Asset group · My Company
Add your domains
Create an asset group and drop in one or more domains. That single group is your entire scope — no config files, no agents, no installs.
HaxUnit continuously maps your external attack surface, performs vulnerability assessment, and converts risk signals into action.
Platform coverage
How it works
Add a domain. We handle everything else — automatically, continuously.
Asset group · My Company
Create an asset group and drop in one or more domains. That single group is your entire scope — no config files, no agents, no installs.
blog.haxunit.com
Discovered 1m agoadmin.haxunit.io
Discovered 2 days agoanalytics.haxunit.com
Discovered 5m agoapp.haxunit.ai
Discovered 1m agoapi.haxunit.com
Discovered 12m agostaging.haxunit.com
Discovered 3h agoauth.haxunit.io
Discovered 4 days agodocs.haxunit.com
Discovered 22m agocdn.haxunit.ai
Discovered 8m agosupport.haxunit.com
Discovered 6h agomail.haxunit.com
Discovered 1 day agostatus.haxunit.io
Discovered 30m agodev.haxunit.com
Discovered 18m agocdn-eu.haxunit.com
Discovered 2h agoblog.haxunit.com
Discovered 1m agoadmin.haxunit.io
Discovered 2 days agoanalytics.haxunit.com
Discovered 5m agoapp.haxunit.ai
Discovered 1m agoapi.haxunit.com
Discovered 12m agostaging.haxunit.com
Discovered 3h agoauth.haxunit.io
Discovered 4 days agodocs.haxunit.com
Discovered 22m agocdn.haxunit.ai
Discovered 8m agosupport.haxunit.com
Discovered 6h agomail.haxunit.com
Discovered 1 day agostatus.haxunit.io
Discovered 30m agodev.haxunit.com
Discovered 18m agocdn-eu.haxunit.com
Discovered 2h agoEvery subdomain, IP, open port, and technology across your entire footprint — discovered and available to browse immediately as results come in.
Vulnerability scanning in progress..
Redis < 8.2.1 lua script
CVE-2025-46817
Redis Lua Parser < 8.2.2
CVE-2025-46631
Redis Server - Unauthenticated
Password not required
Public metrics endpoint exposed
/metrics publicly reachable
Redis < 8.2.1 lua script
CVE-2025-46817
Redis Lua Parser < 8.2.2
CVE-2025-46631
An automated scan runs across every discovered asset. For large attack surfaces, scanning is distributed across multiple servers simultaneously.
Finding
Ready to verify
Latest scan confirms the fixEvery finding comes with reproduction steps, evidence, and a one-click retest after you've fixed it. Get notified via email or Slack the moment something crosses your severity threshold.
Pricing
Select the option that fits your needs and start today.
Free Scan
$0/one-time
Test HaxUnit on a domain you own and get a focused vulnerability report in minutes.
Pro
$99/monthly
Direct paid subscription for teams ready to skip the trial.
Enterprise
Custom
Perfect for large organizations with advanced needs.
FAQs
Quick answers to your questions.
The free scan includes a one-time vulnerability scan for one domain, up to 100 assets, and a focused report. No credit card is required.
Create an account, add a domain you own, and HaxUnit starts mapping exposed assets and checking for vulnerabilities. Results are shown in your dashboard as the scan completes.
The free scan is a one-time check. Pro adds continuous discovery, recurring vulnerability scanning, up to 200 assets, deeper prioritization, and ongoing remediation workflows.
An asset is an externally discoverable item such as a domain, subdomain or IP address that HaxUnit tracks during discovery and scanning.
No. HaxUnit scans externally reachable assets from the domain scope you provide, so there are no agents, code changes, or config files required to get started.
Yes. HaxUnit keeps your scan results and asset telemetry isolated to your account and uses access controls and secure processing practices to protect your data.
No. You should only scan domains and assets you own or are explicitly authorized to test. HaxUnit is intended for legitimate security monitoring of your own attack surface.