Ilax Enum
- Passive-source subdomain enumeration
- DNS resolution, records & brute force
- Live HTTP probing and redirect chains
- TLS certificate and expiry inspection
- TCP ports, service detection & banners
- CDN, WAF and origin analysis
Ilax maps your public footprint, probes every live web service, and ranks vulnerabilities by severity — so you close real gaps instead of chasing noise.
How it works
You bring the domains. Ilax brings the visibility.
Enter the domains you own or are authorized to assess. We verify ownership via DNS TXT or a hosted file before any active scanning begins.
Ilax runs passive subdomain discovery, DNS validation, HTTP probing, TLS inspection, and port scanning. Results stream to your workspace in real time.
Findings are grouped by asset and severity. You get the host, URL, technology, and evidence you need to fix the issue — not a 300-page PDF.
Inside the workspace
No more switching between subdomain tools, port scanners and note files. Ilax streams discovery, reconnaissance and vulnerability findings into a single, prioritized workspace.
Discovered assets
142
+12 this week
Live services
38
3 new
Open findings
7
2 medium
Monitored domains
4
1 pending verify
$ ilax-scan acme-corp.com --active
[00:00:01] ownership verified · launching pipeline
ENUM 42 subdomains discovered
RECON crawling admin.acme-corp.com → 6 forms, 1 exposed env
SCAN 167 targets · tech-detect profile
streaming results to workspace_
Exposed .env file on admin panel
admin.acme-corp.com/.env
Missing Content-Security-Policy
api.acme-corp.com/v2
TLS 1.0 still enabled
legacy-api.acme-corp.com
Informational header disclosure
staging.acme-corp.com
2 high-priority findings can be fixed this week.
One connected platform
Each stage passes its verified output to the next. A finding arrives with the host, URL, technology, and evidence that produced it — no copy-paste between tools.
Use cases
From solo founders to security operations teams, Ilax adapts to your workflow.
See every public asset, track drift, and triage findings by severity. Stop losing track of staging environments and forgotten subdomains.
Get a clear picture of your attack surface without hiring a full security team. Know what to fix first and show investors you take security seriously.
Use Ilax for the reconnaissance phase, then focus on the interesting bugs. Export the inventory and integrate it into your report.
Run authorized assessments for multiple clients from one workspace. Keep scan results scoped per client and export white-label reports.
Built for security teams
Ilax is designed for teams that need to prove ownership before probing, keep scan output under control, and separate external from internal work.
“We finally have a single place to see what is actually exposed without stitching together five different tools.”
Security lead
B2B SaaS company
“The scanner found a staging subdomain we had forgotten about. That alone paid for the subscription.”
Engineering manager
Fintech startup
“Internal scan mode let us run our quarterly network assessment from the same dashboard we use for external assets.”
IT director
Healthcare provider
Pricing
The free plan lets you explore the workspace and verify domains. Paid plans unlock scans, deeper reconnaissance and internal network visibility.
For solo founders and small security teams getting started.
For teams that need continuous monitoring and internal coverage.
Free plan: 1 domain, no scans included. No credit card required to sign up.
FAQ
From first scan to response
Start with a domain or an internal range. Ilax streams discoveries as they happen and sorts them by asset and severity, so your next step is obvious.
Get in touch
Whether you are a founder, security lead, or MSP, we would love to hear what you are protecting and how Ilax can help. We usually reply within 24 hours.
contact@ilax.io