Leakscope
An all-in-one Shodan & ZoomEye supported tool to search, browse, preview and dump data leakage across 20+ services. Pulls real exposure straight from the source.
Open the official app on gainsec.com
This tool is hosted by its maintainers. Click below to open gainsec.com in a new tab — it's their official demo.
Browse network tools →What's next with Leakscope?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is Leakscope?
Search, triage, preview, and dump exposed services and code leaks using Shodan and ZoomEye with a provider aware UI and database. Find data leaks, threat intelligence and other useful data exposed and accessible on the internet *without authentication or exploitation.* - Dual-provider discovery (Shodan + ZoomEye) with provider-specific dorks/templates and per-search provider selection. - Coverage: GitLab, Elasticsearch/OpenSearch, Kibana, Jenkins, Mongo/Mongo Express, Rsync, FTP, Cassandra, CouchDB, RethinkDB, S3 buckets (open + brute force), Angular apps, JS secrets, Grafana, Prometheus, MinIO, Swagger/OpenAPI, Nexus, Artifactory, Docker Registry/Harbor (auth-free), key patterns, etc. - Landing page shows env sanity (SHODAN/ZOOMEYE keys, blacklist), WAN/LAN I Source: GainSec/LeakScope (https://github.com/GainSec/LeakScope)
How it works
Repository: GainSec/LeakScope - Dual-provider discovery (Shodan + ZoomEye) with provider-specific dorks/templates and per-search provider selection. - Coverage: GitLab, Elasticsearch/OpenSearch, Kibana, Jenkins, Mongo/Mongo Express, Rsync, FTP, Cassandra, CouchDB, RethinkDB, S3 buckets (open + brute force), Angular apps, JS secr
How to use it
- 1Usage
- 2Set env vars (e.g. in `.env`): SHODAN_API_KEY=your_key_here # optional if you only use ZoomEye ZOOMEYE_API_KEY=your_zoomeye_key # optional if you only use Shodan BLACKLIST=1.2.3.4,example-bucket # optional
- 3Build and run: docker compose build docker compose up -d
- 4Apply migrations (first run): docker compose exec web python manage.py migrate
- 5Open the app at http://localhost:8000 (or your host IP:8000 on the LAN). python -m venv.venv && source.venv/bin/activate pip install -r requirem Configuration | Name | Purpose | Required | | --- | --- | --- | | `SHODAN_API_KEY` | Shodan API key used for all searches | Yes | | `ZOOMEYE_API_KEY` | ZoomEye API key (API-KEY header) | Yes (if using ZoomEye) | | `ZOOMEYE_TIMEOUT` | ZoomEye request timeout seconds (default 30) | Optional | | `ZOOMEYE_SUBTYPE` | ZoomEye sub_type (`v4`, `v6`, `web`, `all`; default `all`) | Optional | | `ZOOMEYE_PAGESIZE` | Defau
What it can do
- AI Tools
- Search
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/GainSec/LeakScope
- license: MIT — free to use
- privacy: Opens an external demo
Limitations
- Uses Django dev server in Docker
- Keep queries scoped to control provider credits/points.
- This tool is for defensive/offensive security use.
- **Landing**: shows IP info, env var presence (SHODAN/ZOOMEYE/BLACKLIST), total DB entries, credits used per provider, CTA to Home.
- **Home**: stacked per-type bar chart (Shodan vs ZoomEye), Shodan credits, ZoomEye points, total entries.
Understanding the result
An all-in-one Shodan & ZoomEye supported tool to search, browse, preview and dump data leakage across 20+ services. Pulls real exposure straight from the sources instead of guessing. Drop it into your workflow and watch it surface leaks you won't find anywhere else.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by LeakScope (MIT).
- Built with
- LeakScope (GainSec/LeakScope)
- License
- MIT
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Text Input
- Output
- Processed Output
Built with GainSec/LeakScope. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- LeakScope
- License
- MIT
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- GainSec/LeakScope — GitHub Repository
Upstream project · GitHub
- MIT License
Upstream project
Frequently asked
What is Gainsec Leakscope?
Search, triage, preview, and dump exposed services and code leaks using Shodan and ZoomEye with a provider aware UI and database. Find data leaks, threat intelligence and other useful data exposed and accessible on the internet *without authentication or exploitation.* It is available on GitHub at GainSec/LeakScope.
Is Gainsec Leakscope free to use?
Yes — Gainsec Leakscope is open-source software. You can use it freely, and the source code is available at https://github.com/GainSec/LeakScope.
What configuration options are available?
| Name | Purpose | Required | | --- | --- | --- | | `SHODAN_API_KEY` | Shodan API key used for all searches | Yes | | `ZOOMEYE_API_KEY` | ZoomEye API key (API-KEY header) | Yes (if using ZoomEye) | | `ZOOMEYE_TIMEOUT` | ZoomEye request timeout seconds (default 30) | Optional | | `ZOOMEYE_SUBTYPE` | ZoomEye sub_type (`v4`, `v6`, `web`, `all`; default `all`) | Optional | | `ZOOMEYE_PAGESIZE` | Defau
What are its key capabilities?
- Dual-provider discovery (Shodan + ZoomEye) with provider-specific dorks/templates and per-search provider selection. - Coverage: GitLab, Elasticsearch/OpenSearch, Kibana, Jenkins, Mongo/Mongo Express, Rsync, FTP, Cassandra, CouchDB, RethinkDB, S3 buckets (open + brute force), Angular apps, JS secrets, Grafana, Prometheus, MinIO, Swagger/OpenAPI,
Where can I try this tool?
This tool is hosted by its maintainers. Visit the official demo or source repository to use it. (https://github.com/GainSec/LeakScope)