Centraleyezer logo
Centraleyezer
Live scanning engine ยท EU & UAE hosting

See your attack surface
the way attackers do.

eyezer is the offensive scanning console behind Centraleyezer โ€” dynamic app testing, external attack-surface management, OSINT, secret & container scanning and network probing in one place, with recurring automated monitoring that keeps watching after the first scan.

No credit card for the free tier ยท 1 free DAST + 1 free IP scan included ยท Upgrade any time

400+
Built-in modules & growing โ€” plus extensible templates
Native
Full Centraleyezer platform integration
Agentless
Point at a URL โ€” nothing to install
EU ยท UAE
Data residency options
Why eyezer

One tool for everything an attacker touches first

Most teams juggle a DAST scanner, an ASM feed, a secret scanner and a port scanner โ€” each with its own login, its own false positives, its own bill. eyezer runs all of them from a single console, correlates the results, verifies the findings, and hands you a prioritized list you can actually act on.

Capabilities

Deep coverage across every surface

Every capability below is a real, feature-gated module in the platform โ€” not a roadmap promise.

Application exposure

What your running web apps and APIs expose

Dynamic app scanning (DAST)
+

100+ active modules

Dynamic app scanning (DAST)

Full OWASP coverage plus modern classes โ€” injection, auth, deserialization, SSRF, request smuggling, and framework-specific modules โ€” with out-of-band confirmation built in.

  • SQLi / NoSQLi
  • XSS (reflected ยท stored ยท DOM)
  • SSRF
  • RCE / cmd injection
  • XXE ยท SSTI
  • IDOR ยท access control
  • JWT attacks
  • Request smuggling

Domain & email exposure

Your internet-facing domain, DNS and email posture

External attack-surface (EASM)
+

150+ domain & email modules

External attack-surface (EASM)

A full domain security assessment: DNS & email posture (SPF/DKIM/DMARC/MTA-STS), TLS audit, cloud exposure, WAF detection, subdomain takeover and threat-intel reputation.

  • Subdomain takeover
  • Email spoofing
  • TLS / weak crypto
  • WAF detection
  • Threat-intel reputation
  • security.txt / CT logs

Public & shadow exposure

Repos, images, secrets and containers attackers can find

OSINT discoveryLeaked-credential scanningContainer security โ€” configurationContainer security โ€” vulnerabilities
+

Repos + images

OSINT discovery

Finds the public code repositories and container images tied to your brand across the major hosts and registries โ€” the shadow surface you didn't know was exposed.

  • Public code repos
  • Container registries
  • Typosquat / lookalike domains
  • Brand exposure

Secret scanning

Leaked-credential scanning

Scan discovered public repositories and container images for secrets baked into source history and image layers โ€” API keys, tokens, private keys and cloud credentials.

  • Secrets in repos
  • Secrets in image layers
  • API keys / tokens
  • Private keys

Misconfiguration audit

Container security โ€” configuration

Audit each discovered container image for insecure configuration and hardening gaps โ€” misconfigured defaults, excessive privileges and Dockerfile issues.

  • Image misconfig audit
  • Insecure defaults
  • Excessive privileges
  • Hardening gaps

Vulnerability (CVE) audit

Container security โ€” vulnerabilities

Audit each discovered container image for known vulnerabilities (CVEs) across OS and application packages, backed by a continuously refreshed vulnerability database.

  • Image CVE audit
  • OS + app packages
  • Known vulnerabilities
  • Fresh vuln data

Network exposure

Exposed services across your IP ranges

IP & network testing
+

130+ own network rules

IP & network testing

TCP connect scanning with banner grabbing, eyezer's own exposed-service vulnerability rules, and extended vulnerability templates against live services โ€” against domains or raw IP/CIDR targets.

  • Port scan + banners
  • eyezer service rules
  • Extended service templates
  • Direct IP / subnet targets

Continuous monitoring

Keeps watching after the first scan

Recurring monitoring & verified findings
+

Continuous monitoring

Recurring monitoring & verified findings

Set it and keep watching: eyezer re-runs your scans on a recurring schedule โ€” hourly, daily or weekly by plan โ€” and alerts you the moment something changes. Findings carry confidence scoring, verification, reproduction steps and remediation guidance.

  • Recurring re-scans
  • Change & exposure alerts
  • Hourly / daily / weekly
  • Confidence + verification

Platform integration

Findings become prioritized, tracked actions

Native Centraleyezer integration
+

Risk-based prioritization

Native Centraleyezer integration

eyezer isn't a silo. Every finding flows straight into the Centraleyezer platform, where it's enriched with contextual risk scoring, remediation SLAs, ownership routing and audit-ready compliance evidence โ€” so a raw scan result becomes a prioritized, trackable action.

  • Contextual risk scoring
  • Remediation SLAs
  • ISO 27001 ยท DORA
  • NIS2 ยท PCI DSS
  • Ownership routing
  • Compliance evidence
How it works

From a domain to a prioritized fix list in four steps

No agents to deploy, no appliance to rack. Sign in and point eyezer at what you own.

1

Add your surface

Enter a domain, an app URL, or a raw IP/CIDR. eyezer maps subdomains, hosts, exposed ports and public repos & images automatically.

2

Scan deeply

Authenticated or unauthenticated, it runs the full active-module suite, EASM assessment, secret & image audits and network probes โ€” with out-of-band confirmation.

3

Verify & prioritize

Findings are de-duplicated, confidence-scored and verified with reproduction steps, so your team works real issues instead of chasing false positives.

4

Monitor & report

Schedule recurring re-scans, get change alerts, export PDF reports, push to webhooks & chat โ€” and feed every finding into the Centraleyezer platform.

Part of Centraleyezer

eyezer feeds the Centraleyezer platform

eyezer isn't a silo. Every finding flows straight into Centraleyezer โ€” your risk-based vulnerability management platform โ€” where a raw scan result becomes a prioritized, owned, trackable action with a full audit trail. Discovery and remediation, one continuous loop.

  • Contextual risk scoring

    Findings are re-prioritized by real business risk, not raw severity.

  • Remediation SLAs & ownership

    Every issue gets an owner, a deadline and SLA tracking.

  • Compliance evidence

    Audit-ready trails mapped to NIS2, DORA, ISO 27001, PCI-DSS and CRA.

  • One source of truth

    eyezer findings sit alongside 40+ other scanners in a single console.

Pricing

Start free. Scale when you're ready.

Hosted in the EU and UAE. Quotas are per plan; Enterprise quotas are fully custom. Prices in EUR, billed monthly.

Free
โ‚ฌ0

Passive surface & posture, plus a one-time DAST + IP sample.

  • Domains1
  • DAST targets1
  • IPs32
  • Concurrent scans1
  • Active DAST1 sample
  • MonitoringMonthly
Starter
โ‚ฌ99/mo

Active testing unlocked, weekly rhythm.

  • Domains5
  • DAST targets5
  • IPs256
  • Concurrent scans1
  • Active DASTUnlimited
  • MonitoringWeekly
Most popular
Pro
โ‚ฌ299/mo

Full scanning depth for a security function.

  • Domains15
  • DAST targets20
  • IPs1,024
  • Concurrent scans3
  • Active DASTUnlimited
  • MonitoringDaily
Business
โ‚ฌ699/mo

Governance, brand & SSO for larger teams.

  • Domains40
  • DAST targets60
  • IPs4,096
  • Concurrent scans5
  • Active DASTUnlimited
  • MonitoringHourly
Enterprise
Custom

Regulated buyers & MSSPs. Everything, custom quotas, single-tenant option.

  • DomainsUnlimited
  • DAST targetsUnlimited
  • IPsUnlimited
  • Concurrent scansUnlimited
  • Active DASTUnlimited
  • MonitoringOn-demand

Enterprise is single-tenant with custom quotas and MSSP terms, offered through our team โ€” contact us for details.

Need risk-based vulnerability management across 40+ scanners, compliance evidence and MSSP multi-tenancy? See the Centraleyezer platform โ†’

Compare plans

What's provisioned in every tier

The exact capability entitlements each plan unlocks. Higher tiers include everything below them.

CapabilityFreeStarterProBusinessEnterprise
Attack surface & posture
Domain security assessment (EASM)
OSINT discovery (repos + images)
Recurring monitoring & change alertsMonthlyWeeklyDailyHourlyOn-demand
Dynamic application scanning (DAST)
Web-app scanning ยท full OWASP + modern classes1 sample
Extended vulnerability templates (web)โ€”โ€”
Authenticated / credentialed scansโ€”โ€”
Deeper OSINT inspection
Leaked-credential (secret) scanningโ€”โ€”
Container image security (CVE + misconfig)โ€”โ€”
IP & network
Port scan + banner grabbingโ€”
eyezer exposed-service vuln rulesโ€”
Extended vulnerability templates (services)โ€”โ€”
Direct IP / subnet targetsโ€”โ€”
Platform
Alerting (webhook ยท email ยท chat)โ€”
Report export (PDF)โ€”
API accessโ€”
Posture trendsโ€”
Single sign-on (OIDC SSO)โ€”โ€”โ€”
Single-tenant / custom quotas / MSSPโ€”โ€”โ€”โ€”
Quotas
Domains151540Unlimited
DAST targets152060Unlimited
IP addresses322561,0244,096Unlimited
Concurrent scans1135Unlimited
Price / monthโ‚ฌ0โ‚ฌ99โ‚ฌ299โ‚ฌ699Contact us
FAQ

Questions, answered

What can I do on the free plan?+
The Free plan gives you continuous surface & posture visibility โ€” the domain security assessment (EASM) and OSINT discovery run on a monthly monitoring cadence โ€” plus one full active DAST scan and one IP scan so you can see the depth of eyezer before you upgrade. It covers 1 domain, 1 DAST target and up to 32 IPs.
How is eyezer different from a normal DAST scanner?+
A typical DAST tool only tests a running web app. eyezer combines dynamic app testing (100+ active modules across OWASP and modern attack classes) with external attack-surface management, OSINT discovery of your public repos and container images, secret and container-CVE scanning, and IP/network probing โ€” then correlates and verifies everything in one console so you get a single prioritized list instead of five disconnected reports.
Can it scan authenticated apps and APIs?+
Yes. From the Pro plan up, eyezer performs authenticated/credentialed scanning with stored credentials, form login, headless-browser auth and multi-identity support. It also imports OpenAPI, Postman and HAR definitions and discovers GraphQL and WebSocket endpoints.
Does it keep scanning after the first run?+
Yes โ€” recurring monitoring is built in. eyezer re-runs your scans automatically on a schedule that scales by plan (monthly on Free, up to hourly on Business) and alerts you when something changes or a new exposure appears.
Where is my data hosted?+
In the EU and the UAE. Enterprise customers can additionally run eyezer as a single-tenant deployment with custom data-residency and quota terms.
How do I export or integrate findings?+
From Starter up you get alerting via webhook, email and chat, PDF report export, and full API access โ€” so eyezer drops into your existing ticketing, SIEM and CI/CD workflows. And every finding flows natively into the Centraleyezer platform for contextual risk scoring, remediation SLAs and audit-ready compliance evidence.
Do you offer plans for MSSPs?+
Yes โ€” the Enterprise tier is designed for regulated buyers and MSSPs, with unlimited quotas, single-tenant isolation and custom commercial terms. It's sold through our team rather than self-serve checkout.

Get your free exposure summary

Enter your domain and we'll email you a snapshot of what an attacker can see โ€” no credit card, no call.

EU & UAE hosted ยท we only scan what you own ยท unsubscribe anytime

Find your exposure before someone else does.

Spin up eyezer, point it at a domain, and get your first verified findings in minutes. The free tier costs nothing.

eyezer โ€” Attack-Surface & DAST Console | Centraleyezer