Restricted Preview
nmap…
masscan…
httpx…
nuclei…
subfinder…
dnsx…
Defender…
MODE
▶ Start here
1Connect Microsoft
2Add targets
3Scan
🔹 Targets
0 hosts
Quick add: public
Expand attack surface
Add known targets, or discover public infrastructure you have not listed yet.
Paste
Upload File
Domain
Azure by name
Uses subfinder (passive subdomain enum) + dnsx (DNS resolution). Results are listed for review — nothing joins your target list until you add it. See Quick Setup Guide to install.
Enter a company, product, application or project name.
Unauthenticated, external check for public Azure namespaces (blob storage, web apps, SQL, Key Vault, …) built from your keyword. Flags publicly listable blob containers (data exposure). No credentials used — the attacker's-eye view.
Microsoft
Azure
Entra
Defender
Cloud Apps
Permissions & admin consent → Quick Setup Guide ↗
Azure
Defender
★ Endpoint is the key selection. Sightline uses Defender EDR to determine which exposed hosts are covered, which are blind spots, and who owns the device behind an attack path.
Without Endpoint, Sightline can identify exposure but cannot assess EDR coverage.
Entra
Cloud Apps portal URL — required for Cloud Apps · where to find it ↗
Register redirect URI: http://localhost:5000
API permission: Azure Service Management → user_impersonation
API permission: Microsoft Graph → Policy.Read.All (Delegated)
Filters: Location Type = IP ranges · Trusted = Yes
Uses your app registration + the Cloud Apps API permission — no token to paste. Prototype: verifying delegated read access.
— or paste a static API token —
Cloud Apps portal → Settings → Cloud apps → API tokens → + Add token
Fetches: Type = Custom · Category = Corporate
Register redirect URI: http://localhost:5000
API permissions: WindowsDefenderATP → Machine.Read + AdvancedQuery.Read + Vulnerability.Read (Delegated)
Optional (Entra roles on the device card): Microsoft Threat Protection → AdvancedHunting.Read + Microsoft Graph → RoleManagement.Read.Directory (active + PIM-eligible, Delegated)
Admin consent required · Can reuse same registration as Azure tab
Scan origin
Blue16 Sightline
Microsoft-sourced CTEM
Scanning from
Locating…
Detecting the address this scanner leaves from…
Add targets on the left to begin →
🔹 Recent Scans
Loading…