Ilax Enum
- Passive-source subdomain enumeration
- DNS resolution, records & brute force
- Live HTTP probing and redirect chains
- TLS certificate and expiry inspection
- TCP ports, service detection & banners
- CDN, WAF and origin analysis
Attack-surface monitoring
Most breaches start with an asset the security team did not know they owned. Ilax Scan maps your public footprint, probes every reachable web service, checks for weaknesses, and watches for change — outside and inside the perimeter.
$ ilax-scan example.com --active --watch
[00:00:02] ownership confirmed · starting external pipeline
ENUM 42 subdomains discovered from passive sources + DNS
ENUM 18 live hosts · 31 services · 6 certificates
RECON crawling https://api.example.com/v2 → 84 endpoints
RECON React · nginx · Cloudflare · 12 technologies
SCAN checking 167 deduplicated targets with tech-detect profile
FIND medium missing Content-Security-Policy admin.example.com
WATCH new service observed: staging.example.com:8443
results streaming to workspace_
One connected platform
Each stage passes its verified output to the next. A finding arrives with the host, URL, technology and evidence that produced it — no copy-paste between tools.
From first scan to response
Start with a domain or an internal range. Ilax streams discoveries as they happen and sorts them by asset and severity, so your next step is obvious.