Attack-surface management for blue teams — discover, monitor, report.
Discover every reachable host, subdomain, and IP range tied to your organization.
Enumerate services, ports, and certificates to see what's actually exposed.
Track changes to your perimeter and get alerted the moment something shifts.
Cross-reference discovered assets against known vulnerabilities and threat intel.
Automate scans and pipe results straight into your existing toolchain.
Share findings with your security team in clean, digestible views.
$ xwllz discover acme --passive [+] harvesting certificate transparency . . . 1,284 subdomains [+] resolving hosts . . . 312 live [+] checking DNS posture (SPF / DMARC / DKIM) . . . 27 risks [+] writing snapshot . . . done done — 27 exposure points mapped in 4.2s
$ pipx install xwllz $ xwllz init acme --domains example.com $ xwllz discover acme $ xwllz monitor acme $ xwllz report acme --format md
This software is intended for defensive security purposes only. Use it solely on systems and networks you own or are explicitly authorized to test. The author(s) assume no liability for any damages or legal issues arising from misuse. Always comply with all applicable laws and regulations.