASM, CTEM

Enterprise From $5k/year

Osprey Vision

Face & Object Clustering for CCTV and Drone Feeds

Enterprise From $5k/year

Consumer Security

EncryptLayer

Android Anti-Stalkerware, Spyware & Banking-Trojan Firewall

Coming soon

Offensive Security Services

Red Teaming & VAPT

Red Teaming, VAPT and adversarial simulation, run by the same team that builds our intelligence products.

Engagement-based

What we build

A.R.P. Syndicate builds and operates internet-scale intelligence datasets. Rather than reselling another vendor's feed, we run our own discovery infrastructure and publish the results through APIs that are free to query and priced flatly when you need them at scale.

Subdomain & Shadow IT Intelligence

Subdomain Center maps hosts across more than a billion registered domains. Discovery does not rely on DNS brute force — it combines web-scale crawling, real-time Certificate Transparency ingestion and embedding-based host correlation, which surfaces infrastructure that wordlists and certificate logs alone do not reach, including hosts sitting behind a reverse proxy.

In an independent benchmark, it returned more than twice as many valid subdomains as the next-best free source. The dataset is integrated into BBOT, theHarvester and OWASP Amass.

Vulnerability & Exploit Intelligence

Exploit Observer resolves the identifier sprawl around vulnerabilities. A single real-world flaw typically accumulates a CVE number, a GHSA advisory, vendor bulletins, exploit modules and entries in national registries — all describing the same thing. Our VEDAS system clusters them under one identifier, so a single lookup returns the complete picture rather than one fragment of it.

Coverage deliberately extends past the English-language advisory ecosystem to include CNNVD, CNVD, BDU (Russian FSTEC), JVNDB and EUVD — registries that publish independently of MITRE and that most Western vulnerability feeds omit entirely.

Vulnerability Management & Risk Scoring Platform

Kenzer is our vulnerability management and risk scoring platform, built on the same subdomain and exploit intelligence powering the two products above. It covers third-party risk management (TPRM), external attack surface management (EASM), continuous threat exposure management (CTEM), cyber insurance underwriting, and sovereign threat intelligence for CERTs and defense agencies — continuous reconnaissance in place of point-in-time surveys.

Physical Security Intelligence

Osprey Vision applies the same reconnaissance discipline to physical security: it ingests CCTV and drone feeds over a secure encrypted tunnel and clusters faces and objects in the cloud, with on-prem deployment available for sensitive environments. Faces are grouped by similarity, not identified, unless you supply your own reference set.

Consumer Device Security

EncryptLayer (ENCLAY) is an on-device Android firewall that blocks stalkerware, spyware, banking trojans, cryptomining and infostealer malware by IP, domain and TLS fingerprint, and detects tampering with the app itself — no root, no account, no cloud. It is currently in development and not yet publicly launched.

Offensive Security Services

Beyond our own products, we run Red Teaming, VAPT (vulnerability assessment and penetration testing) and similar offensive security engagements — the same reconnaissance and exploit intelligence behind Exploit Observer and Kenzer, applied directly against your environment by our team.

How access works

Both Subdomain Center and Exploit Observer are free to query with no account and no key, subject to result caps and rate limits. Paid keys remove those limits rather than unlocking different data — you can evaluate the full quality of either dataset before speaking to anyone. Both are queryable from the command line via puncia, our open-source CLI. Kenzer and Osprey Vision are enterprise products sold directly; register your interest below and our team will follow up.

Express your interest

Our team will reach out with more information.