Mangudai Mounted Archer Logo

We scout your attack surface before attackers do.

The Mangudai scouted the enemy before the battle began. Your attack surface deserves the same intelligence. Stop leaks, secure DNS, audit headers, and inspect certificates.

POWERING CYBERSECURITY DEFENSIBILITY FOR TECH TEAMS

NMAP
SUBFINDER
GEMINI PRO
NIKTO ENGINE
OWASP ZAP
OPENVAS
DIRBUSTER
SHODAN
CENSYS
WHOIS
SSLSCAN
NMAP
SUBFINDER
GEMINI PRO
NIKTO ENGINE
OWASP ZAP
OPENVAS
DIRBUSTER
SHODAN
CENSYS
WHOIS
SSLSCAN
NMAP
SUBFINDER
GEMINI PRO
NIKTO ENGINE
OWASP ZAP
OPENVAS
DIRBUSTER
SHODAN
CENSYS
WHOIS
SSLSCAN
NMAP
SUBFINDER
GEMINI PRO
NIKTO ENGINE
OWASP ZAP
OPENVAS
DIRBUSTER
SHODAN
CENSYS
WHOIS
SSLSCAN
MANGUDAI VULNERABILITY REPORT - demo-target.comLIVE
0SCORE
SECURE
Mapped Subdomains:18
Open Ports:3 (80, 443, 22)
SSL/TLS Certificate:Valid
Vulnerability Analysis:2 Medium Risk
$ mangudai scan --quick target.com
[+] Scanning DNS subdomains... 18 hosts resolved
[+] Port scanner: 80 (nginx), 443 (nginx)
[!] SSL scan: Expiring in 18 days
[!] Security Header: Missing Content-Security-Policy
[+] Surface analysis completed.

Test Your Attack Surface in Real Time

The Mangudai Legacy

The Mangudai cavalry never entered battle without scouting the enemy first. We audit your system before attackers do — the same reflex, in the digital age.

Mangudai Emblem

Your Journey: From Scout to Khan

01
DISCOVER

Scout

Discover the perimeter. Initiate basic scans and analyze initial security posture.

Scout
DISCOVER

01DISCOVER

STATUSACTIVE
02
FIGHT

Warrior

Fight vulnerabilities. Conduct active scan modules and regular security checks.

Warrior
FIGHT

02FIGHT

STATUSACTIVE
03
MANAGE

Commander

Manage operations. Access AI analysis, dark web checks, and multiple integrations.

Commander
MANAGE

03MANAGE

STATUSACTIVE
04
DOMINATE

Khan

Dominate the attack surface. Execute unlimited scans with white-label executive reporting.

Khan
DOMINATE

04DOMINATE

STATUSACTIVE
Scout

Mangudai Scanning Engine Core

01

1. Forgotten Asset Discovery

Detects old, forgotten, or staging subdomains to prevent unauthorized access and perimeter leaks.

CORE ENGINEACTIVE
02

2. Open Port & Service Audit

Scans for exposed databases and open service ports, blocking entry points for ransomware.

CORE ENGINEACTIVE
03

3. Web Availability Probing

Validates HTTP and HTTPS availability, handling protocol fallback without false positives.

CORE ENGINEACTIVE
04

4. Security Header Audit

Evaluates HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy.

CORE ENGINEACTIVE
05

5. Critical File & Data Leak Guard

Inspects exposed .git repositories, backup archives, env files, and sensitive directory listings.

CORE ENGINEACTIVE
06

6. SSL/TLS Certificate Inspector

Checks expiration dates, self-signed certificates, hostname mismatches, and weak TLS protocol versions.

CORE ENGINEACTIVE
07

7. Email Security (SPF/DMARC)

Audits DNS TXT records for missing or weak SPF policies and checks DMARC authentication protocols.

CORE ENGINEACTIVE
08

8. Nikto Vulnerability Scanner

Audits target hosts using Nikto to discover common web vulnerabilities and misconfigurations.

CORE ENGINEACTIVE
09

9. SQL Injection / XSS Protection

Appends safe canary characters to query parameters to search for database leaks in responses.

CORE ENGINEACTIVE

Enterprise Security at SMB Scale

Enterprise solutions demand days of installation and cost thousands of dollars. Mangudai offers a budget-friendly, high-value alternative for SMBs and MSSPs with instant setup.

PRICING

Starting at $29/mo

Enterprise Tools: $2.400 - $93.000/yr
DIY Scanning: Free (Takes time)
LOCALIZED PDF REPORTS

Yes (Full Translation)

Enterprise Tools: ❌ No (English only)
DIY Scanning: ❌ Manual translation
AI EXECUTIVE SUMMARIES

Yes (Gemini Powered)

Enterprise Tools: ❌ Hard to digest
DIY Scanning: ❌ None
SETUP SPEED

Under 30 Seconds

Enterprise Tools: Days of sales calls
DIY Scanning: Hours of manual config

POWERING CYBERSECURITY DEFENSIBILITY FOR TECH TEAMS

NMAP
SUBFINDER
GEMINI PRO
NIKTO ENGINE

Flexible and Fair Plans

Take control of your attack surface. Choose a plan tailored to your needs.

2 Months Free on Annual Billing (Coming Soon)

Scout

Try Mangudai for free

$0
  • 5 scans per month
  • 1 project, 1 target
  • Basic scan modules
  • SPF/DMARC/SSL check
  • Critical findings hidden
  • PDF reports
  • AI analysis
  • Continuous monitoring
Start Free

Warrior

Essential tools for proactive defense

$0/mo
  • 20 scans per month
  • 5 projects, 20 targets
  • Port, Web, Header & File Scan
  • Email notifications
  • PDF report exports in 6 languages
  • Continuous monitoring
  • Dark web check
  • AI analysis
  • API access
  • Slack + email notifications
Get Warrior
MOST POPULAR

Commander

For security teams and companies

$0/mo
  • 50 scans per month
  • Unlimited projects & targets
  • KVKK & Leak/Dark Web Scan
  • PDF report exports in 6 languages
  • AI analysis (Gemini)
  • Continuous monitoring
  • Slack + email notifications
  • API access
  • White-label reports
Get Commander

Khan

For consultancies managing multiple clients

$0/mo
  • 150 scans per month
  • All 9 scan modules (Nikto & SQLi included)
  • White-label PDF reports
  • Client portfolio view
  • API & Integration Access
  • Priority support
Get Khan

What Security Experts Are Saying About Mangudai

"Within 10 minutes of using Mangudai, we discovered 5 forgotten database ports and an old test subdomain from 3 years ago. An absolute must for every B2B company."

Mert Y.
CTO, SaaS Startup

"We use the Khan plan when presenting cybersecurity audit reports to clients. Adding our own logo and instantly exporting PDFs has dramatically accelerated our workflow."

Sarah K.
Cybersecurity Consultant

"Thanks to continuous monitoring, we receive instant Slack alerts whenever a new subdomain is spun up in our perimeter. Our engineering team is far more secure."

David L.
DevSecOps Lead

Frequently Asked Questions

Mangudai is an Attack Surface Management (ASM) SaaS platform that continuously monitors your public domains, IP addresses, open ports, SSL certificates, exposed sensitive files, and security header configurations to detect vulnerabilities before attackers do.

No. Mangudai scans utilize passive reconnaissance and non-intrusive active probing techniques. Scans do not cause downtime, high server load, or service degradation.

Yes. Mangudai identifies technical compliance gaps (such as missing Cookie Consent Banners, Privacy Disclosures, CSP, and HSTS headers) to support GDPR, KVKK, and ISO 27001 readiness.

The Scout plan allows you to add 1 domain target, perform port, SSL, and subdomain discovery scans, and view baseline risk scores instantly.

Initial discovery and scanning typically complete within 1 to 3 minutes, with findings updated live on your project dashboard.