System Operational

Uncover vulnerabilities
before they strike

Mergen continuously monitors your external attack surface, discovering assets and exposing risks in real-time.

24.5M+
Assets tracked
99.9%
Uptime SLA
mergen --target corp.example.com
$Initializing reconnaissance...
$Discovered 1,247 subdomains
$Port scan: 89 services exposed
$ALERT: Critical vulnerability
$CVE-2024-1234: Apache Struts RCECRITICAL
$Generating report...
_

Reconnaissance capabilities

Eight specialized engines working continuously to map your attack surface from an adversary's perspective.

Core Discovery Engines

Subdomain Discovery

Passive enumeration via certificate transparency, DNS brute-force, and permutation scanning across thousands of resolvers.

Certificate Transparency logs, DNS brute-force, permutation scanning, zone transfers, and passive DNS replication. Discovers subdomains even when they resolve to internal networks or behind CDNs.

Port Analysis

Masscan for rapid discovery, Nmap for deep service fingerprinting and version detection.

Full TCP/UDP sweep via Masscan at 10M+ packets per second, followed by targeted Nmap scans for service fingerprinting, version detection, OS identification, and script-based vulnerability enumeration.

Web Crawling

JavaScript-aware crawling with API endpoint extraction and form discovery.

Chromium-based crawler renders JavaScript, extracts API routes from compiled bundles, discovers hidden forms, maps authentication endpoints, and catalogs every reachable resource.

Data Enrichment Layer

Technology Detection

Identify 7,500+ technologies from response signatures — frameworks, CMS, analytics, CDNs, and version numbers.

IP Intelligence

GeoIP mapping, CDN detection, ASN correlation, and reverse DNS across every discovered host.

Historical Data

URL discovery from Wayback Machine, Common Crawl, and passive DNS archives spanning years of data.

Continuous monitoring pipeline

Set your scope once. Mergen handles the rest.

01

Define Scope

Specify domains, IP ranges, and seed targets. Mergen respects your boundaries.

Any CIDR, ASN, or domain
02

Discover

Automated reconnaissance runs continuously across all eight engines, mapping your external footprint from an adversary's perspective.

24/7 continuous scanning
03

Monitor

Real-time alerts when new assets appear, configurations change, or vulnerabilities are exposed. No false-positive fatigue.

Real-time signal, no noise

What Mergen finds

Real findings from real scans. Every asset, service, exposure, and endpoint your organization has connected to the internet.

Subdomains
1,247

admin.corp.example.com, dev-api.example.com, staging-vpn.internal.example.com, partner-portal.example.com

Open Ports
89

SSH (22), RDP (3389), MySQL (3306), Elasticsearch (9200), Jenkins (8080)

Web Endpoints
4,312

Login pages, API docs, admin panels, file uploads, GraphQL consoles

Technologies
37

Apache Struts 2.3, WordPress 5.8, OpenVPN, Django 3.2, Nginx 1.18

Combined findings per project
across all eight engines
5,685
Avg. total
18
Avg. critical
12.4m
Scan duration

Built for security operations

Different roles, same surface. From the SOC to the CISO, everyone sees what matters to them.

Daily triage

SOC Analyst

New findings triaged by severity, validated against accurate scope, and escalated through webhook-integrated workflows.

Minute-to-value: 30s

Attack surface mapping

Security Engineer

Shadow IT and forgotten services flagged on discovery. Asset history tracked through point-in-time comparisons.

Average surface growth: 8-12%/mo

Risk visibility

CISO

Organizational exposure at a glance, with executive-ready summaries and trend charts for board reporting.

Demonstrable due diligence in one view

Free Tier Available

Start mapping your attack surface in under a minute

Add up to 3 domains, define your scope, and Mergen begins continuous discovery immediately.

No credit card required. No time limit on the free tier.