JAXEN
Stateful Go recon framework with deep TLS forensics
§ Workflow phase
- 01 hunt
- 02 analyze
- 03 enrich
- 04 report
- 05 instrument
Discovery. Finds what is exposed.
JAXEN is a stateful Go recon framework. Shodan integration with a local SQLite ledger, AI/LLM hunting modes, Menlo gateway enumeration, continuous diffing between scans, and deep TLS forensics for direct-IP cert attribution.
What it does
- Shodan-driven discovery with persistent state
- AI/LLM hunting modes (Ollama, vLLM, MCP, vector DBs, gateways)
- Menlo Security gateway enumeration
- Continuous diff between scans, surface changes over time
- Direct-IP TLS probe (no SNI), surfaces customer OV/EV certs on vendor infra
- SQLite-backed ledger so every scan is queryable later
Why this exists
Field engagements are stateful. The same target gets re-checked weeks later, and what changed between scans matters more than the snapshot. JAXEN holds that state and surfaces deltas.
§ Used in
Used in
SURVEYS · 04
- 01
Code assistants — category 09 population follow-up survey 2026-05-18
- 02
AutoGen Studio, agent-platform tier cloud survey 2026-05-14
- 03
JupyterHub on .edu networks, Shodan-driven exposure survey with full chain triage (2026-05-07)
- 04
Langfuse cross-survey-correlation single-host case study (2026-05-06)
FIELD CASES · 06
- 01
Unauthenticated ML Training Server — velutina-service.ch
- 02
116.202.28.181 — Pantaflow Live Transcription Server
- 03
PromptLayer — Marker-Build Assessment
- 04
Embedding Services Survey — Tier-2 Cloud (2026-05-21)
- 05
LLM Orchestration Re-Run — 2026-05-19
- 06
sub2api — Population survey: 7,720 indexed hosts, auth-on-default at scale, zero pool-leak
§ hunt layer
Same phase
- 01
aimap
nmap for AI infrastructure
- 02
VisorGraph
High-performance infrastructure mapping with native gVisor sandboxing
- 03
VisorGoose
Government TLD AI discovery via CT logs, Shodan, DNS, and Ollama fingerprinting
- 04
menlohunt
GCP External Attack Surface Management with automated chain detection
- 05
recongraph
Seed-polymorphic recon engine with environmental contamination detection
- 06
VisorSD
Shodan exposure scanner + adversarial RAG security testing
- 07
VisorBishop
Cross-platform AI/LLM observability fingerprinter, 12 platforms, IP-direct-shadow probe