See your attack surface
the way attackers do.
eyezer is the offensive scanning console behind Centraleyezer โ dynamic app testing, external attack-surface management, OSINT, secret & container scanning and network probing in one place, with recurring automated monitoring that keeps watching after the first scan.
No credit card for the free tier ยท 1 free DAST + 1 free IP scan included ยท Upgrade any time
One tool for everything an attacker touches first
Most teams juggle a DAST scanner, an ASM feed, a secret scanner and a port scanner โ each with its own login, its own false positives, its own bill. eyezer runs all of them from a single console, correlates the results, verifies the findings, and hands you a prioritized list you can actually act on.
Deep coverage across every surface
Every capability below is a real, feature-gated module in the platform โ not a roadmap promise.
Application exposure
What your running web apps and APIs expose
Dynamic app scanning (DAST)+
Application exposure
What your running web apps and APIs expose
100+ active modules
Dynamic app scanning (DAST)
Full OWASP coverage plus modern classes โ injection, auth, deserialization, SSRF, request smuggling, and framework-specific modules โ with out-of-band confirmation built in.
- SQLi / NoSQLi
- XSS (reflected ยท stored ยท DOM)
- SSRF
- RCE / cmd injection
- XXE ยท SSTI
- IDOR ยท access control
- JWT attacks
- Request smuggling
Domain & email exposure
Your internet-facing domain, DNS and email posture
External attack-surface (EASM)+
Domain & email exposure
Your internet-facing domain, DNS and email posture
150+ domain & email modules
External attack-surface (EASM)
A full domain security assessment: DNS & email posture (SPF/DKIM/DMARC/MTA-STS), TLS audit, cloud exposure, WAF detection, subdomain takeover and threat-intel reputation.
- Subdomain takeover
- Email spoofing
- TLS / weak crypto
- WAF detection
- Threat-intel reputation
- security.txt / CT logs
Public & shadow exposure
Repos, images, secrets and containers attackers can find
OSINT discoveryLeaked-credential scanningContainer security โ configurationContainer security โ vulnerabilities+
Public & shadow exposure
Repos, images, secrets and containers attackers can find
Repos + images
OSINT discovery
Finds the public code repositories and container images tied to your brand across the major hosts and registries โ the shadow surface you didn't know was exposed.
- Public code repos
- Container registries
- Typosquat / lookalike domains
- Brand exposure
Secret scanning
Leaked-credential scanning
Scan discovered public repositories and container images for secrets baked into source history and image layers โ API keys, tokens, private keys and cloud credentials.
- Secrets in repos
- Secrets in image layers
- API keys / tokens
- Private keys
Misconfiguration audit
Container security โ configuration
Audit each discovered container image for insecure configuration and hardening gaps โ misconfigured defaults, excessive privileges and Dockerfile issues.
- Image misconfig audit
- Insecure defaults
- Excessive privileges
- Hardening gaps
Vulnerability (CVE) audit
Container security โ vulnerabilities
Audit each discovered container image for known vulnerabilities (CVEs) across OS and application packages, backed by a continuously refreshed vulnerability database.
- Image CVE audit
- OS + app packages
- Known vulnerabilities
- Fresh vuln data
Network exposure
Exposed services across your IP ranges
IP & network testing+
Network exposure
Exposed services across your IP ranges
130+ own network rules
IP & network testing
TCP connect scanning with banner grabbing, eyezer's own exposed-service vulnerability rules, and extended vulnerability templates against live services โ against domains or raw IP/CIDR targets.
- Port scan + banners
- eyezer service rules
- Extended service templates
- Direct IP / subnet targets
Continuous monitoring
Keeps watching after the first scan
Recurring monitoring & verified findings+
Continuous monitoring
Keeps watching after the first scan
Continuous monitoring
Recurring monitoring & verified findings
Set it and keep watching: eyezer re-runs your scans on a recurring schedule โ hourly, daily or weekly by plan โ and alerts you the moment something changes. Findings carry confidence scoring, verification, reproduction steps and remediation guidance.
- Recurring re-scans
- Change & exposure alerts
- Hourly / daily / weekly
- Confidence + verification
Platform integration
Findings become prioritized, tracked actions
Native Centraleyezer integration+
Platform integration
Findings become prioritized, tracked actions
Risk-based prioritization
Native Centraleyezer integration
eyezer isn't a silo. Every finding flows straight into the Centraleyezer platform, where it's enriched with contextual risk scoring, remediation SLAs, ownership routing and audit-ready compliance evidence โ so a raw scan result becomes a prioritized, trackable action.
- Contextual risk scoring
- Remediation SLAs
- ISO 27001 ยท DORA
- NIS2 ยท PCI DSS
- Ownership routing
- Compliance evidence
From a domain to a prioritized fix list in four steps
No agents to deploy, no appliance to rack. Sign in and point eyezer at what you own.
Add your surface
Enter a domain, an app URL, or a raw IP/CIDR. eyezer maps subdomains, hosts, exposed ports and public repos & images automatically.
Scan deeply
Authenticated or unauthenticated, it runs the full active-module suite, EASM assessment, secret & image audits and network probes โ with out-of-band confirmation.
Verify & prioritize
Findings are de-duplicated, confidence-scored and verified with reproduction steps, so your team works real issues instead of chasing false positives.
Monitor & report
Schedule recurring re-scans, get change alerts, export PDF reports, push to webhooks & chat โ and feed every finding into the Centraleyezer platform.
eyezer feeds the Centraleyezer platform
eyezer isn't a silo. Every finding flows straight into Centraleyezer โ your risk-based vulnerability management platform โ where a raw scan result becomes a prioritized, owned, trackable action with a full audit trail. Discovery and remediation, one continuous loop.
Contextual risk scoring
Findings are re-prioritized by real business risk, not raw severity.
Remediation SLAs & ownership
Every issue gets an owner, a deadline and SLA tracking.
Compliance evidence
Audit-ready trails mapped to NIS2, DORA, ISO 27001, PCI-DSS and CRA.
One source of truth
eyezer findings sit alongside 40+ other scanners in a single console.
Start free. Scale when you're ready.
Hosted in the EU and UAE. Quotas are per plan; Enterprise quotas are fully custom. Prices in EUR, billed monthly.
Passive surface & posture, plus a one-time DAST + IP sample.
- Domains1
- DAST targets1
- IPs32
- Concurrent scans1
- Active DAST1 sample
- MonitoringMonthly
Active testing unlocked, weekly rhythm.
- Domains5
- DAST targets5
- IPs256
- Concurrent scans1
- Active DASTUnlimited
- MonitoringWeekly
Full scanning depth for a security function.
- Domains15
- DAST targets20
- IPs1,024
- Concurrent scans3
- Active DASTUnlimited
- MonitoringDaily
Governance, brand & SSO for larger teams.
- Domains40
- DAST targets60
- IPs4,096
- Concurrent scans5
- Active DASTUnlimited
- MonitoringHourly
Enterprise is single-tenant with custom quotas and MSSP terms, offered through our team โ contact us for details.
Need risk-based vulnerability management across 40+ scanners, compliance evidence and MSSP multi-tenancy? See the Centraleyezer platform โ
What's provisioned in every tier
The exact capability entitlements each plan unlocks. Higher tiers include everything below them.
Questions, answered
What can I do on the free plan?+
How is eyezer different from a normal DAST scanner?+
Can it scan authenticated apps and APIs?+
Does it keep scanning after the first run?+
Where is my data hosted?+
How do I export or integrate findings?+
Do you offer plans for MSSPs?+
Get your free exposure summary
Enter your domain and we'll email you a snapshot of what an attacker can see โ no credit card, no call.
EU & UAE hosted ยท we only scan what you own ยท unsubscribe anytime