External attack-surface scanning
See the public systems attackers can see.
Start with a domain you own. Ilax finds its subdomains, crawls every reachable web service, then runs focused security checks against the targets that actually matter.
ENUMDiscoveryRECONWeb contextSCANVulnerability checks
What an external scan can cover
Passive subdomain discovery with source traceability
DNS records, brute force and resolution status
Live HTTP services, redirects, headers and TLS posture
Port scanning and service identification
Technology, CDN and WAF fingerprinting
Crawled endpoints, forms and exposure signals
Template-based vulnerability checks
CVE matching for identified technologies
01
Verify
Prove control using DNS TXT or a well-known file before launching active checks.
02
Map
Discovery and recon stages stream assets, services and web data as they are found.
03
Prioritize
Review findings with the asset and technical evidence already attached.