New: Internal network scanning

Find every exposed asset before attackers do.

Ilax maps your public footprint, probes every live web service, and ranks vulnerabilities by severity — so you close real gaps instead of chasing noise.

No credit card required1 free scanSelf-hosting available

How it works

From domain to fix in minutes, not weeks.

You bring the domains. Ilax brings the visibility.

1

Add your domains

Enter the domains you own or are authorized to assess. We verify ownership via DNS TXT or a hosted file before any active scanning begins.

2

We map and probe

Ilax runs passive subdomain discovery, DNS validation, HTTP probing, TLS inspection, and port scanning. Results stream to your workspace in real time.

3

Fix what matters

Findings are grouped by asset and severity. You get the host, URL, technology, and evidence you need to fix the issue — not a 300-page PDF.

Inside the workspace

See everything attackers see — in one dashboard.

No more switching between subdomain tools, port scanners and note files. Ilax streams discovery, reconnaissance and vulnerability findings into a single, prioritized workspace.

Ilax Workspace

Discovered assets

142

+12 this week

Live services

38

3 new

Open findings

7

2 medium

Monitored domains

4

1 pending verify

Recent scans

Live updates
acme-corp.comactive
completed2m ago
staging.acme-corp.comactive
runningnow
legacy-api.acme-corp.compassive
completed1h ago

$ ilax-scan acme-corp.com --active

[00:00:01] ownership verified · launching pipeline

ENUM 42 subdomains discovered

RECON crawling admin.acme-corp.com → 6 forms, 1 exposed env

SCAN 167 targets · tech-detect profile

streaming results to workspace_

Latest findings

highRecon

Exposed .env file on admin panel

admin.acme-corp.com/.env

mediumScanner

Missing Content-Security-Policy

api.acme-corp.com/v2

mediumEnum

TLS 1.0 still enabled

legacy-api.acme-corp.com

lowScanner

Informational header disclosure

staging.acme-corp.com

Risk summary
Attack surfaceMedium

2 high-priority findings can be fixed this week.

Terminal-first pipelineNuclei-powered checksDomain verification required

One connected platform

Discovery feeds recon. Recon feeds the scanner.

Each stage passes its verified output to the next. A finding arrives with the host, URL, technology, and evidence that produced it — no copy-paste between tools.

Plate C · External discovery

Ilax Enum

  • Passive-source subdomain enumeration
  • DNS resolution, records & brute force
  • Live HTTP probing and redirect chains
  • TLS certificate and expiry inspection
  • TCP ports, service detection & banners
  • CDN, WAF and origin analysis
Plate M · Web reconnaissance

Ilax Recon

  • Crawled routes and endpoint extraction
  • Forms, inputs and client-side routes
  • Technology and framework fingerprinting
  • Secrets and exposed configuration signals
  • Headers, response metadata and screenshots
  • Web application inventory per live URL
Plate Y · Vulnerability scanning

Ilax Scanner

  • Template-based security checks
  • HTTP, DNS, TCP and SSL protocols
  • Technology-aware detection profiles
  • Severity-ranked evidence and remediation notes
  • Deduplicated targets from discovered assets
  • Exportable findings and risk analysis
Plate K · Private networks

Ilax Internal

  • CIDR, range and host discovery
  • Port scanning and service identification
  • Internal vulnerability checks
  • SMB, Active Directory and share inventory
  • Segmentation policy evaluation
  • Encrypted secret capture and run history

Use cases

Built for teams that need to see everything.

From solo founders to security operations teams, Ilax adapts to your workflow.

Security teams

See every public asset, track drift, and triage findings by severity. Stop losing track of staging environments and forgotten subdomains.

Founders and CTOs

Get a clear picture of your attack surface without hiring a full security team. Know what to fix first and show investors you take security seriously.

Penetration testers

Use Ilax for the reconnaissance phase, then focus on the interesting bugs. Export the inventory and integrate it into your report.

MSPs and MSSPs

Run authorized assessments for multiple clients from one workspace. Keep scan results scoped per client and export white-label reports.

Built for security teams

Authorized testing, encrypted data, no surprises.

Ilax is designed for teams that need to prove ownership before probing, keep scan output under control, and separate external from internal work.

Domain-verified scans only
Encrypted scan secrets at rest
Self-host friendly architecture
Authorized testing workflows

We finally have a single place to see what is actually exposed without stitching together five different tools.

Security lead

B2B SaaS company

The scanner found a staging subdomain we had forgotten about. That alone paid for the subscription.

Engineering manager

Fintech startup

Internal scan mode let us run our quarterly network assessment from the same dashboard we use for external assets.

IT director

Healthcare provider

Pricing

Start free. Upgrade when you are ready to scan.

The free plan lets you explore the workspace and verify domains. Paid plans unlock scans, deeper reconnaissance and internal network visibility.

Starter

For solo founders and small security teams getting started.

₹5,999/month
  • 3 external scans / month
  • Up to 3 domains
  • Scan depth up to 3
  • Subdomain discovery + DNS
  • Web reconnaissance
  • Vulnerability scanning
  • JSON / CSV export
Start with Starter
Most popular

Pro

For teams that need continuous monitoring and internal coverage.

₹11,999/month
  • 15 external scans / month
  • Up to 10 domains
  • Scan depth up to 5
  • Internal network scanning
  • Full markdown reports
  • Risk score analysis
  • JSON / CSV export
Get Pro access

Free plan: 1 domain, no scans included. No credit card required to sign up.

FAQ

Questions people ask before they buy.

Can I scan domains I do not own?
No. Active external scanning requires domain verification via DNS TXT or a hosted file. Passive discovery is available for any domain, but active probing is gated by ownership.
What happens after I sign up?
You verify a domain, run your first scan, and watch results stream into your workspace. If you need more scans, domains, or internal coverage, you can upgrade from the billing page.
How does Ilax decide what to flag?
Findings are based on template checks, technology fingerprints, and observed exposure. Each finding comes with the host, URL, technology, and evidence that produced it, so you can validate it yourself.
Is my scan data encrypted?
Scan secrets and internal network collected secrets are encrypted at rest with AES-256-GCM. Exported CSV values are escaped to reduce formula-injection risk.
Can I cancel anytime?
Yes. You can cancel from the billing page. Access continues until the end of the current paid period. Unused quota does not roll over.

From first scan to response

Build a living inventory of everything attackers can reach.

Start with a domain or an internal range. Ilax streams discoveries as they happen and sorts them by asset and severity, so your next step is obvious.

Enter Ilax Scan

Get in touch

Talk to us about your attack surface.

Whether you are a founder, security lead, or MSP, we would love to hear what you are protecting and how Ilax can help. We usually reply within 24 hours.

contact@ilax.io