External Attack Surface Scanner

See your perimeter the way an attacker does.

Run a free external security assessment of any domain you own. DNS to OWASP, passive reconnaissance to active vulnerability scan. By Cyberlinx.

Enter a domain you own - you'll verify ownership with your work email on the next screen.

⚡ Quick scan · 2 min 🔍 Comprehensive · 10 min ✉️ PDF emailed to you
No signup. No credit card.
Why Cactus

Built for the people who own the perimeter.

Cactus runs the same reconnaissance an attacker runs first, then hands you a graded, prioritised report before they get the chance to act on it.

Your own domain only

You verify ownership by submitting an email on the domain you're scanning. Free providers (Gmail, Yahoo, etc.) are blocked - you can't kick off a scan against a site you don't control.

Report goes straight to your inbox

The full PDF report is emailed to the address you verified - share it with your team, vendor, or auditor. The live dashboard is also yours to download or share via link.

You pick the depth

Quick (less than 5 min) for a daily-driver overview, or comprehensive (10-15 min) for a full external audit including TLS deep audit, web server audit, WordPress audit and active vulnerability probing. Up to 3 scans per company per 24 hours.

yourdomain.com.au Live scan preview
Overall Risk Score F36/100
TLS Grade A+TLS 1.2/1.3
Email Posture CDMARC p=none
Scan completed in 2m 40s View full sample report →
An external attack surface scanner by
18
Checks across 4 categories
2-15
Minutes per scan
3
Scans per company / 24h
$0
No signup. No card.
What we check

Everything an attacker would do.

Cactus runs 18 distinct checks that include passive reconnaissance and active vulnerability scanning. Quick Mode only runs reconnaissance.

Passive recon - available in both Quick & Comprehensive Modes

DNS & records

Authoritative A / AAAA / MX / NS / TXT / SOA / CAA inventory with issuer and policy gaps flagged.

Subdomain discovery

Certificate Transparency log mining - the full subdomain footprint you've shipped over time.

TLS & certificates

Protocol versions, cipher strength, chain validity, expiry windows, graded per host.

HTTP security headers

HSTS, CSP, X-Frame-Options, Referrer-Policy, Permissions-Policy, present vs missing, per host.

Email security

SPF · DKIM · DMARC · MTA-STS · TLS-RPT posture with actionable deliverability and spoofing risks.

Tech stack & CVEs

Frameworks, CMS's, JS libraries fingerprinted and cross-checked against retire.js and EOL data.

OWASP Top 10 (2021)

Passive-applicable categories mapped against live evidence, no guesswork, no padding.

Subdomain takeover

Dangling CNAMEs scored against a fingerprint library of vulnerable SaaS services.

Compliance snapshot

ISO 27001 · PCI-DSS · NIST CSF · CIS Controls rollup - where you stand before the auditor arrives.

OSINT & exposure

Wayback, GitHub leaks, search-engine dorks - what's already public about your perimeter.

Open ports

Top-1000 TCP discovery - catch admin panels, databases and dev services hiding on non-standard ports.

Top priorities

An auto-generated, action-ready backlog ranked by severity × exploitability, not alphabetised junk.

Active vulnerability scanning - Available in Comprehensive Mode only
ACTIVE

TLS deep audit

Cipher hygiene, deprecated protocols, Heartbleed, ROBOT, BEAST, BREACH, FREAK, SWEET32 and other known TLS CVEs, verified against the live handshake.

ACTIVE

Web server audit

Misconfigurations, dangerous files (.git, .env, backups), default admin pages, dangerous HTTP methods and a long tail of well-known web-server issues.

ACTIVE

WordPress audit

Auto-runs only if WordPress is detected. Enumerates plugins, themes and users; matches detected components against the WordPress vulnerability database.

ACTIVE

Active vulnerability scan

Template-driven probes against the apex and discovered hosts: thousands of known CVEs, exposed admin panels, default credentials, dangerous misconfigurations and takeover-prone services.

How it works

Truly agent-less with no API access required.

From entering your domain to a downloadable PDF,
in less than the time it takes to make a ☕

1

Enter your domain

Drop in the domain you own. We do basic sanity checks - no IPs, no internal addresses, no IP literals.

2

Verify with a company email

Confirm authorisation with an email (no Gmail, no Yahoo, no free providers). This is how we make sure you only scan what you own.

3

Pick your mode

Quick (less than 5 min): passive recon + open ports. Comprehensive (10-15 min): everything, including active vulnerability probing.

4

Live dashboard + PDF in your inbox

Watch each check land on the live dashboard as the scan runs. The full PDF report is emailed as soon as it's ready - share it with your team, vendor, or auditor.

What you'll get

A real report, not a screenshot.

Every scan produces three artefacts you can take to your team, or the board.

Live dashboard

13 sections, severity-ranked findings, jump-anywhere sidebar, severity gauge with letter grade. Shareable via URL, no signup needed for viewers.

Branded PDF report

Cover page with grade and target, executive summary, every section with context and recommendations, full findings table. Emailed to your verified inbox.

Prioritised action list

An prioritised backlog ranked by severity × exploitability. What to fix first, what to schedule, what's noise. No jargon or junk.

Ready?

Run your first scan now.

Start scan Need authenticated, human-led testing?
Book a Penetration Test with Cyberlinx
cyberlinx.com.au
cactus
Scan in progress

,

Comprehensive Started just now
Progress
0%
complete
Elapsed
0s
since start
Estimated remaining
,
calculating…
Steps
0 / 0
queued
Currently running
Starting…
0%

Scan checklist

0 done · 0 running · 0 queued

    Passive recon + active vulnerability checks · authorized targets only.