Attack-surface monitoring

Know what's exposed.
Know what to fix.

Most breaches start with an asset the security team did not know they owned. Ilax Scan maps your public footprint, probes every reachable web service, checks for weaknesses, and watches for change — outside and inside the perimeter.

Verify before you probeLive scan progressCSV and JSON exports
ilax-scan / live run
STREAMING

$ ilax-scan example.com --active --watch

[00:00:02] ownership confirmed · starting external pipeline

ENUM 42 subdomains discovered from passive sources + DNS

ENUM 18 live hosts · 31 services · 6 certificates

RECON crawling https://api.example.com/v2 → 84 endpoints

RECON React · nginx · Cloudflare · 12 technologies

SCAN checking 167 deduplicated targets with tech-detect profile

FIND medium missing Content-Security-Policy admin.example.com

WATCH new service observed: staging.example.com:8443

results streaming to workspace_

One connected platform

Discovery feeds recon. Recon feeds the scanner.

Each stage passes its verified output to the next. A finding arrives with the host, URL, technology and evidence that produced it — no copy-paste between tools.

Plate C · External discovery

Ilax Enum

  • Passive-source subdomain enumeration
  • DNS resolution, records & brute force
  • Live HTTP probing and redirect chains
  • TLS certificate and expiry inspection
  • TCP ports, service detection & banners
  • CDN, WAF and origin analysis
Plate M · Web reconnaissance

Ilax Recon

  • Crawled routes and endpoint extraction
  • Forms, inputs and client-side routes
  • Technology and framework fingerprinting
  • Secrets and exposed configuration signals
  • Headers, response metadata and screenshots
  • Web application inventory per live URL
Plate Y · Vulnerability scanning

Ilax Scanner

  • Template-based security checks
  • HTTP, DNS, TCP and SSL protocols
  • Technology-aware detection profiles
  • Severity-ranked evidence and remediation notes
  • Deduplicated targets from discovered assets
  • Exportable findings and risk analysis
Plate K · Private networks

Ilax Internal

  • CIDR, range and host discovery
  • Port scanning and service identification
  • Internal vulnerability checks
  • SMB, Active Directory and share inventory
  • Segmentation policy evaluation
  • Encrypted secret capture and run history

From first scan to response

Build a living inventory of everything attackers can reach.

Start with a domain or an internal range. Ilax streams discoveries as they happen and sorts them by asset and severity, so your next step is obvious.

Enter Ilax Scan