No sign-up11,173 open-source and SaaS tools, with GitHub stats refreshed every day.

VeilScan

SaaS

External attack surface scanner that maps your internet-facing assets, chains findings into simulated attack paths and attaches reproducible proof to critical issues.

About VeilScan

VeilScan performs external attack surface management. A pipeline of about 50 nodes maps your public footprint, covering subdomains, ports, exposed services, JavaScript secrets, cloud buckets and vulnerable endpoints, with no setup beyond a domain. AI reasoning then correlates findings into attack paths, such as SQL injection that exposes a credentials file which then gives admin access, and shows the step-by-step breach an intruder could run, with the time each hop takes.

Each critical finding is backed by proof, including a curl command that reproduces the issue together with the real server response, and the site says anything it cannot prove is not rated critical. Reports are written in plain language with a business impact score from 0 to 10, mapped to standards such as ISO 27001 and GDPR, and the product re-scans on a schedule and sends Slack alerts when a critical issue appears.

The first report is promised in about two hours, data stays in the UK, and scanning a domain is free with no credit card. It is a hosted service with pricing, blog, compare, FAQ and use-case pages, along with a sample report on request.

Key features

  • External perimeter and subdomain mapping
  • Detection of exposed secrets and cloud buckets
  • AI-built attack path simulation
  • Reproducible proof for critical findings
  • Business impact score from 0 to 10
  • Scheduled re-scans with Slack alerts

Good fit for

  • Finding forgotten subdomains and staging servers
  • Showing leadership the real business impact of a vulnerability
Tags
security
attack-surface
vulnerability-scanner
easm
penetration-testing
slack
compliance
external-scan

VeilScan: questions and answers

What is VeilScan used for?
VeilScan is an external attack surface scanner that maps your internet-facing assets, chains findings into simulated attack paths and attaches reproducible proof to critical issues. It is a good fit for finding forgotten subdomains and staging servers, and showing leadership the real business impact of a vulnerability.
Is VeilScan free?
Yes. VeilScan has a free plan, and paid plans start at $49 per month.
Is VeilScan open source?
No. VeilScan is proprietary (closed-source) software and can't be self-hosted. In the Security category, open-source options include CISO Assistant, Wazuh and Grype.
What are some alternatives to VeilScan?
VeilScan competes with Intruder, Invicti and Pentera.

Open-source alternatives to VeilScan

See all

SaaS alternatives to VeilScan

See all