Navigation
Redkit · Security audits

Audit your websites and your networks

Redkit looks at your organization the way an attacker would: the web applications on your domains and the services open on your IP ranges. Every finding comes with its severity, the evidence behind it and how to fix it, in one place for your whole team.

01

How it works

The same three steps for every scan type. Nothing to install: Redkit runs on mlab.sh infrastructure in France, in a fresh container for every scan.

  1. 01 Prove it is yours Add the asset to your organization. A DNS record for a domain, a review by our team for an IP range.
  2. 02 Launch the scan By hand when you need it, or on a schedule. Choose how deep to go: a quick pass for routine checks, a full one when you want everything.
  3. 03 Fix what matters first Findings are ranked by severity, each with its evidence and a remediation, and stay in your history so you can see what changed.
02

Redkit Web

A full security audit of the websites and applications on your domains.

Your website is the part of your organization anyone on the internet can reach. Redkit Web maps what it exposes, tests it for the vulnerabilities attackers try first and checks its configuration against current standards. Start with a quick pass that is safe on production, or run the full audit on staging.

Target
A verified domain or one of its subdomains
Depth
Quick, Full or module by module
Coverage
44 checks in 3 families
Recon

See your site the way an attacker sees it on day one: subdomains, open ports, technologies and versions, DNS, files left lying around.

Vulnerabilities

Test for the flaws that get sites breached: injections, cross-site scripting, outdated software with known CVEs, leaked secrets, weak tokens.

Compliance

Check the settings auditors ask about: TLS, cookies, Content Security Policy, SPF, DKIM and DMARC, DNSSEC, security.txt.

03

Redkit IP

Know every service your networks expose to the internet.

A database left open, a remote desktop port, an admin panel on a forgotten server: most incidents start with a service nobody knew was reachable. Redkit IP sweeps your public IP ranges, lists every open port and identifies the software and version behind it, host by host. Run it regularly and you see new exposure as soon as it appears.

Target
A public IP or range validated by our team
Depth
Quick on key ports, or all 65,535
Result
Open ports, services and versions per host
Discovery

Finds the hosts that answer in your range and the ports open on each one.

Identification

Names the service and version behind each port, so you know what is really running.

Host view

One page per host, with its history across scans, to follow what opens and what closes.

04

Redkit Source code is now Code

Source code scanning has its own home: secrets, dependencies, supply chain and CI for your GitHub and GitLab repositories, on code.mlab.sh with your mlab account.

Discover Code
05

After the scan

A scan is only useful if it turns into fixes. Redkit keeps the results organized and lets you prove the fixes worked.

Ranked findings
Every finding by severity, with its evidence and how to fix it.
PDF report
Web audits export to a clean report for a developer, a client or an auditor.
History and comparison
Every run is kept. Put two side by side to see what was fixed and what is new.
Watchdog
Rerun the same audit every week or every month, without thinking about it.
Shared with your team
Assets, scans and results belong to your organization, with roles for who can launch what.
API
Launch web audits and fetch results as JSON with an API key scoped to Redkit.
06

Safe by design

Redkit is a defensive audit tool. The limits below are built into the scanners, not left as options.

  • Your assets onlyA scan starts only on a domain or range your organization has proven it controls. If the proof goes away, scans stop.
  • Stays in scopeScanners only reach the target you launched. Private and internal addresses are refused.
  • Announces itselfWeb requests carry the User-Agent Redkit/<version> (security scanner; +https://mlab.sh), easy to spot in your logs.
  • Paced trafficRequests are rate limited and capped, so a scan does not hammer your servers.
  • Proves, never extractsTests stop once a flaw is shown. Secrets are stored masked and are never tried against the service that issued them.
  • No evasionNo stealth scanning, no firewall bypass. Everything runs from mlab.sh servers in France.
07

Plans

One Redkit quota covers both scan types: a web audit or an IP range scan each use one. Your first one is included with a free account, and paid plans add a monthly quota shared by your organization.

Free account
1
scan, once
Mlab Pro
5
scans per month
Mlab Team
20
scans per month
Mlab Enterprise
Unlimited
scans

PDF export is included on every plan. Compare all plans.

08

FAQ

Can I scan something I do not own?

No. Every Redkit scan runs on an asset your organization has verified, and the proof is checked again over time. To audit a client, ask them to add you to their organization or to complete the verification. Our terms of service set out the full conditions.

I see Redkit in my logs, what is it?

Redkit is the security audit service of mlab.sh. Its web requests carry the User-Agent Redkit/<version> (security scanner; +https://mlab.sh). A scan can only be launched by an organization that has proven it owns the target: the domain or the IP range. If you see it on your infrastructure, someone with control over that asset ordered the audit, often a client, a colleague or a provider of yours. If you do not recognise it, or you host the asset for someone else and want it stopped, write to [email protected] with the target, the time and your logs. We will identify the organization behind the scan and follow up with you.

How do I prove an IP range is mine?

Declare it in your infrastructure, then our team checks the allocation (RIR or WHOIS records, ASN, hosting contract) before it can be scanned. Contact us if you need to speed it up.

Can a scan break my site?

The quick web audit only reads and runs light checks. The full audit sends test inputs to prove a flaw exists, without writing data or keeping what your server returns. On a fragile production, start quick, or run the full audit on staging first.

Should I tell my hosting provider?

Some providers ask to be told before any security testing, even on your own resources. Check your hosting contract before running a full web audit or an IP scan.

Teams and enterprises

A whole estate to audit?

Dozens of domains, several IP ranges or a client portfolio: tell us what you run and we will size it with you.

  1. 01
    List your assetsDomains and IP ranges you want covered.
  2. 02
    Verify them onceEach proof is shared by everyone in your organization.
  3. 03
    Audit on a scheduleRecurring scans and reports ready when you need them.