Every company has a public shadow it forgets about: old subdomains, expiring certificates, email servers missing their defenses, ports left open by long-gone contractors. Attackers inventory all of it before they knock. xwllz is a free defensive tool that builds the same inventory first — subdomains, certificates, mail protections, open ports — so you can fix things before anyone else notices.
Its best trick is starting with nothing: no accounts, no API keys. Public certificate records alone reveal hundreds of subdomains — eight hundred on a demo domain — and from there it checks mail defenses, headers, and ports. If you have professional tools with keys, it uses them for enrichment; if you have scanners installed, it drives those too, otherwise it falls back to pure Python. Discover, watch for changes, report — in documents, data, or a web page — backed by two dozen automated tests and checks across three Python versions. Strictly defensive, by design.
Students: this is the friendliest door into security — no specialist OS, no keys, just Python and curiosity about how the internet leaks. Hiring managers: tested, product-minded tooling with an honest list of what's deferred (app-store publishing, deeper scan wiring) reads very differently from yet another scanner wrapper.




No comments yet