VULNIX0 / CASE FILEPG. 00 — COVER
CLASSIFICATION: PUBLIC FILE NO. V0‑001 — ATTACK SURFACE INTELLIGENCE

Your attack surface,
red-teamed by AI.
Every day.

Vulnix0 builds a live inventory of every domain, subdomain, open port, and exposed service your organization owns, then runs the same reconnaissance-to-exploitation chain an attacker would use to actually ██████████ — continuously, under policy control, instead of █████████████.

Origin Velocity Lab R&D
Built With AquilaX Security
Status Live, Operational
Coverage 6+ Modules, 24/7
LIVE ATTACK SURFACE MAP LIVE
CLASSIFICATION: DEMO DATA NODES: 10 · EDGES: 12

Vulnix0 is the first project out of Velocity Lab — OneFirewall Alliance's research & development team — built in collaboration with AquilaX Security, OneFirewall's code and infrastructure assessment partner. It was born inside the lab and is now running live. Read about Velocity Lab →

A JOINT OPERATION BY
OneFirewall Alliance logo
OneFirewall Alliance
Velocity Lab · R&D
×
AquilaX Security logo
AquilaX Security
AI Engine · Technology Partner
VULNIX0 / CASE FILEPG. 01 — PLATFORM
The Platform — Manifest 001–016

Sixteen modules. One engine. No gaps between them.

Most teams run a scanner for the perimeter, a separate tool for the application layer, a mailing list for threat intel, and a spreadsheet to track what a pentester found eight months ago. Vulnix0 is the sixteen-module replacement for that stack — every module below feeds the same asset graph and the same finding correlation engine.

001 Attack Surface Management Continuous enumeration of domains, subdomains, open ports, and cloud-hosted assets; every pass diffs against the last. → 002 Asset Discovery & Recon Subdomain enumeration, DNS record analysis, WHOIS, and technology fingerprinting — reconnaissance before exploitation. → 003 Automated Penetration Testing Policy-scoped exploit attempts against what recon finds, returned as a reproducible request/response, not a CVSS score. → 004 Dynamic Application Security Testing Runtime fuzzing of every crawled parameter for injection, broken access control, and logic flaws. → 005 Dynamic Security Analysis Full-site crawl, form and parameter extraction, and header-posture scoring ahead of the exploit phase. → 006 Data Leakage Detection Exposed .env files, verbose stack traces, and hardcoded secrets, surfaced before they're indexed by someone else. → 007 DNS & Email Security SPF, DKIM, and DMARC policy validation, plus unauthenticated zone-transfer (AXFR) testing. → 008 Files Discovery Directory and file enumeration against the paths attackers check first — .git, backups, configuration dumps. → 009 Performance Load Testing Concurrent-request generation that measures latency percentiles and confirms rate limiting engages under real load. → 010 Offensive Security Assessments Correlates findings across modules into attack paths — the way an adversary chains low-severity issues into a breach. → 011 Open Port Analysis Full TCP enumeration with service fingerprinting, flagging insecure protocols and exposed databases. → 012 Threat Intelligence Validation Cross-references owned domains, IPs, and file hashes against live threat-intelligence feeds. → 013 Threat Intel Asset inventory feeding continuous reputation correlation, not a one-time lookup. → 014 Cybercrime Intel Checks whether your IPs and domains already appear in botnet, C2, or phishing-tracking sources. → 015 TLS/SSL Security Scan Protocol, cipher-suite, and certificate-chain assessment at the depth of a full testssl.sh run. → 016 Continuous Security Monitoring Every module re-run on schedule, with drift detection in place of a single point-in-time report. →
VULNIX0 / CASE FILEPG. 02 — METHOD
Methodology

Hunt. Exploit. Prove. Repeat.

Four stages, not a single scan. Each one feeds the next, and the loop restarts the moment your infrastructure changes — not on a yearly calendar entry.

01

Discover

Reconnaissance agents enumerate domains, subdomains, APIs, cloud assets, and exposed credentials, then build a graph of how they connect.

02

Exploit, under policy

Each candidate finding is actually attempted — not inferred from a banner — within the aggressiveness ceiling your scan policy sets.

03

Prioritize

A SQL injection on an internal staging form and one on your auth endpoint get the same CVSS score and a very different priority here.

04

Repeat, on change

A new subdomain, an opened port, or a deployed endpoint triggers re-testing on its own — no engagement letter required.

VULNIX0 / CASE FILEPG. 03 — SAMPLE FINDINGS
Case Log — Redacted Excerpts

What an attacker — or Vulnix0 — would actually find.

Eight entries, pulled from the classes of finding the engine confirms most often across real engagements. Each one below is a live check with a request and a response behind it, not a CVE title copied off an advisory feed.

Critical SQL Injection CWE-89 · T1190

An unsanitized query parameter accepts ' OR '1'='1 and returns full result rows — read access to the underlying database from an unauthenticated request.

High Stored Cross-Site Scripting CWE-79 · T1059.007

A comment or profile field persists <script> payloads and replays them to every future visitor of that page, session included.

High Broken Object-Level Authorization CWE-639 · T1190

Incrementing an ?id= parameter returns other users' records with no ownership check — classic IDOR, confirmed by sequential probing.

High Anonymous FTP Login CWE-287 · T1078.001

USER anonymous / PASS <anything> is accepted with no real credential check — unauthenticated access to whatever file store sits behind it.

Critical Unauthenticated Redis Access CWE-306 · T1133

Commands succeed with no AUTH at all — read, write, or delete every key, the exact signal behind a long string of real ransom/wiper incidents.

Critical Kubernetes Dashboard — Skip Auth T1078

A dashboard reachable with no RBAC, offering "Skip" instead of a token — logs you in as whatever the service account can do. The exact bug behind the 2018 Tesla cryptomining breach.

High Unauthenticated AI Model API (Ollama / MCP) T1595.002

The model-serving API or an MCP server's tools/list answers with no auth — model inventory, inference, and in some cases filesystem/shell tool access, free for anyone who finds the port.

Critical DNS Zone Transfer (AXFR) CWE-200 · T1018

The nameserver hands the entire zone — every internal hostname, mail server, and IP — to any anonymous dig axfr request, not just its configured secondaries.

The eight above are illustrative, not exhaustive. What follows is the actual class taxonomy the sixteen modules test against — grouped the way a penetration tester scopes an engagement, not as a marketing checklist.

Injection & Application Logic CWE-89 · CWE-79 · CWE-78 · CWE-22 · CWE-639
✓SQL injection, including blind and time-based extraction
✓Reflected and stored cross-site scripting
✓OS command injection and path traversal
✓Server-side template injection (SSTI)
✓Broken object-level authorization (IDOR/BOLA) via sequential-ID probing
✓Open redirect and CORS misconfiguration
Authentication & Session Handling CWE-287 · CWE-306 · CWE-798
✓Missing or bypassable authentication on exposed services
✓Default and hardcoded credential acceptance
✓Session cookie attributes — Secure, HttpOnly, SameSite
✓Brute-force and rate-limit exposure on login and reset endpoints
Exposed Infrastructure & Services CWE-306 · CWE-200
✓Unauthenticated Redis, MongoDB, and Elasticsearch instances
✓Anonymous FTP and open SMTP relays
✓Kubernetes Dashboard, kubelet, and etcd without RBAC
✓Remote-management exposure — VNC, WinRM, RDP
✓IoT/ICS protocol exposure — MQTT, Modbus, RTSP, DICOM
AI/ML Attack Surface CWE-306 · T1595.002
✓Unauthenticated Ollama and other model-serving APIs
✓MCP servers exposing tools/list with filesystem or shell access
✓Vector database exposure without access control
Network, DNS & Transport CWE-200 · CWE-295 · CWE-326
✓DNS zone transfer (AXFR) exposure
✓SPF, DKIM, and DMARC misconfiguration enabling spoofing
✓Deprecated TLS versions and weak cipher suites
✓Certificate chain, expiry, and revocation status
Information Disclosure CWE-200 · CWE-538
✓Exposed .env, .git, and backup files
✓Verbose stack traces and internal hostname leakage
✓Hardcoded secrets and credential patterns in responses
External Reputation & Threat Correlation
✓Domain/IP presence on botnet, C2, and phishing infrastructure lists
✓Dark-web and paste-site mentions tied to your assets
✓Historical compromise indicators on owned infrastructure
VULNIX0 / CASE FILEPG. 04 — WHY CONTINUOUS
Declassified

The annual pentest was never built for how fast you ship.

Capability
Traditional Pentest
Vulnix0
Testing cadence
Once or twice a year
✓ Continuous, 24/7
Coverage as you grow
Fixed scope, goes stale fast
✓ Auto-discovers new assets
Driven by
Manual human testers
✓ AI agents + human-grade methodology
Time to re-test a fix
Next engagement cycle
✓ Same day
Output
Static PDF report
✓ Live dashboard + prioritized findings
VULNIX0 / CASE FILEPG. 05 — FAQ
Debrief

Questions, answered

What is Vulnix0? +
Vulnix0 is an AI-driven offensive security platform that continuously discovers your real attack surface and safely simulates real-world attacker behavior against it — combining attack surface management, autonomous penetration testing, DAST, threat intelligence validation, and data leakage detection in one system.
Where did Vulnix0 come from? +
Vulnix0 is the first project out of Velocity Lab, OneFirewall Alliance's R&D team. It was built inside the lab in collaboration with AquilaX Security and is now operating as a live product.
How is AI actually used in the pentesting? +
AI chains reconnaissance, prioritizes which discovered assets and parameters are worth testing, adapts exploit payloads based on live responses, and correlates findings the way a human red teamer would — so testing runs continuously without a human manually driving every step.
Is it safe to run against production? +
Vulnix0 is built for authorized, scoped testing: scans run only against assets you define, with configurable policies ranging from passive reconnaissance up to active exploit verification.
How is this different from an annual pentest? +
A traditional pentest is a manual, point-in-time engagement that reflects your environment on one day a year. Vulnix0 runs continuously and autonomously, re-testing your attack surface as it changes.
What vulnerability classes does Vulnix0 actually test for? +
Injection and application-logic flaws (SQL injection, XSS, SSTI, IDOR/BOLA), authentication and session weaknesses, exposed infrastructure (unauthenticated Redis/Kubernetes/VNC and similar), AI/ML attack surface (unauthenticated Ollama and MCP endpoints), DNS and TLS misconfiguration, information disclosure (exposed .env and .git files, leaked secrets), and external reputation signals from threat-intel and dark-web sources. The full taxonomy with CWE references is on this page, above.
VULNIX0 / CASE FILEPG. 06 — CONTACT
Close the File

Find out what an attacker would find. Today.

Start a free scan, or talk to the team behind Vulnix0.