Puncia is the official command-line client for two A.R.P. Syndicate intelligence APIs โ point it at a domain, a brand, or a vulnerability ID and get structured JSON back in seconds, no browser required:
- ๐ธ๏ธ Subdomain Center โ subdomain enumeration, subdomain takeover surfacing, shadow IT discovery, and brand impersonation / lookalike-domain (typosquat) detection at internet scale.
- ๐ฅ Exploit Observer โ exploit & vulnerability intelligence across 150+ identifier schemes (CVE, GHSA, EDB, MSF, ZDI, nation-state feeds and more), with CVE/GHSA enrichment (EPSS + VEDAS maturity scoring) and SBOM scanning.
$ puncia subdomain arpsyndicate.io
โญโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฎ
โ Panthera(P.)uncia v0.36 โ
โ subdomain recon ยท brand impersonation ยท exploit intel ยท sbom analysis โ from the CLI โ
โ A.R.P. Syndicate โ https://www.arpsyndicate.io โ
โฐโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฏ
[
"advisories.arpsyndicate.io",
"asm.arpsyndicate.io",
"blog.arpsyndicate.io",
...
]
$ puncia sbom bom.json ./out
puncia โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ 100% (128/128) 0:00:41
Please note that although these results can sometimes be pretty inaccurate & unreliable, they can greatly differ from time to time due to their self-improvement capabilities.
Aggressive rate-limits can be avoided with an API key: https://www.arpsyndicate.io/pricing.html
- Brand Impersonation & Phishing Domain Detection
Surface replica, lookalike, and typosquat domains riding on your brand before they're used against you or your customers. - Shadow IT & External Attack Surface Discovery
Identify and monitor exposed subdomains and infrastructure spun up outside official channels. - Subdomain Takeover Reconnaissance
Enumerate the full subdomain footprint of a target, a key first step in spotting dangling/takeover-prone records. - Advanced Vulnerability Research & Monitoring
Discover and track known and emerging threats, including obscure or unlisted vulnerabilities. - Contextual Enrichment of CVE/GHSA Data
Add depth and actionable intelligence (EPSS + VEDAS maturity scores) to known vulnerabilities for better prioritization. - Vulnerability Detection in Software Bill of Materials (SBOM)
Analyze software components for known exploits and security issues using structured SBOM data. - Seamless Integration with CI/CD & Threat Intel Workflows
Automate intelligence gathering and vulnerability checks within development or security pipelines. - Monitoring Nation-State Exploit Trends
Stay ahead of threats by tracking vulnerabilities flagged by foreign actors but not yet recognized by mainstream databases. - Keyword-Based Subdomain Discovery
Surface hosts carrying a given keyword across the internet, independent of a specific parent domain. - Bulk Threat Intelligence Processing
Run batch queries (domains, vulnerabilities, etc.) for scalable analysis across large datasets or enterprise asset inventories. - Passive Reconnaissance for Red Teams
Conduct stealthy reconnaissance by using passive data sources (no direct interaction with targets). - Open Source Intelligence (OSINT) Collection
Combine subdomain and exploit intelligence to enhance OSINT investigations. - Compliance & Risk Management Support
Enrich vulnerability data to support compliance audits (e.g., ISO 27001, SOC 2) with deeper context.
- From PyPi -
pip3 install puncia - From Source -
pip3 install .
pip3 install puncia
# subdomain footprint of a target (shadow IT / attack surface / takeover recon)
puncia subdomain example.com
# lookalike / typosquat / brand-impersonation domains
puncia replica example.com
# what's known about a CVE
puncia exploit CVE-2021-44228puncia <mode> <query> [output] [--match M] [--domain D] [--limit N] [--offset N]
[--api-key K] [--concurrency N] [--timeout S]
[--retries N] [--quiet]
Run puncia --help for the full reference. Results are printed to stdout; the
banner, progress bars, warnings and errors all go to stderr, so
puncia subdomain example.com > out.json always yields clean, valid JSON.
Exit codes: 0 success ยท 1 request or input error ยท 2 usage error.
-
(PAID) Store an API key (storekey) -
puncia storekey <api-key>- Stored at
~/.punciawith0600permissions.$PUNCIA_API_KEYoverrides it, which is usually what you want in CI.
- Stored at
-
(FREEMIUM) Query Domains, clustered by domain (subdomain /
cuttlefishengine) -puncia subdomain <domain> <output-file>- Pagination (authenticated only): an authenticated result has no total
cap. By default
subdomain/replica/keywordwalk every page and merge them for you. Pass--offset(with or without--limit) to fetch exactly one raw page yourself instead, e.g. for a resumable or streaming walk:Anonymous requests ignorepuncia subdomain bigco.com --limit 50000 --offset 0 # stderr prints: note: more results available โ continue with --offset 50000 puncia subdomain bigco.com --limit 50000 --offset 50000--limit/--offsetserver-side (always a shuffled sample of up to 500 rows); puncia warns rather than pretending they did something.
- Pagination (authenticated only): an authenticated result has no total
cap. By default
-
(FREEMIUM) Query Replica Domains, clustered by brand (replica /
octopusengine) -puncia replica <domain> --match <prefix|exact|substring> <output-file> -
(FREEMIUM) Query by Keyword, clustered by keyword (keyword /
ammonitesengine) -puncia keyword <keyword> --match <exact|prefix> <output-file>- Optionally scope the keyword to a single domain with
--domain:puncia keyword blog --domain bandcamp.com
- Optionally scope the keyword to a single domain with
-
Query Exploit & Vulnerability Identifiers (exploit)
- (FREE) Vulnerability & Exploit Identifers Watchlist (^WATCHLIST_IDES) -
puncia exploit ^WATCHLIST_IDES <output-file> - (FREE) Vulnerability & Exploit Identifers Watchlist with Descriptions (^WATCHLIST_INFO) -
puncia exploit ^WATCHLIST_INFO <output-file> - (FREE) Vulnerable Technologies Watchlist (^WATCHLIST_TECH) -
puncia exploit ^WATCHLIST_TECH <output-file> - (FREEMIUM) Supported Vulnerability Identifiers -
puncia exploit <eoidentifier> --match <substring|prefix|exact> <output-file>
- (FREE) Vulnerability & Exploit Identifers Watchlist (^WATCHLIST_IDES) -
-
(FREEMIUM) Enrich CVE/GHSA Identifiers (enrich) -
puncia enrich <cve-id/ghsa-id> <output-file> -
(PAID) Non-CVE Identifiers by VEDAS group (noncve) -
puncia noncve <browser/china/russia/europe/exploitable> <output-file> -
Multiple Queries (bulk/sbom)
- (FREEMIUM) Bulk Input JSON File Format -
puncia bulk <json-file> <output-directory>{ "subdomain": [ "domainA.com", "domainB.com" ], "replica": [ "domainA.com", "domainB.com" ], "keyword": [ "keywordA", "keywordB" ], "exploit": [ "eoidentifierA", "eoidentifierB" ], "enrich": [ "eoidentifierA", "eoidentifierB" ] } - (FREEMIUM) SBOM Input JSON File Format -
puncia sbom <json-file> <output-directory>
Bulk and SBOM runs de-duplicate queries, cap parallelism at
--concurrency(default 10), and โ when no API key is present โ pace requests to stay inside the free-tier budget automatically. - (FREEMIUM) Bulk Input JSON File Format -
-
(FREEMIUM) External Import
import asyncio
import puncia
async def main():
# Without an API key (ratelimited)
print(await puncia.query_api("exploit", "CVE-2021-3450"))
print(await puncia.query_api("subdomain", "arpsyndicate.io"))
# With an API key
await puncia.store_key("ARPS-xxxxxxxxxx")
api_key = await puncia.read_key()
print(await puncia.query_api("subdomain", "arpsyndicate.io", apikey=api_key))
print(await puncia.query_api("replica", "arpsyndicate.io", match="exact", apikey=api_key))
print(await puncia.query_api("enrich", "CVE-2021-3450", apikey=api_key))
print(await puncia.query_api("noncve", "exploitable", apikey=api_key))
# Write straight to disk
await puncia.query_api("subdomain", "arpsyndicate.io", "out.json", apikey=api_key)
asyncio.run(main())Failures raise puncia.PunciaError; an empty result ({} / []) is returned
as-is rather than being treated as an error. Reuse one session across many
queries by passing session= and a shared limiter=, exactly as
process_bulk() does.
from puncia import PunciaError, query_api
try:
data = await query_api("exploit", "CVE-2021-3450", apikey=api_key)
except PunciaError as exc:
print(f"lookup failed: {exc}")git clone https://github.com/ARPSyndicate/puncia && cd puncia
pip install --upgrade pip # editable installs need pip >= 21.3
pip install -e ".[dev]"
pytest # 42 offline tests, no API calls or network accessThe test suite is fully offline โ it covers URL construction, output-path containment, SBOM parsing, bulk planning and ratelimiter timing without touching the network, so it is safe to run in any environment.
- Passive Subdomain Enumeration: Uncovering More Subdomains than Subfinder & Amass
- Around 1000 exploitable cybersecurity vulnerabilities that MITRE & NIST โmightโ have missed but China or Russia didnโt.
- Utilizing GitHub Actions for gathering Subdomain & Exploit Intelligence
- Introducing Exploit Observer โ More than Shodan Exploits, Less than Vulners
- PUNCIA โ The Panthera(P.)uncia of Cybersecurity
- Subdomain Enumeration Tool Face-off - 2023 Edition


