External attack-surface scanning

See the public systems attackers can see.

Start with a domain you own. Ilax finds its subdomains, crawls every reachable web service, then runs focused security checks against the targets that actually matter.

ENUMDiscoveryRECONWeb contextSCANVulnerability checks

What an external scan can cover

Passive subdomain discovery with source traceability
DNS records, brute force and resolution status
Live HTTP services, redirects, headers and TLS posture
Port scanning and service identification
Technology, CDN and WAF fingerprinting
Crawled endpoints, forms and exposure signals
Template-based vulnerability checks
CVE matching for identified technologies

01

Verify

Prove control using DNS TXT or a well-known file before launching active checks.

02

Map

Discovery and recon stages stream assets, services and web data as they are found.

03

Prioritize

Review findings with the asset and technical evidence already attached.