About VeilScan
VeilScan performs external attack surface management. A pipeline of about 50 nodes maps your public footprint, covering subdomains, ports, exposed services, JavaScript secrets, cloud buckets and vulnerable endpoints, with no setup beyond a domain. AI reasoning then correlates findings into attack paths, such as SQL injection that exposes a credentials file which then gives admin access, and shows the step-by-step breach an intruder could run, with the time each hop takes.
Each critical finding is backed by proof, including a curl command that reproduces the issue together with the real server response, and the site says anything it cannot prove is not rated critical. Reports are written in plain language with a business impact score from 0 to 10, mapped to standards such as ISO 27001 and GDPR, and the product re-scans on a schedule and sends Slack alerts when a critical issue appears.
The first report is promised in about two hours, data stays in the UK, and scanning a domain is free with no credit card. It is a hosted service with pricing, blog, compare, FAQ and use-case pages, along with a sample report on request.
Key features
- External perimeter and subdomain mapping
- Detection of exposed secrets and cloud buckets
- AI-built attack path simulation
- Reproducible proof for critical findings
- Business impact score from 0 to 10
- Scheduled re-scans with Slack alerts
Good fit for
- Finding forgotten subdomains and staging servers
- Showing leadership the real business impact of a vulnerability
VeilScan: questions and answers
- What is VeilScan used for?
- VeilScan is an external attack surface scanner that maps your internet-facing assets, chains findings into simulated attack paths and attaches reproducible proof to critical issues. It is a good fit for finding forgotten subdomains and staging servers, and showing leadership the real business impact of a vulnerability.
- Is VeilScan free?
- Yes. VeilScan has a free plan, and paid plans start at $49 per month.
- Is VeilScan open source?
- No. VeilScan is proprietary (closed-source) software and can't be self-hosted. In the Security category, open-source options include CISO Assistant, Wazuh and Grype.
- What are some alternatives to VeilScan?
- VeilScan competes with Intruder, Invicti and Pentera.
Open-source alternatives to VeilScan
See all
CISO Assistant
Security
CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & A
OSSvs Vanta★ 4.5k
Wazuh
Security
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints a
OSSvs Splunk★ 17k
Grype
Security
A vulnerability scanner for container images and filesystems
Apache-2.0vs Snyk★ 13k
Kubescape
Security
Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, an
Apache-2.0vs Wiz★ 12k
OSSEC
Security
OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis,
GPL-2.0vs CrowdStrike★ 5.1k
OpenVAS
Security
This repository contains the scanner component for Greenbone Community Edition.
GPL-2.0vs Tenable★ 4.9k
SaaS alternatives to VeilScan
See all
Intruder
Security
Cloud-based vulnerability scanner for external attack surface
SaaS
Invicti
Security
Web application security scanning platform formerly known as Netsparker
SaaS
Pentera
Security
Automated penetration testing and security validation platform
SaaS
Tenable
Security
Vulnerability management and exposure assessment, maker of the Nessus scanner
SaaS
Qualys
Security
Cloud platform for vulnerability management, compliance and asset inventory
SaaSRapid7
Security
Vulnerability management, SIEM and managed detection tools for security teams
SaaS
