Redkit looks at your organization the way an attacker would: the web applications on your domains and the services open on your IP ranges. Every finding comes with its severity, the evidence behind it and how to fix it, in one place for your whole team.
The same three steps for every scan type. Nothing to install: Redkit runs on mlab.sh infrastructure in France, in a fresh container for every scan.
A full security audit of the websites and applications on your domains.
Your website is the part of your organization anyone on the internet can reach. Redkit Web maps what it exposes, tests it for the vulnerabilities attackers try first and checks its configuration against current standards. Start with a quick pass that is safe on production, or run the full audit on staging.
See your site the way an attacker sees it on day one: subdomains, open ports, technologies and versions, DNS, files left lying around.
Test for the flaws that get sites breached: injections, cross-site scripting, outdated software with known CVEs, leaked secrets, weak tokens.
Check the settings auditors ask about: TLS, cookies, Content Security Policy, SPF, DKIM and DMARC, DNSSEC, security.txt.
Know every service your networks expose to the internet.
A database left open, a remote desktop port, an admin panel on a forgotten server: most incidents start with a service nobody knew was reachable. Redkit IP sweeps your public IP ranges, lists every open port and identifies the software and version behind it, host by host. Run it regularly and you see new exposure as soon as it appears.
Finds the hosts that answer in your range and the ports open on each one.
Names the service and version behind each port, so you know what is really running.
One page per host, with its history across scans, to follow what opens and what closes.
Source code scanning has its own home: secrets, dependencies, supply chain and CI for your GitHub and GitLab repositories, on code.mlab.sh with your mlab account.
Discover CodeA scan is only useful if it turns into fixes. Redkit keeps the results organized and lets you prove the fixes worked.
Redkit is a defensive audit tool. The limits below are built into the scanners, not left as options.
Redkit/<version> (security scanner; +https://mlab.sh), easy to spot in your logs.One Redkit quota covers both scan types: a web audit or an IP range scan each use one. Your first one is included with a free account, and paid plans add a monthly quota shared by your organization.
PDF export is included on every plan. Compare all plans.
No. Every Redkit scan runs on an asset your organization has verified, and the proof is checked again over time. To audit a client, ask them to add you to their organization or to complete the verification. Our terms of service set out the full conditions.
Redkit is the security audit service of mlab.sh. Its web requests carry the User-Agent Redkit/<version> (security scanner; +https://mlab.sh). A scan can only be launched by an organization that has proven it owns the target: the domain or the IP range. If you see it on your infrastructure, someone with control over that asset ordered the audit, often a client, a colleague or a provider of yours. If you do not recognise it, or you host the asset for someone else and want it stopped, write to [email protected] with the target, the time and your logs. We will identify the organization behind the scan and follow up with you.
Declare it in your infrastructure, then our team checks the allocation (RIR or WHOIS records, ASN, hosting contract) before it can be scanned. Contact us if you need to speed it up.
The quick web audit only reads and runs light checks. The full audit sends test inputs to prove a flaw exists, without writing data or keeping what your server returns. On a fragile production, start quick, or run the full audit on staging first.
Some providers ask to be told before any security testing, even on your own resources. Check your hosting contract before running a full web audit or an IP scan.