scan100.cipher-scout.com

An authorised security scanning address operated by ExeQuantum.

What this address is

Name
scan100.cipher-scout.com
Address
209.38.29.218
Role
part of the shared scanning pool
Operator
ExeQuantum

Every connection from 209.38.29.218 is a security scan made on behalf of a customer who owns or is authorised to test the systems being scanned and who has asked ExeQuantum to assess them. We do not scan systems we have not been asked to scan.

This address is part of the shared scanning pool: scans for several customers leave from it and every one of them is authorised by the customer whose systems it reaches.

Check that traffic is ours

The name scan100.cipher-scout.com resolves to 209.38.29.218 and the reverse record of 209.38.29.218 resolves back to scan100.cipher-scout.com. To check an address that has contacted you:

  1. Look up the reverse record for the address. It will be a name of the form scanN.cipher-scout.com.
  2. Look up that name. It will resolve to the address you started with.

If both steps agree, the traffic came from us. An address whose reverse record claims our name but whose name does not resolve back to it is not ours, and we would like to hear about it at the contact below.

We never scan from an address that does not have this two-way record.

What the scans do

Our scans check how a customer's internet-facing systems respond: which services are reachable, how they are configured and how their encryption is set up. The scans are read-only. They do not attempt to log in, exploit a weakness, change data or disrupt a service. They are paced so that a scanned system sees a low, steady rate of connections rather than a burst.

Allow our scans

Allow inbound connections from the addresses that names of the form scanN.cipher-scout.com resolve to. Addresses are added and retired over time and each one is announced on its own name before it is used, so rules based on the names stay correct where rules based on fixed addresses go stale.

Request exclusion

If you believe your systems are being scanned without authorisation, or you do not want them scanned even though a customer has asked us to, write to the contact below with the addresses or names you want excluded and the address of ours that contacted you. We will confirm receipt, check the authorisation on record and either stop or explain why the scan is authorised. Exclusion requests from the owner of a system are honoured.

Contact

Abuse and security contact: abuse@cipher-scout.com

We respond to every message within 2 business days. Please include the date and time of the traffic you saw, the address it came from and the address it reached, so we can match it to a scan. Logs or packet captures are welcome but not required.

Machine-readable contact details are published at /.well-known/security.txt.