xwllz

Attack-surface management for blue teams — discover, monitor, report.

Commands
8
init · discover · monitor · report …
Keyless sources
5
crt.sh · DNS · HTTP · TLS · ports
Keyed enrichments
6
Shodan … VirusTotal
Report formats
3
md · json · html

What xwllz tracks

six lenses on your perimeter

Attack-surface mapping

Discover every reachable host, subdomain, and IP range tied to your organization.

Asset discovery

Enumerate services, ports, and certificates to see what's actually exposed.

Continuous monitoring

Track changes to your perimeter and get alerted the moment something shifts.

Threat correlation

Cross-reference discovered assets against known vulnerabilities and threat intel.

CLI & API

Automate scans and pipe results straight into your existing toolchain.

Team dashboards

Share findings with your security team in clean, digestible views.

How it works

pure-Python core · optional accelerators
xwllz architecture diagram

The ASM loop

every run snapshots · monitor diffs
xwllz attack-surface loop diagram

Built for the terminal

sample discovery run
xwllz — scan
$ xwllz discover acme --passive

  [+] harvesting certificate transparency . . . 1,284 subdomains
  [+] resolving hosts . . . 312 live
  [+] checking DNS posture (SPF / DMARC / DKIM) . . . 27 risks
  [+] writing snapshot . . . done

  done — 27 exposure points mapped in 4.2s

Install in seconds

open source · MIT · Python 3.10+
xwllz — quickstart
$ pipx install xwllz

$ xwllz init acme --domains example.com
$ xwllz discover acme
$ xwllz monitor acme
$ xwllz report acme --format md

Legal disclaimer

defensive security only

This software is intended for defensive security purposes only. Use it solely on systems and networks you own or are explicitly authorized to test. The author(s) assume no liability for any damages or legal issues arising from misuse. Always comply with all applicable laws and regulations.