| API Paths | Discovered API endpoints and routes |
| Headers | HTTP response headers collected during scanning |
| URLs | All URLs discovered during the crawl |
| Domains | Subdomains and related domains found |
| AWS Assets | Amazon Web Services resources (S3 buckets, CloudFront distributions, etc.) |
| IP Addresses | IP addresses associated with the target |
| Emails | Email addresses found in the target’s assets |
| S3 Bucket Takeovers | S3 buckets vulnerable to subdomain takeover |
| GQL Queries | GraphQL query operations discovered |
| GQL Mutations | GraphQL mutation operations discovered |
| GQL Fragments | GraphQL fragment definitions found |
| Parameters | URL and form parameters identified |
| Node Modules | JavaScript packages and dependencies detected |
| NPM Confusion | Packages potentially vulnerable to dependency confusion attacks |
| GUIDs | Globally Unique Identifiers found in assets |
| Vulnerabilities | Security vulnerabilities identified during scanning |
| Localhost | References to localhost or internal addresses |
| Expired Domains | Domains with expired registrations (potential takeover targets) |
| Social Media URLs | Links to social media profiles and pages |
| Filtered Port URLs | URLs with non-standard ports |
| File Extension URLs | URLs organized by file extension type |