BreakMesh – Vulnerability Simulator & Cyber Range

Scanner package

Threat Readiness scanner

A read-only assessment of a target's edge defenses — the things that stand between the internet and your origin server.

What it checks

Threat Readiness detects whether a WAF or CDN sits in front of the target, evidences rate-limit and DDoS readiness, checks for bot-protection signals, and looks for exposed origin servers that bypass the edge entirely.

It also runs subdomain discovery via certificate transparency logs and flags subdomains at risk of takeover — a common way attackers hijack abandoned DNS records.

Optional WAF canary probe

With explicit consent, BreakMesh sends a small number of harmless canary HTTP requests to confirm the WAF actually blocks known-bad patterns, rather than just being present and misconfigured.

Skipping that consent still runs the rest of the package — WAF/CDN detection, bot protection, rate-limit and DDoS evidence, and subdomain checks don't require it.

All 8 checks in this package

Included from the Team plan and up.

  • WAF/CDN Detection
  • WAF Harmless Canary Probe
  • Bot Protection Detection
  • Rate-Limit Readiness
  • DDoS Readiness Evidence
  • Origin Exposure Check
  • Subdomain Discovery (Certificate Transparency)
  • Subdomain Takeover Risk