See what an attacker can actually reach.
Arx continuously discovers an organization's internet-facing assets, actively tests them for exploitable vulnerabilities, and delivers scored, attributable findings - so security teams see what an attacker could actually reach, not just a list of theoretical issues.

What ARX does.
Continuous attack-surface discovery & monitoring
Discovers and enriches assets, then keeps them under watch. Freshness is tracked per technique, so Arx automatically re-queues only the checks that have gone stale - genuinely continuous, not a scan you remember to re-run.
Active vulnerability testing
Arx proves vulnerabilities rather than merely fingerprinting them, with a purpose-built confirmation method for each class. Every class supports parameter and header injection points.
Generic detection engine
Every response passes through a single rule-driven matcher. A rule can combine status code, headers, body content (with regex plus AND/OR logic), redirect URL, response timing, and size bounds - and fires only when all its criteria are met.
Blind & out-of-band confirmation
For vulnerabilities that never surface in the response, Arx confirms exploitation through an out-of-band interaction server. Payloads are self-identifying, so each interaction ties back to the exact target, parameter, header, and method that triggered it.
Risk scoring & severity
Every finding is scored on a 0–10 scale and bucketed into Low / Medium / High / Critical, with per-target ceilings to keep results signal-dense and de-duplicated.
Safety, scope & controls
Because Arx sends real payloads, it is built to stay within authorized scope, with controls at multiple levels and fail-safe execution.
Discover → Test → Match → Score → Report.
Discover assets and enrich each target with HTTP, DNS, ASN, and certificate data.
Test targets with active attack modules across the vulnerability catalog.
Match every response through the generic rule engine to confirm real findings.
Score each finding 0–10 and assign severity.
Report within the project, then re-queue stale techniques to keep coverage current.