Your attack surface,
red-teamed by AI.
Every day.
Vulnix0 builds a live inventory of every domain, subdomain, open port, and exposed service your organization owns, then runs the same reconnaissance-to-exploitation chain an attacker would use to actually ██████████ — continuously, under policy control, instead of █████████████.
Vulnix0 is the first project out of Velocity Lab — OneFirewall Alliance's research & development team — built in collaboration with AquilaX Security, OneFirewall's code and infrastructure assessment partner. It was born inside the lab and is now running live. Read about Velocity Lab →
Sixteen modules. One engine. No gaps between them.
Most teams run a scanner for the perimeter, a separate tool for the application layer, a mailing list for threat intel, and a spreadsheet to track what a pentester found eight months ago. Vulnix0 is the sixteen-module replacement for that stack — every module below feeds the same asset graph and the same finding correlation engine.
Hunt. Exploit. Prove. Repeat.
Four stages, not a single scan. Each one feeds the next, and the loop restarts the moment your infrastructure changes — not on a yearly calendar entry.
Discover
Reconnaissance agents enumerate domains, subdomains, APIs, cloud assets, and exposed credentials, then build a graph of how they connect.
Exploit, under policy
Each candidate finding is actually attempted — not inferred from a banner — within the aggressiveness ceiling your scan policy sets.
Prioritize
A SQL injection on an internal staging form and one on your auth endpoint get the same CVSS score and a very different priority here.
Repeat, on change
A new subdomain, an opened port, or a deployed endpoint triggers re-testing on its own — no engagement letter required.
What an attacker — or Vulnix0 — would actually find.
Eight entries, pulled from the classes of finding the engine confirms most often across real engagements. Each one below is a live check with a request and a response behind it, not a CVE title copied off an advisory feed.
An unsanitized query parameter accepts ' OR '1'='1 and returns full result rows — read access to the underlying database from an unauthenticated request.
A comment or profile field persists <script> payloads and replays them to every future visitor of that page, session included.
Incrementing an ?id= parameter returns other users' records with no ownership check — classic IDOR, confirmed by sequential probing.
USER anonymous / PASS <anything> is accepted with no real credential check — unauthenticated access to whatever file store sits behind it.
Commands succeed with no AUTH at all — read, write, or delete every key, the exact signal behind a long string of real ransom/wiper incidents.
A dashboard reachable with no RBAC, offering "Skip" instead of a token — logs you in as whatever the service account can do. The exact bug behind the 2018 Tesla cryptomining breach.
The model-serving API or an MCP server's tools/list answers with no auth — model inventory, inference, and in some cases filesystem/shell tool access, free for anyone who finds the port.
The nameserver hands the entire zone — every internal hostname, mail server, and IP — to any anonymous dig axfr request, not just its configured secondaries.
The eight above are illustrative, not exhaustive. What follows is the actual class taxonomy the sixteen modules test against — grouped the way a penetration tester scopes an engagement, not as a marketing checklist.
tools/list with filesystem or shell accessThe annual pentest was never built for how fast you ship.
Questions, answered
Find out what an attacker would find. Today.
Start a free scan, or talk to the team behind Vulnix0.