What it checks
Threat Readiness detects whether a WAF or CDN sits in front of the target, evidences rate-limit and DDoS readiness, checks for bot-protection signals, and looks for exposed origin servers that bypass the edge entirely.
It also runs subdomain discovery via certificate transparency logs and flags subdomains at risk of takeover — a common way attackers hijack abandoned DNS records.
Optional WAF canary probe
With explicit consent, BreakMesh sends a small number of harmless canary HTTP requests to confirm the WAF actually blocks known-bad patterns, rather than just being present and misconfigured.
Skipping that consent still runs the rest of the package — WAF/CDN detection, bot protection, rate-limit and DDoS evidence, and subdomain checks don't require it.